CompTIA Security+ Practice Test of the Day 260620

Welcome to today’s CompTIA Security+ practice test!

This practice test uses our new UI!

Today’s practice test is based on Subdomain 4.8 (Explain appropriate incident response activities) from the CompTIA Security+ SY0-701 objectives.

This beginner-level practice test is inspired by the CompTIA Security+ (SY0-701) exam and is designed to help you reinforce key cybersecurity concepts on a daily basis.

These questions are not official exam questions, nor are they brain dumps, but they reflect topics and scenarios relevant to the Security+ certification. Use them to test your knowledge, identify areas for improvement, and build daily cybersecurity habits.

Note: CompTIA and Security+ are registered trademarks of CompTIA. This content is not affiliated with or endorsed by CompTIA.

To choose CompTIA Security+ practice tests based on specific domains/subdomains, click that link.

Recommended read: Ultimate CompTIA Security+ Study Guide (2026)

CompTIA Security+ Practice Test of the Day 260620
10 questions • Single best answer
Question 1
An incident response lead at an energy utility isolates infected hosts from the network to stop malware from spreading further during an active intrusion. Which incident response phase is this?
    Question 2
    After containment, the team removes malware, deletes malicious accounts, and wipes affected drives. Which phase of the process is this?
      Question 3
      A company runs a discussion-based exercise where stakeholders talk through their roles in a simulated breach without touching live systems. Which testing method is this?
        Question 4
        To preserve evidence integrity, responders document every person who handled a seized drive and when. Which forensic concept does this maintain?
          Question 5
          Following an incident, the team meets to identify what went well, what failed, and how to improve future responses. Which phase is this?
            Question 6
            Analysts proactively search the environment for signs of an undetected adversary, forming hypotheses based on threat intelligence. Which activity is this?
              Question 7
              After resolving an incident, investigators determine the underlying flaw that allowed the breach so it can be permanently fixed. Which process is this?
                Question 8
                Legal counsel directs the company to suspend routine deletion of emails relevant to anticipated litigation. Which action is this?
                  Question 9
                  Before an incident occurs, an organization builds playbooks, trains responders, and stocks tools. Which phase of the process is this?
                    Question 10
                    A forensic analyst creates a bit-for-bit copy of a suspect hard drive to examine without altering the original. Which forensic step is this?
                      Cybersecurity Acronyms Desk Mat

                      Tired of Googling acronyms while practicing/studying?
                      Keep them all under your keyboard.

                      📋 GET_THE_DESK_MAT

                      Take more CompTIA Security+ practice tests

                      Leave a Comment

                      Your email address will not be published. Required fields are marked *

                      Scroll to Top