Try CompTIA SecOT+
Try 10 questions now. No account, no card.
A free account unlocks 25 questions per course plus readiness tracking.
Get full access to CompTIA SecOT+
All questions, timed exams, flashcards, PDF study guide download & progress tracking.
Lifetime · all courses
$29.99
One payment · future courses included
30 seconds, then straight to checkout.
Pass, or your money back
Reach 85% readiness on this course, sit the real exam, and if you don't pass we refund it in full. Applies to this single-course purchase. Terms.
CompTIA · Exam reference
About the CompTIA SecOT+ exam
CompTIA SecOT+ (SOT-001) is CompTIA's operational technology security certification, covering the ICS, SCADA and safety instrumented systems that run plants, utilities and factory floors. The exam is scheduled for release on 1 December 2026. This course is ready now, so you can study the objectives before launch day rather than after it.
10
Sample questions
90 min
Exam time limit
70%
Practice pass mark
CompTIA SecOT+ (SOT-001) is scheduled for release on 1 December 2026. It certifies the security of operational technology: the programmable logic controllers, SCADA masters, historians and safety instrumented systems that run water treatment works, refineries, factory floors and power distribution. The certification exists because IT security practice breaks in OT. On an office network you patch on Tuesday and reboot. On a plant floor the controller has a five-year uptime requirement, the vendor withdraws support if you patch outside a scheduled outage, and the safety instrumented system is the last barrier between a runaway process and the people standing next to it. Confidentiality comes third in OT, behind safety and availability. Candidates who carry Security+ habits into SecOT+ scenarios reach for the answer that isolates the compromised host, and lose the mark, because isolating that host drops the process into a state nobody can control. CompTIA recommends three years of hands-on work in OT environments and two years implementing OT cybersecurity before you sit it. The six domains run from OT systems and safety foundations through risk management, threat intelligence, architecture and engineering, security operations, and incident management. You are expected to know the Purdue model well enough to place a jump host correctly, to read a Modbus or DNP3 capture and say what is abnormal, and to write an incident response plan a plant manager will sign. CompTIA has not published the final domain weights, question count or pass mark for version one. Confirm those on comptia.org before you book.
Exam Domains Covered
Exam Format & Details
CompTIA has not published the final exam specifications for SecOT+ version one. The certification is scheduled for release on 1 December 2026, and the draft exam objectives list the six domains without percentage weights. CertCrush distributes practice questions evenly across those six domains and will re-weight the bank once CompTIA publishes the final blueprint. The question count, time limit and pass mark shown on this page are CertCrush's practice configuration, not confirmed CompTIA figures. Check comptia.org for the official exam details and voucher price before you book. Expect a mix of multiple-choice and performance-based items, in line with CompTIA's other security certifications.
Why Practice Questions Matter
Most SecOT+ questions are scenario questions, and the scenario is usually built so that the IT-correct answer is sitting there among the options, and is wrong. You get a compromised engineering workstation at level 3 and four plausible responses, and the one that scores is the one that keeps the process controllable and safe. That instinct does not come from reading a book. It comes from being shown the same trap thirty times until you stop walking into it. Every question here carries an explanation that says why the IT answer fails in an OT context, because that distinction is what the exam is built to test.
Sample Practice Questions
The following questions are a preview of the type of syllabus-aligned questions you will practise in CertCrush. They reflect the format and reasoning style of the CompTIA SecOT+ exam — not actual exam content.
Q1.Substation breakers open one after another. The traffic carrying the trip commands is correctly formatted for the protocol in use, but it originates from a host that has never sent control commands before. Which technique is this?
- A.Unauthorised command message
- B.Denial of service
- C.Spoof reporting message, because the control centre received data indicating the breakers were in a state they were not in
- D.Modify parameter, since opening a breaker changes the operating configuration of the substation feeder
Domain: OT Threat Intelligence
Q2.During recovery from an OT intrusion, what must the team confirm before rebuilding or restoring anything?
- A.That containment holds and the attacker's path into the environment is closed
- B.That the historian retention window still covers the whole period of the intrusion
- C.That the regulator has acknowledged the notification submitted at the start of the incident
- D.That antivirus signatures on all level 2 machines have been updated to the current release
Domain: OT Incident Management
Q3.Why is a shared vendor account a problem even when the password is strong and changed regularly?
- A.It proves a company connected but not which individual did
- B.It cannot be protected with multifactor authentication because the second factor is bound to one device
- C.It cannot be disabled quickly because several vendor engineers would lose access at the same time
- D.It usually holds engineering rights on the controller rather than read-only rights on the historian
Domain: OT Risk Management
Q4.An advisory affects a protocol feature that the site's controllers support but have never had enabled. How does this affect the assessment?
- A.It lowers the priority, but the finding is recorded and revisited if a future change enables the feature
- B.It has no effect, because the vulnerable code is present in the firmware image whether or not the function is configured for use on site
- C.It removes the finding from the register permanently
- D.It raises the priority, because unused features receive less scrutiny during operation
Domain: OT Security Operations
Q5.Two advisories arrive. Advisory A scores 9.8 and affects a controller behind a one-way gateway inside a zone that four people can reach. Advisory B scores 5.3 and affects a device on a conduit carrying traffic to a safety instrumented system. How should the site prioritise?
- A.Advisory B first, because it is reachable from an adjacent zone and the consequence is loss of a safety function
- B.Advisory A first, because a base score above nine indicates a flaw that is trivially exploitable and must always be treated as the more urgent of the two
- C.Both at equal priority, since neither has a vendor validated patch yet
- D.Neither, until the vendor publishes an updated temporal score
Domain: OT Security Operations
Frequently Asked Questions
What is included in the free CompTIA SecOT+ sample?
The free sample includes 10 syllabus-aligned practice questions, sample flashcards, and a preview chapter from the study guide. No account or payment is required to try the sample.
How many questions are in the full CompTIA SecOT+ course?
The full course includes a comprehensive question bank covering all exam domains. You can see the total question count on the CompTIA SecOT+ course page.
Are these official CompTIA exam questions?
No. CertCrush questions are independently written and syllabus-aligned — they mirror the format, difficulty, and reasoning style of the official exam. We are not affiliated with or endorsed by CompTIA.
Which domains does the CompTIA SecOT+ course cover?
The course covers 6 exam domains: OT Systems and Safety Foundations, OT Risk Management, OT Threat Intelligence, OT Cybersecurity Architecture, Design, and Engineering, OT Security Operations, OT Incident Management.
Can I study on mobile?
Yes. CertCrush is fully responsive and works on phones, tablets, and desktops. The timed exam, flashcards, and study guide all work on mobile without installing an app.
What happens when I create an account?
Creating a free account lets you access full courses, track your weak areas by domain, and resume practice sessions across devices. No credit card is required to register.