CompTIA Security+ Practice Test of the Day 260724

Welcome to today’s CompTIA Security+ practice test!

This practice test uses our new UI!

Today’s practice test is based on Subdomain 5.5 (Explain types and purposes of audits and assessments) from the CompTIA Security+ SY0-701 objectives.

This beginner-level practice test is inspired by the CompTIA Security+ (SY0-701) exam and is designed to help you reinforce key cybersecurity concepts on a daily basis.

These questions are not official exam questions, nor are they brain dumps, but they reflect topics and scenarios relevant to the Security+ certification. Use them to test your knowledge, identify areas for improvement, and build daily cybersecurity habits.

Note: CompTIA and Security+ are registered trademarks of CompTIA. This content is not affiliated with or endorsed by CompTIA.

To choose CompTIA Security+ practice tests based on specific domains/subdomains, click that link.

Recommended read: Ultimate CompTIA Security+ Study Guide (2026)

CompTIA Security+ Practice Test of the Day 260724
10 questions • Single best answer
Question 1
An internal audit lead at a hospital has each department evaluate its own controls and report weaknesses before the formal review. No outside party is involved in this initial step. Which activity does this describe?
    Question 2
    A retailer hires testers who receive no prior information about the network, mimicking an outside attacker with zero knowledge. They must discover everything on their own. Which penetration testing approach is this?
      Question 3
      During a penetration test's early phase, testers gather information about the target using public records and search engines without sending traffic to its systems. They avoid any direct interaction. Which technique is this?
        Question 4
        A bank must prove its controls to regulators, so it engages an outside accredited firm with no ties to the bank to formally examine them. The results carry external credibility. Which type of audit is this?
          Question 5
          A security exercise assigns one team to actively attack systems and exploit weaknesses to test resilience. Their role is purely to simulate an adversary. Which type of team is this?
            Question 6
            Testers at a utility are given limited details, such as user-level credentials and some network diagrams, but not full architecture. They combine insider and outsider perspectives. Which testing approach describes this?
              Question 7
              A cloud provider formally declares and signs a statement confirming its controls meet a defined standard, giving customers assurance. This signed declaration is provided to clients. Which practice is this?
                Question 8
                At a corporation, an independent group of board members oversees the internal audit function and reviews control findings on behalf of shareholders. They guide governance from the top. Which body is this?
                  Question 9
                  A firm hires specialists to attempt entry into its data center by tailgating and bypassing badge readers. The goal is to test building security, not networks. Which type of penetration test is this?
                    Question 10
                    A federal banking regulator conducts a mandatory on-site review of an institution's compliance with required controls. The institution cannot opt out of this government-mandated review. Which type of assessment is this?
                      Next step: Hands-on

                      Theory tested. Now put it into practice.

                      The exam checks what you know, but employers check what you can do.

                      HTB Academy’s guided labs cover the same ground hands-on, with you at the keyboard.

                      Build hands-on skills →

                      This is an affiliate link. If you sign up, The Cybersecurity Trail earns a commission at no cost to you.

                      Take more CompTIA Security+ practice tests

                      Leave a Comment

                      Your email address will not be published. Required fields are marked *

                      Scroll to Top