CompTIA Security+ Practice Test of the Day 260621

Welcome to today’s CompTIA Security+ practice test!

This practice test uses our new UI!

Today’s practice test is based on Subdomain 4.9 (Given a scenario, use data sources to support an investigation) from the CompTIA Security+ SY0-701 objectives.

This beginner-level practice test is inspired by the CompTIA Security+ (SY0-701) exam and is designed to help you reinforce key cybersecurity concepts on a daily basis.

These questions are not official exam questions, nor are they brain dumps, but they reflect topics and scenarios relevant to the Security+ certification. Use them to test your knowledge, identify areas for improvement, and build daily cybersecurity habits.

Note: CompTIA and Security+ are registered trademarks of CompTIA. This content is not affiliated with or endorsed by CompTIA.

To choose CompTIA Security+ practice tests based on specific domains/subdomains, click that link.

Recommended read: Ultimate CompTIA Security+ Study Guide (2026)

CompTIA Security+ Practice Test of the Day 260621
10 questions • Single best answer
Question 1
A SOC analyst at a retail chain investigates whether a blocked connection attempt came from an external IP. Which log source most directly shows allowed and denied traffic at the perimeter?
    Question 2
    An investigator needs to see process execution and local file changes on a compromised laptop. Which data source provides this host-level detail?
      Question 3
      An analyst examines an email's hidden fields to determine the originating server, timestamps, and routing path. Which type of data is being analyzed?
        Question 4
        To analyze the exact contents of suspicious network traffic byte by byte, an analyst reviews a full recording of the packets. Which data source is this?
          Question 5
          During an investigation, an analyst reviews entries showing failed logon attempts and privilege changes on a Windows server. Which log source provides these?
            Question 6
            An analyst wants an at-a-glance visual summary of current alert volumes and system health across the environment. Which data source best provides this?
              Question 7
              An investigator reviews records generated by the intrusion prevention system to see which signatures triggered during an attack. Which log source is this?
                Question 8
                An analyst troubleshoots errors in a custom web application by reviewing events the software itself recorded. Which log source is most relevant?
                  Question 9
                  A manager receives a scheduled summary of open findings and detected weaknesses produced automatically by the security platform. Which data source is this?
                    Question 10
                    To confirm which hosts had a known weakness during an incident, an analyst reviews results from a recent assessment that probed systems for flaws. Which data source is this?
                      Cybersecurity Acronyms Desk Mat

                      Tired of Googling acronyms while practicing/studying?
                      Keep them all under your keyboard.

                      📋 GET_THE_DESK_MAT

                      Take more CompTIA Security+ practice tests

                      Leave a Comment

                      Your email address will not be published. Required fields are marked *

                      Scroll to Top