CompTIA Security+ Practice Test of the Day 260409

Welcome to today’s CompTIA Security+ practice test!

This practice test uses our new UI!

Today’s practice test is based on Subdomain 5.5 (Explain types and purposes of audits and assessments) from the CompTIA Security+ SY0-701 objectives.

This beginner-level practice test is inspired by the CompTIA Security+ (SY0-701) exam and is designed to help you reinforce key cybersecurity concepts on a daily basis.

These questions are not official exam questions, nor are they brain dumps, but they reflect topics and scenarios relevant to the Security+ certification. Use them to test your knowledge, identify areas for improvement, and build daily cybersecurity habits.

Note: CompTIA and Security+ are registered trademarks of CompTIA. This content is not affiliated with or endorsed by CompTIA.

To choose CompTIA Security+ practice tests based on specific domains/subdomains, click that link.

Recommended read: Ultimate CompTIA Security+ Study Guide (2026)

CompTIA Security+ Practice Test of the Day 260409
10 questions • Single best answer
Question 1
An organization's CISO signs a formal declaration submitted to a payment card industry regulatory body confirming the company has reviewed its controls, met all required benchmarks, and is currently in compliance with applicable standards. Which audit and assessment activity does this represent?
    Question 2
    A healthcare IT team evaluates its own HIPAA Security Rule compliance by working through a structured checklist — documenting which controls are in place, partially implemented, or missing. No external auditors are involved. Which audit activity does this represent?
      Question 3
      A SaaS company engages a licensed public accounting firm to examine its security controls and data handling practices — producing a report customers can rely on to assess the vendor's trustworthiness without conducting their own audits. Which assessment type does this describe?
        Question 4
        A federal banking regulator sends examiners to a community bank to independently assess its information security program, review audit trails, interview staff, and verify required controls are in place. Which external assessment type is this?
          Question 5
          A penetration tester is given complete network diagrams, system inventories, firewall rule sets, and administrator credentials before starting an engagement. Which type of penetration test environment is this?
            Question 6
            Before actively probing a target, a penetration tester gathers information by analyzing public DNS records, LinkedIn profiles, WHOIS data, and job postings — without sending any packets to the target's network. Which reconnaissance technique is this?
              Question 7
              A security team hires a red team to simulate a sophisticated attacker attempting to compromise the network, exfiltrate data, and maintain persistent access — without the internal defenders being aware of the exercise. Which type of penetration test is this?
                Question 8
                A security consultant attempts to gain unauthorized physical access to a data center by tailgating employees through badge-controlled doors, posing as a maintenance worker, and planting a rogue device on an exposed network port. Which type of penetration test is this?
                  Question 9
                  A board of directors establishes an internal body composed of board members and independent directors chartered to oversee the internal audit function, review findings, ensure controls are effective, and escalate material issues to the full board. Which governance structure is this?
                    Question 10
                    A security exercise involves a red team conducting attack simulations while the blue team actively defends — with findings shared in real time and both teams collaborating to identify detection gaps and improve response playbooks. Which type of penetration test is this?
                      Cybersecurity Acronyms Desk Mat

                      Tired of Googling acronyms while practicing/studying?
                      Keep them all under your keyboard.

                      📋 GET_THE_DESK_MAT

                      Take more CompTIA Security+ practice tests

                      Leave a Comment

                      Your email address will not be published. Required fields are marked *

                      Scroll to Top