CompTIA
Free CompTIA SecOT+ Practice Questions
The CompTIA SecOT+ exam is up to 90 questions in 90 minutes. CertCrush provides 400 syllabus-aligned practice questions and 20 performance-based questions across all 6 exam domains, each with a full explanation. Free to try, no account required.
CompTIA SecOT+ (SOT-001) is CompTIA's operational technology security certification, covering the ICS, SCADA and safety instrumented systems that run plants, utilities and factory floors. The exam is scheduled for release on 1 December 2026. This course is ready now, so you can study the objectives before launch day rather than after it.
Practice content last updated · Independently written and aligned to CompTIA’s published exam objectives.
10
Sample questions
90 min
Exam time limit
70%
Practice pass mark
About the CompTIA SecOT+ Exam
CompTIA SecOT+ (SOT-001) is scheduled for release on 1 December 2026. It certifies the security of operational technology: the programmable logic controllers, SCADA masters, historians and safety instrumented systems that run water treatment works, refineries, factory floors and power distribution. The certification exists because IT security practice breaks in OT. On an office network you patch on Tuesday and reboot. On a plant floor the controller has a five-year uptime requirement, the vendor withdraws support if you patch outside a scheduled outage, and the safety instrumented system is the last barrier between a runaway process and the people standing next to it. Confidentiality comes third in OT, behind safety and availability. Candidates who carry Security+ habits into SecOT+ scenarios reach for the answer that isolates the compromised host, and lose the mark, because isolating that host drops the process into a state nobody can control. CompTIA recommends three years of hands-on work in OT environments and two years implementing OT cybersecurity before you sit it. The six domains run from OT systems and safety foundations through risk management, threat intelligence, architecture and engineering, security operations, and incident management. You are expected to know the Purdue model well enough to place a jump host correctly, to read a Modbus or DNP3 capture and say what is abnormal, and to write an incident response plan a plant manager will sign. CompTIA has not published the final domain weights, question count or pass mark for version one. Confirm those on comptia.org before you book.
Exam Domains Covered
Exam Format & Details
CompTIA has not published the final exam specifications for SecOT+ version one. The certification is scheduled for release on 1 December 2026, and the draft exam objectives list the six domains without percentage weights. CertCrush distributes practice questions evenly across those six domains and will re-weight the bank once CompTIA publishes the final blueprint. The question count, time limit and pass mark shown on this page are CertCrush's practice configuration, not confirmed CompTIA figures. Check comptia.org for the official exam details and voucher price before you book. Expect a mix of multiple-choice and performance-based items, in line with CompTIA's other security certifications.
Why Practice Questions Matter
Most SecOT+ questions are scenario questions, and the scenario is usually built so that the IT-correct answer is sitting there among the options, and is wrong. You get a compromised engineering workstation at level 3 and four plausible responses, and the one that scores is the one that keeps the process controllable and safe. That instinct does not come from reading a book. It comes from being shown the same trap thirty times until you stop walking into it. Every question here carries an explanation that says why the IT answer fails in an OT context, because that distinction is what the exam is built to test.
Try CompTIA SecOT+
Try 10 questions now. No account, no card.
A free account unlocks 25 questions per course plus readiness tracking.
Get full access to CompTIA SecOT+
All questions, timed exams, flashcards, PDF study guide download & progress tracking.
Lifetime · all courses
$29.99
One payment · future courses included
30 seconds, then straight to checkout.
Try 2 performance tasks free
Drag-and-drop, sequencing and configuration tasks that mirror the interactive questions on the real CompTIA SecOT+ exam, marked with partial credit.
Sample Practice Questions
The following questions are a preview of the type of syllabus-aligned questions you will practise in CertCrush. They reflect the format and reasoning style of the CompTIA SecOT+ exam, not actual exam content.
Q1.A post-incident review concludes that the root cause was a phishing email. What is wrong with stopping there?
- A.Phishing is the first cause, not the root cause, which lies in conditions such as remote access without multi-factor authentication and a flat path to level 2
- B.Phishing cannot be a root cause because the message was delivered by the enterprise environment rather than by anything inside the plant network itself
- C.The review should name the specific malware family involved before any cause is recorded as final
- D.A root cause must always name a failed technical control rather than a human action by staff
Domain: OT Incident Management
Q2.What does eradication mean in an OT environment, as distinct from removing malicious files?
- A.Closing the access path, rebuilding systems that can write to controllers and rotating exposed credentials
- B.Deleting the malicious files identified by antivirus from every Windows machine in the affected zone
- C.Replacing all affected controllers with new hardware so no compromised device remains in service
- D.Blocking the attacker's command and control addresses at the enterprise internet gateway
Domain: OT Incident Management
Q3.When verifying setpoints and alarm limits before restart, what should they be checked against?
- A.The design documentation, because the values in the controller may be the ones that were altered
- B.The values recorded in the controller immediately before the incident was declared
- C.The historian trend for the same production campaign in the preceding month
- D.The operator's recollection of normal running values for that unit under steady conditions
Domain: OT Incident Management
Q4.On a plant site, who holds the authority to veto a proposed change on safety grounds?
- A.The process safety engineer
- B.The chief information security officer, because the security policy applies to every system the organisation owns
- C.The controls engineer who maintains the instrument loops and the controller programs for the affected unit
- D.The lead operator on shift at the time the change is proposed for the affected process area
Domain: OT Systems and Safety Foundations
Q5.What defines a properly functioning industrial DMZ?
- A.Neither side initiates a session straight through; the plant initiates into it and the enterprise initiates into it
- B.Every session that crosses it is encrypted end to end and authenticated with multi-factor credentials issued by the enterprise identity provider
- C.It is placed on a separate physical switch stack with its own address range and its own set of firewall management credentials
- D.Traffic crossing it is inspected by an intrusion detection sensor and every allowed flow is recorded in the site log archive
Domain: OT Systems and Safety Foundations
Q6.Which statement best describes operational technology?
- A.Hardware and software that monitors and controls physical equipment and physical processes such as pumps, valves, motors and breakers
- B.Hardware and software that stores, processes and transmits business records, transactions and correspondence for an organisation
- C.A category of networking equipment purpose built to carry encrypted traffic between geographically separated corporate data centres
- D.The collection of regulatory frameworks that govern how critical infrastructure operators report cyber incidents to a national authority
Domain: OT Systems and Safety Foundations
Q7.What is the correct order of security priorities on a plant floor, from highest to lowest?
- A.Safety, availability, integrity, confidentiality
- B.Confidentiality, integrity, availability, followed by safety as a separate engineering concern
- C.Availability, safety, confidentiality, integrity, because production uptime funds every other control
- D.Integrity, safety, availability, confidentiality, because bad data causes every physical failure
Domain: OT Systems and Safety Foundations
Q8.An analyst finds an unpatched remote code execution flaw on an operator station displaying a running exothermic reaction. Company policy for corporate servers is immediate network isolation. What should the analyst do?
- A.Keep the station in service, apply compensating controls at the network boundary, and schedule remediation through the plant change process
- B.Isolate the operator station from the network immediately in line with the corporate incident response policy for unpatched hosts
- C.Disconnect the station and instruct the operator to monitor the reaction from the engineering workstation in the site server room instead
- D.Install the vendor patch during the current shift and reboot the station once the operator confirms the reaction is stable
Domain: OT Systems and Safety Foundations
Q9.A programmable logic controller has been in continuous service since 2004 and runs an operating system that lost vendor support years ago. How should this be characterised?
- A.A normal operational technology condition, managed with compensating controls until a planned outage allows replacement
- B.Evidence of negligence by the plant engineering team that should be escalated to the audit committee as a governance failure
- C.A finding requiring the controller to be replaced within the current quarter regardless of the production schedule and vendor validation
- D.A licensing violation, because operating systems past vendor support may not lawfully be used in an industrial setting
Domain: OT Systems and Safety Foundations
Q10.When restoring controller logic after an incident, where should the logic come from?
- A.The verified golden copy held in the backup repository rather than the running controller
- B.An upload taken from the running controller just before the restore, so current tuning is preserved
- C.The most recent project file found on the engineering workstation that manages that controller
- D.The vendor's default template for that controller family, reconfigured to match the process
Domain: OT Incident Management
CompTIA SecOT+ guides & exam news
CompTIA SecOT+ Explained: Domains, Cost and Is It Worth It in 2026?
CompTIA SecOT+ is the brand new operational technology security certification launching in December 2026. Here is what the exam covers, the domains, the cost, the beta timeline and an honest verdict on whether it is worth your time.
CompTIA A+ Practice Questions: 25 Exam-Style Examples With Answers and Explanations (220-1201 and 220-1202, 2026)
25 free CompTIA A+ practice questions written to the current 220-1201 and 220-1202 objectives, weighted by domain, with the answer and the reasoning for every one. Includes pass marks, domain splits and a scoring guide.
CompTIA Data+ DA0-002 in 2026: What Changed From DA0-001, Exam Cost and Is It Worth It?
DA0-001 retired on 14 April 2026, so CompTIA Data+ DA0-002 is now the only version you can sit. The format is identical, but two of the five domains were rebuilt. Here is what changed, what it costs, and who should take it.
Frequently Asked Questions
Does the CompTIA SecOT+ course include performance-based questions?
Yes. The CompTIA SecOT+ course includes 20 performance-based questions (PBQs): hands-on tasks that mirror the interactive questions on the real exam, including drag-and-drop matching, sequencing and configuration screens. Each one is marked with partial credit, so you can see exactly which placements were wrong, and every task includes a full explanation. The first two are free to try.
What is included in the free CompTIA SecOT+ sample?
The free sample includes 10 syllabus-aligned practice questions, sample flashcards, and a preview chapter from the study guide. No account or payment is required to try the sample.
How many questions are in the full CompTIA SecOT+ course?
The full CompTIA SecOT+ course includes 400 practice questions and 20 performance-based tasks, covering all 6 exam domains. Every question carries a full explanation for the right answer and the wrong ones.
Are these official CompTIA exam questions?
No. CertCrush questions are independently written and syllabus-aligned. They mirror the format, difficulty, and reasoning style of the official exam. We are not affiliated with or endorsed by CompTIA.
Which domains does the CompTIA SecOT+ course cover?
The course covers 6 exam domains: OT Systems and Safety Foundations, OT Risk Management, OT Threat Intelligence, OT Cybersecurity Architecture, Design, and Engineering, OT Security Operations, OT Incident Management.
Can I study on mobile?
Yes. CertCrush is fully responsive and works on phones, tablets, and desktops. The timed exam, flashcards, and study guide all work on mobile without installing an app.
What happens when I create an account?
Creating a free account lets you access full courses, track your weak areas by domain, and resume practice sessions across devices. No credit card is required to register.