CompTIA Security+ Practice Test of the Day 260430

Welcome to today’s CompTIA Security+ practice test!

This practice test uses our new UI!

Today’s practice test is based on Subdomain 2.2 (Explain common threat vectors and attack surfaces) from the CompTIA Security+ SY0-701 objectives.

This beginner-level practice test is inspired by the CompTIA Security+ (SY0-701) exam and is designed to help you reinforce key cybersecurity concepts on a daily basis.

These questions are not official exam questions, nor are they brain dumps, but they reflect topics and scenarios relevant to the Security+ certification. Use them to test your knowledge, identify areas for improvement, and build daily cybersecurity habits.

Note: CompTIA and Security+ are registered trademarks of CompTIA. This content is not affiliated with or endorsed by CompTIA.

To choose CompTIA Security+ practice tests based on specific domains/subdomains, click that link.

Recommended read: Ultimate CompTIA Security+ Study Guide (2026)

CompTIA Security+ Practice Test of the Day 260430
10 questions • Single best answer
Question 1
A SOC analyst investigating a wire fraud incident finds that the CFO's assistant received an email appearing to come from the CEO. The attacker had studied the CEO's communication style, knew the company was closing a major deal, and requested an urgent transfer to a 'new vendor account.' Which attack type does this represent?
    Question 2
    An employee receives a phone call from someone claiming to be from the IT help desk, requesting her Active Directory credentials to 'fix a critical issue with her account.' Which threat vector is being used?
      Question 3
      An employee receives a text message appearing to come from his bank stating his account has been suspended, with a link to verify his identity. The link leads to a fake banking site that harvests his credentials. Which threat vector is being used?
        Question 4
        Attackers identify that security researchers regularly visit a specific industry forum. They compromise the forum's web server and inject malware that exploits a browser vulnerability in site visitors' systems — silently infecting researchers who browse to the site. Which attack type does this represent?
          Question 5
          An attacker registers the domain 'arnazon.com' and builds a replica of the Amazon shopping site. Users who mistype the URL are redirected to the fake site and prompted to enter their credentials. Which threat vector is being used?
            Question 6
            A software vendor's build server is compromised. The attacker inserts malicious code into the vendor's legitimate software update, which is then digitally signed and distributed to thousands of customers who automatically install it. Which attack vector does this represent?
              Question 7
              A penetration tester scans a newly deployed network switch and finds it accessible via SSH using the manufacturer's default username and password. Which attack surface does this represent?
                Question 8
                An attacker drops several USB drives labeled 'Payroll Q4 2025' in a company's parking lot. A curious employee plugs one into their workstation, and the drive automatically executes a payload installing a remote access trojan. Which threat vector was used?
                  Question 9
                  An attacker poses as a new IT vendor at a company's reception desk, presenting a fabricated work order and fake business card. He convinces the receptionist to grant him escorted access to the server room to 'perform scheduled maintenance.' Which social engineering technique does this describe?
                    Question 10
                    During a network audit, a security engineer discovers that a test server deployed six months ago is still internet-facing with TCP ports 21, 23, and 3389 open — all accessible without firewall filtering. Which attack surface concern does this represent?
                      Next step: Hands-on

                      Theory tested. Now put it into practice.

                      The exam checks what you know, but employers check what you can do.

                      HTB Academy’s guided labs cover the same ground hands-on, with you at the keyboard.

                      Build hands-on skills →

                      This is an affiliate link. If you sign up, The Cybersecurity Trail earns a commission at no cost to you.

                      Take more CompTIA Security+ practice tests

                      Leave a Comment

                      Your email address will not be published. Required fields are marked *

                      Scroll to Top