CompTIA Security+ Practice Test of the Day 260721

Welcome to today’s CompTIA Security+ practice test!

This practice test uses our new UI!

Today’s practice test is based on Subdomain 5.2 (Explain elements of the risk management process) from the CompTIA Security+ SY0-701 objectives.

This beginner-level practice test is inspired by the CompTIA Security+ (SY0-701) exam and is designed to help you reinforce key cybersecurity concepts on a daily basis.

These questions are not official exam questions, nor are they brain dumps, but they reflect topics and scenarios relevant to the Security+ certification. Use them to test your knowledge, identify areas for improvement, and build daily cybersecurity habits.

Note: CompTIA and Security+ are registered trademarks of CompTIA. This content is not affiliated with or endorsed by CompTIA.

To choose CompTIA Security+ practice tests based on specific domains/subdomains, click that link.

Recommended read: Ultimate CompTIA Security+ Study Guide (2026)

CompTIA Security+ Practice Test of the Day 260721
10 questions • Single best answer
Question 1
A risk analyst at an insurance company calculates that one flood would destroy 40% of a $500,000 data center. Management wants the dollar loss expected from a single such event. Which value should the analyst report?
    Question 2
    A company expects a server outage twice per year, with each occurrence costing $10,000. Leadership asks for the expected yearly loss from this risk. Which figure is correct?
      Question 3
      A security team maintains a document that tracks each identified risk, its assigned owner, and current status. Leadership uses it to monitor treatment progress. What is this document called?
        Question 4
        An executive board decides to pursue aggressive growth and will accept substantial risk to gain market share. The security team documents this overall posture. Which term describes it?
          Question 5
          A firm buys cyber insurance to shift the financial burden of a potential breach to a third party. The security team classifies this decision. Which risk management strategy is being used?
            Question 6
            After analysis, a company decides a legacy application's risk is too high and discontinues using it entirely. No controls are added because the activity stops. Which strategy is this?
              Question 7
              A continuity planning team performing a business impact analysis defines the maximum time an application may remain down before serious harm occurs. They document this target for planning. Which metric is this?
                Question 8
                A business impact analysis specifies the maximum amount of data, measured in time, the company can afford to lose during an outage. Backups are scheduled to meet it. Which metric is defined?
                  Question 9
                  A risk committee assigns specific metrics that signal when a risk is approaching an unacceptable level, prompting action. These early-warning measures are tracked continuously. What are they called?
                    Question 10
                    A CISO chooses to run risk assessments on a fixed annual schedule rather than only after major incidents. Leadership wants predictable, repeated evaluation. Which assessment type is this?
                      Next step: Hands-on

                      Theory tested. Now put it into practice.

                      The exam checks what you know, but employers check what you can do.

                      HTB Academy’s guided labs cover the same ground hands-on, with you at the keyboard.

                      Build hands-on skills →

                      This is an affiliate link. If you sign up, The Cybersecurity Trail earns a commission at no cost to you.

                      Take more CompTIA Security+ practice tests

                      Leave a Comment

                      Your email address will not be published. Required fields are marked *

                      Scroll to Top