CompTIA Security+ Practice Test of the Day 260408

Welcome to today’s CompTIA Security+ practice test!

This practice test uses our new UI!

Today’s practice test is based on Subdomain 5.4 (Summarize elements of effective security compliance) from the CompTIA Security+ SY0-701 objectives.

This beginner-level practice test is inspired by the CompTIA Security+ (SY0-701) exam and is designed to help you reinforce key cybersecurity concepts on a daily basis.

These questions are not official exam questions, nor are they brain dumps, but they reflect topics and scenarios relevant to the Security+ certification. Use them to test your knowledge, identify areas for improvement, and build daily cybersecurity habits.

Note: CompTIA and Security+ are registered trademarks of CompTIA. This content is not affiliated with or endorsed by CompTIA.

To choose CompTIA Security+ practice tests based on specific domains/subdomains, click that link.

Recommended read: Ultimate CompTIA Security+ Study Guide (2026)

CompTIA Security+ Practice Test of the Day 260408
10 questions • Single best answer
Question 1
A healthcare organization prepares quarterly security reports for its board of directors and separately submits annual attestation reports to HHS under HIPAA. Which two types of compliance reporting are being performed, respectively?
    Question 2
    A European retailer fails to implement required data security controls under applicable privacy law. Following a breach, the regulatory authority imposes a financial penalty equal to 2% of the company's global annual revenue. Which consequence of non-compliance does this represent?
      Question 3
      A payment processor suffers a breach affecting 10 million cardholders. Following disclosure, the company loses 35% of its enterprise customers and several major clients publicly announce contract terminations. The CEO attributes the revenue loss to diminished market trust. Which consequence of non-compliance does this illustrate?
        Question 4
        A financial advisory firm repeatedly violates anti-money laundering compliance requirements. After failed remediation attempts, the federal banking regulator formally revokes the firm's authorization to operate as a registered investment advisor. Which consequence of non-compliance does this represent?
          Question 5
          A company requires all employees to read the updated information security policy annually and confirm in the HR portal that they have read, understood, and will comply with it. Which compliance monitoring activity does this represent?
            Question 6
            A user submits a formal request to a social media company asking it to permanently delete all personal data associated with his account — including posts, behavioral data, and contact information — citing applicable privacy law. Which privacy concept underlies this request?
              Question 7
              A marketing analytics firm processes customer behavioral data on behalf of an e-commerce company, strictly following the e-commerce company's instructions about what to analyze and how to use outputs. The analytics firm has no independent authority over how the data is used. Which role does the analytics firm occupy under privacy law?
                Question 8
                A compliance officer discovers the company retains former employee records indefinitely because no policy defines how long each data category must be kept or when records should be destroyed. Which privacy compliance element is missing?
                  Question 9
                  A company identified a SQL injection vulnerability three months ago. Management took no action despite having the resources to patch it. A breach subsequently exploited that vulnerability. Which compliance failure does this represent?
                    Question 10
                    A cloud security team deploys a tool that automatically detects when any storage bucket is set to public access, reverts it to private, and generates a compliance report — all without manual intervention. Which compliance monitoring approach does this represent?
                      Cybersecurity Acronyms Desk Mat

                      Tired of Googling acronyms while practicing/studying?
                      Keep them all under your keyboard.

                      📋 GET_THE_DESK_MAT

                      Take more CompTIA Security+ practice tests

                      Leave a Comment

                      Your email address will not be published. Required fields are marked *

                      Scroll to Top