Free CompTIA Security+ SY0-701 10-question practice test
Take one of three fixed public free practice tests, get your score immediately, review every explanation, and see which weak areas Cultiv8 can help you fix next.
Choose a fixed test variant
A software vendor publishes a SHA-256 value next to an installer. After downloading the installer, what should a technician do to verify the file was not altered?
An email claims to be from payroll, links to a benefits portal, and asks the user to sign in on a look-alike domain. Which attack type best matches?
A company wants compromised workstations to have limited reach into server networks. Which design choice best supports that goal?
A critical vulnerability was patched, but the next authenticated scan still reports the same finding on the host. What is the best next step?
A company hires an independent firm to review control evidence and provide findings from outside the organization. Which activity is this?
Authentication logs show one common password tried against hundreds of user accounts, with only one or two attempts per account. Which attack is most likely?
After a suspected breach, the team preserves logs, disk images, timestamps, and chain-of-custody notes for later analysis. Which process is most relevant?
A legacy admin console cannot be patched this week, so access is limited to one management subnet. Which mitigation is being used?
A database analyst needs report access but should not be able to change payroll records. Which principle is being applied?
A governance document requires password length, lockout thresholds, and MFA settings for all workforce accounts. Which artifact type most likely contains those specific settings?