CompTIA Security+ Practice Test of the Day 260718

Welcome to today’s CompTIA Security+ practice test!

This practice test uses our new UI!

Today’s practice test is based on Subdomain 4.8 (Explain appropriate incident response activities) from the CompTIA Security+ SY0-701 objectives.

This beginner-level practice test is inspired by the CompTIA Security+ (SY0-701) exam and is designed to help you reinforce key cybersecurity concepts on a daily basis.

These questions are not official exam questions, nor are they brain dumps, but they reflect topics and scenarios relevant to the Security+ certification. Use them to test your knowledge, identify areas for improvement, and build daily cybersecurity habits.

Note: CompTIA and Security+ are registered trademarks of CompTIA. This content is not affiliated with or endorsed by CompTIA.

To choose CompTIA Security+ practice tests based on specific domains/subdomains, click that link.

Recommended read: Ultimate CompTIA Security+ Study Guide (2026)

CompTIA Security+ Practice Test of the Day 260718
10 questions • Single best answer
Question 1
An incident response coordinator at a manufacturing firm confirms ransomware on several hosts. The immediate priority is to isolate affected systems and stop the malware from spreading to other machines. Which incident response phase is this?
    Question 2
    After fully resolving a breach, the team meets to document what happened, what worked, and how to improve future responses. No blame is assigned during the discussion. Which phase of the process is this?
      Question 3
      A forensic technician logs every person who handled a seized drive, with timestamps and transfer signatures. This keeps the evidence admissible in court. Which forensic concept does this documentation maintain?
        Question 4
        To validate the response plan, managers gather and talk through their roles during a hypothetical breach scenario. No production systems are touched. Which testing method is this?
          Question 5
          After recovery, the team investigates the underlying reason the attacker succeeded. They trace it to an unpatched server to prevent recurrence. Which activity focuses on identifying that fundamental cause?
            Question 6
            Before any incident occurs, a company builds playbooks and trains staff. It also stocks response tools so the team can act quickly later. Which phase of the incident response process does this represent?
              Question 7
              Rather than waiting for alerts, an analyst proactively searches the environment for signs of undetected adversaries. The work is driven by hypotheses about attacker behavior. Which activity best describes this?
                Question 8
                Anticipating litigation, counsel instructs IT to preserve all emails and files related to a matter. Automatic deletion must be suspended. Which requirement compels retaining this potentially relevant data?
                  Question 9
                  After isolating infected hosts, the team removes the malware, deletes malicious accounts, and closes the exploited vulnerability before restoring service. Which phase involves eliminating the threat from the environment?
                    Question 10
                    With the threat removed, the team restores systems from clean backups, validates functionality, and returns operations to normal while monitoring for reinfection. Which phase of the process does this describe?
                      Next step: Hands-on

                      Theory tested. Now put it into practice.

                      The exam checks what you know, but employers check what you can do.

                      HTB Academy’s guided labs cover the same ground hands-on, with you at the keyboard.

                      Build hands-on skills →

                      This is an affiliate link. If you sign up, The Cybersecurity Trail earns a commission at no cost to you.

                      Take more CompTIA Security+ practice tests

                      Leave a Comment

                      Your email address will not be published. Required fields are marked *

                      Scroll to Top