CompTIA · Practice exam

Free Security+ Practice Test & Questions

The CompTIA Security+ exam is up to 90 questions in 90 minutes, and the voucher costs $392. CertCrush provides 1,020 syllabus-aligned practice questions and 20 performance-based questions across all 5 exam domains, each with a full explanation. Free to try, no account required.

No account · No card · Pass or refund

Try one · Threats, Vulnerabilities, and Mitigations

A banking web application lets a signed-in user change their account password by submitting a form. An attacker builds a malicious web page that, when opened by a victim who is currently authenticated to the bank in another tab, silently submits a password-change request to the bank on the victim's behalf — without the victim realising it. Which control would BEST prevent this cross-site request forgery (CSRF) attack?

Practice questions
1,020
Exam time limit
90 min
Practice pass mark
70%
Exam voucher
$392

In the full course

What you get

  • 1,020 exam-style questions, each with a full explanation
  • 20 performance-based tasks, marked with partial credit
  • The full study guide, 8 chapters
  • Timed mock exams matched to the real exam length
  • A readiness score weighted by the official exam blueprint

Get full access to CompTIA Security+

All questions, timed exams, flashcards, PDF study guide download & progress tracking.

This course

$9.99

one-time

Pass or refund
Create account and buy

30 seconds, then straight to checkout.

Until 30 November

Lifetime · all courses

$29.99

One payment · future courses included

Create account and buy

30 seconds, then straight to checkout.

PASS GUARANTEEOR MONEY BACK

Pass, or your money back

Reach 85% readiness on this course, sit the real exam, and if you don't pass we refund it in full. Applies to this single-course purchase. Terms.

More free samples

Marked, and passed

Real feedback from people who passed

“Honestly wasn't expecting much but this is probably the best ten bucks I've spent on exam prep. Did 20–30 questions every morning before work for 6 weeks. Passed with a comfortable margin. The timed exam mode is what really got me comfortable with the pressure.”
PSPriya S.CompTIA Security+
“I'm not a natural test taker and I get bad exam anxiety. Doing 50+ timed practice sessions on here meant by the time I sat the real thing it just felt like another practice run. Huge confidence booster.”
DMDan M.CompTIA CySA+
“I failed my CISSP on the first attempt with another platform. Switched to CertCrush, focused on my weak domains using the tracking feature, and passed three months later. The explanations for wrong answers are genuinely useful, not just 'A is correct because A is correct'.”
MTMarcus T.ISC² CISSP

The CompTIA Security+ (SY0-701) is the world's most recognised entry-level cybersecurity certification, trusted by employers, government agencies, and the US Department of Defense (DoD 8140 approved). It validates the core skills every security professional needs: identifying threats and vulnerabilities, securing hybrid environments, responding to incidents, and applying governance, risk, and compliance principles.The exam covers five domains: General Security Concepts, Threats Vulnerabilities and Mitigations, Security Architecture, Security Operations, and Security Program Management and Oversight. You'll face up to 90 questions (multiple choice plus performance-based) in 90 minutes, with a passing score of 750 out of 900.Security+ is the launchpad for SOC analyst, security engineer, and GRC roles, and it's the foundation for every advanced cert that follows.

Practice content last updated · Independently written and aligned to CompTIA’s published exam objectives.

About the CompTIA Security+ Exam

CompTIA Security+ (SY0-701) is the most widely held entry-level cybersecurity certification in the world, and the baseline standard for IT security roles across both the private sector and US federal government. It is approved under DoD 8570/8140, making it a mandatory requirement for many defence and government contractor positions. Security+ validates that you can assess the security posture of an enterprise environment, recommend and implement appropriate security solutions, monitor and secure hybrid environments, and respond to security incidents. The exam covers five domains: Security Program Management and Oversight; Security Operations; Security Architecture; Threats, Vulnerabilities, and Mitigations; and General Security Concepts. Security+ is vendor-neutral, meaning the skills it certifies apply across all technology platforms and cloud providers. It is the ideal next step after CompTIA Network+ or for IT professionals moving into a dedicated security role. CertCrush gets you exam-ready with a free Security+ practice test experience: realistic practice questions, timed mock exams that mirror the SY0-701 format, and PBQ practice with a clear explanation for every answer.

Exam Domains Covered

  • Security Program Management and Oversight20%
  • Security Operations28%
  • Security Architecture18%
  • Threats, Vulnerabilities, and Mitigations22%
  • General Security Concepts12%

Exam Format & Details

The CompTIA Security+ exam (SY0-701) consists of a maximum of 90 questions, including multiple-choice and performance-based questions (PBQs). The time limit is 90 minutes. The passing score is 750 on a scale of 100–900. The exam is available at Pearson VUE test centres worldwide or via online proctoring. The exam voucher costs $392 USD. CompTIA recommends (but does not require) CompTIA Network+ certification and two years of IT experience with a security focus before sitting Security+. Results are available immediately for computer-based testing.

Why Practice Questions Matter

Security+ uses performance-based questions (PBQs) alongside multiple-choice, which means some questions require you to interact with simulated environments, configuring firewalls, analysing logs, or identifying vulnerabilities in a network diagram. You cannot pass Security+ through memorisation alone. Timed practice builds the fluency you need to move through scenario questions quickly and confidently. CertCrush questions are written to match the SY0-701 domain weighting, so your practice time targets the areas that actually appear on the exam.

Try 2 performance tasks free

Drag-and-drop, sequencing and configuration tasks that mirror the interactive questions on the real CompTIA Security+ exam, marked with partial credit.

Start free

Sample Practice Questions

The following questions are a preview of the type of syllabus-aligned questions you will practise in CertCrush. They reflect the format and reasoning style of the CompTIA Security+ exam, not actual exam content.

Q1.A banking web application lets a signed-in user change their account password by submitting a form. An attacker builds a malicious web page that, when opened by a victim who is currently authenticated to the bank in another tab, silently submits a password-change request to the bank on the victim's behalf — without the victim realising it. Which control would BEST prevent this cross-site request forgery (CSRF) attack?

  • A.Input validation to sanitize the new password value submitted in the reset form
  • B.Server-side request filtering to block requests from internal IP addresses
  • C.Anti-CSRF tokens embedded in forms that tie each request to the user's authenticated session
  • D.Rate limiting on the password reset endpoint to prevent rapid submission

Domain: Threats, Vulnerabilities, and Mitigations

Q2.A healthcare organization's security team conducts a penetration test specifically targeting the physical access controls at its data center, including attempting to tailgate employees through secure doors and testing whether security guards can be socially engineered. What type of testing is this?

  • A.Unknown environment testing
  • B.Red team social engineering
  • C.Physical penetration testing
  • D.Blue team defensive exercise

Domain: Security Program Management and Oversight

Q3.A penetration test reveals that developers have been testing applications using a copy of the live customer database containing real Social Security numbers. Which data security method should have been applied before creating the test copy?

  • A.Masking
  • B.Encryption
  • C.Tokenization
  • D.Hashing

Domain: Security Architecture

Q4.A security analyst reviews logs showing that a web application returned HTTP 500 errors immediately after unusual input strings were submitted. Which data source would provide the MOST useful information for investigating a possible injection attack?

  • A.Network logs
  • B.Firewall logs
  • C.Application logs
  • D.IPS logs

Domain: Security Operations

Q5.A pharmaceutical company shares clinical trial data with a research partner but replaces patient names and birth dates with realistic fictitious values. The partner receives structurally accurate but non-sensitive data. Which technique is being used?

  • A.Tokenization
  • B.Encryption
  • C.Steganography
  • D.Data masking

Domain: General Security Concepts

Q6.An organization's security policy requires all third-party software libraries to be reviewed before inclusion in production applications. A developer bypasses this policy and adds an open-source library with an unpatched remote code execution vulnerability. Which vulnerability type BEST describes the risk introduced?

  • A.OS-based vulnerability because the library runs at the operating system level
  • B.Supply chain vulnerability through inclusion of software from an unvetted provider
  • C.Zero-day vulnerability because the library vulnerability has no public CVE number
  • D.Misconfiguration of the application's dependency management settings

Domain: Threats, Vulnerabilities, and Mitigations

Q7.A penetration tester discovers a vulnerability in an in-scope web application that appears to provide a path to the organization's financial database, which is explicitly listed as out of scope in the rules of engagement. What is the CORRECT action?

  • A.Exploit the vulnerability to demonstrate the risk to the financial database
  • B.Document the finding and notify the client without exploiting the out-of-scope system
  • C.Expand the scope unilaterally to include the financial database given the severity
  • D.Continue the test and include the database access in the final report as a bonus finding

Domain: Security Program Management and Oversight

Q8.A company takes daily full backups of its critical database. A security analyst suggests this consumes excessive storage and recommends a strategy that balances storage efficiency with manageable restore complexity using only two backup sets for restoration. Which strategy BEST meets this recommendation?

  • A.Switch to incremental backups only with no full backups
  • B.Weekly full backups with daily incremental backups and accept complex multi-set restores
  • C.Replace all backups with real-time replication only
  • D.Weekly full backups with daily differential backups

Domain: Security Architecture

Q9.A security orchestration platform automatically disables a compromised user account, notifies the user's manager, creates an incident ticket, and initiates a forensic collection job, all from a single alert. This demonstrates automation's role as a:

  • A.Guard rail for policy enforcement
  • B.Workforce multiplier through orchestrated actions
  • C.Baseline for normal user behavior
  • D.Technical debt reducer

Domain: Security Operations

Q10.An organization cannot implement MFA on a legacy system. As a compensating control, the team restricts access to the system to a dedicated jump server with enhanced logging. Which Zero Trust concept does the access restriction MOST reflect?

  • A.Adaptive identity
  • B.Implicit trust zone creation
  • C.Threat scope reduction
  • D.Policy-driven access control

Domain: General Security Concepts

CompTIA Security+ guides & exam news

Frequently Asked Questions

Does the CompTIA Security+ course include performance-based questions?

Yes. The CompTIA Security+ course includes 20 performance-based questions (PBQs): hands-on tasks that mirror the interactive questions on the real exam, including drag-and-drop matching, sequencing and configuration screens. Each one is marked with partial credit, so you can see exactly which placements were wrong, and every task includes a full explanation. The first two are free to try.

What is included in the free CompTIA Security+ sample?

The free sample includes 10 syllabus-aligned practice questions, sample flashcards, and a preview chapter from the study guide. No account or payment is required to try the sample.

How many questions are in the full CompTIA Security+ course?

The full CompTIA Security+ course includes 1020 practice questions and 20 performance-based tasks, covering all 5 exam domains. Every question carries a full explanation for the right answer and the wrong ones.

Are these official CompTIA exam questions?

No. CertCrush questions are independently written and syllabus-aligned. They mirror the format, difficulty, and reasoning style of the official exam. We are not affiliated with or endorsed by CompTIA.

Which domains does the CompTIA Security+ course cover?

The course covers 5 exam domains: Security Program Management and Oversight, Security Operations, Security Architecture, Threats, Vulnerabilities, and Mitigations, General Security Concepts.

Can I study on mobile?

Yes. CertCrush is fully responsive and works on phones, tablets, and desktops. The timed exam, flashcards, and study guide all work on mobile without installing an app.

What happens when I create an account?

Creating a free account lets you access full courses, track your weak areas by domain, and resume practice sessions across devices. No credit card is required to register.

Start with 10 free questions

No account, no card. The full CompTIA Security+ course is $9.99, once.

Start freeBuy · $9.99