CompTIA Security+ Practice Test of the Day 260331

Welcome to today’s CompTIA Security+ practice test!

This practice test uses our new UI!

Today’s practice test is based on Subdomain 4.9 (Given a scenario, use data sources to support an investigation) from the CompTIA Security+ SY0-701 objectives.

This beginner-level practice test is inspired by the CompTIA Security+ (SY0-701) exam and is designed to help you reinforce key cybersecurity concepts on a daily basis.

These questions are not official exam questions, nor are they brain dumps, but they reflect topics and scenarios relevant to the Security+ certification. Use them to test your knowledge, identify areas for improvement, and build daily cybersecurity habits.

Note: CompTIA and Security+ are registered trademarks of CompTIA. This content is not affiliated with or endorsed by CompTIA.

To choose CompTIA Security+ practice tests based on specific domains/subdomains, click that link.

Recommended read: Ultimate CompTIA Security+ Study Guide (2026)

CompTIA Security+ Practice Test of the Day 260331
10 questions • Single best answer
Question 1
A security analyst reviews logs showing that the perimeter firewall allowed inbound TCP connections on port 3389 from an external IP at 2:00 AM — connections that should never occur. Which log data source provides this information?
    Question 2
    A forensic investigator searches Windows Event Logs for process creation events, service installations, and privilege escalation activity on a compromised workstation. Which log data source is being analyzed?
      Question 3
      An analyst investigating a web application breach queries logs showing every HTTP request — including URIs, parameters, user agents, response codes, and timestamps — to identify the SQL injection payload used. Which log source provides this data?
        Question 4
        A SOC analyst queries network flow records from the core switches to identify all systems that communicated with a suspected compromised host over the past 72 hours — mapping the potential lateral movement paths. Which data source is being used?
          Question 5
          A security engineer captures all network traffic on a segment for a 10-minute window during a suspected data exfiltration event — preserving the complete payload content for forensic analysis. Which data source does this describe?
            Question 6
            A vulnerability management platform automatically scans all assets weekly and produces reports ranking vulnerabilities by CVSS score — showing which systems are missing critical patches. Which security data source does this describe?
              Question 7
              A SIEM platform aggregates data from multiple security tools and presents a unified dashboard showing open incidents, critical alerts, endpoint compliance status, and threat trends — giving the SOC team a consolidated operational view. Which data source concept does this represent?
                Question 8
                An IDS generates an alert when it detects a pattern matching a known buffer overflow exploit attempt in network traffic. Which log data source produced this alert?
                  Question 9
                  During a breach investigation, a forensic analyst examines file system timestamps, registry modification records, prefetch files, and event log entries on a workstation — building a timeline of attacker activity. Which log data category is being primarily analyzed?
                    Question 10
                    A threat intelligence analyst correlates data from vulnerability scans, firewall logs, IDS alerts, and endpoint telemetry — identifying that a specific CVE was exploited after the IDS missed the attempt but the endpoint log shows process injection. Which analytical approach does combining these sources represent?
                      Next step: Hands-on

                      Theory tested. Now put it into practice.

                      The exam checks what you know, but employers check what you can do.

                      HTB Academy’s guided labs cover the same ground hands-on, with you at the keyboard.

                      Build hands-on skills →

                      This is an affiliate link. If you sign up, The Cybersecurity Trail earns a commission at no cost to you.

                      Take more CompTIA Security+ practice tests

                      Leave a Comment

                      Your email address will not be published. Required fields are marked *

                      Scroll to Top