EnglishDeutschFrançaisEspañolPortuguês

CompTIA · SY0-701 · Intermediate

CompTIA Security+ (SY0-701) — Practice Questions and Mock Exam

Prepare for SY0-701 with original practice questions and clear answer explanations. Ask Alex, your AI tutor, when you need more detail, use your results to identify topics to review, and practice your pacing with timed mock exams.

90Mock exam questions
90minTime limit
750/ 900Passing score

Checked against CompTIA · September 2026 · Current exam version

About the exam

CompTIA Security+ (SY0-701) validates the baseline security skills expected in an IT security role. CompTIA lists it against DoD 8140 work roles including cyber defense analyst, incident responder, vulnerability analyst, and security control assessor.

The SY0-701 version launched on November 7, 2023 and covers zero trust, cloud security, threat intelligence, and security program management. It sits between general IT work and specialized cybersecurity roles.

Try five SY0-701 questions

Try five practice questions from the app’s current CompTIA Security+ question bank, with answers and explanations.

General Security Concepts1 / 5

A company wants to ensure that former employees cannot use their credentials to access cloud applications after termination. Which solution provides the MOST immediate and comprehensive access revocation?

AlexFull explanation from Alex

Centralized identity management through an Identity Provider (IdP) enables unified access control across all connected applications. NIST SP 800-53 control PS-4 (Personnel Termination) requires organizations to revoke access promptly upon termination. Control enhancement AC-2(3) recommends automated mechanisms for account management. When automated deprovisioning is triggered (typically via HR integration), disabling one account immediately revokes all active SSO sessions and tokens, prevents new authentication, and triggers SCIM deprovisioning across connected SaaS apps. Without centralization, administrators must manually disable accounts in every application — a slow, error-prone process. Email requests, Wi-Fi changes, and password expiration are inadequate because they are not immediate, not comprehensive, and rely on the terminated employee's cooperation. Ref: NIST SP 800-53 Rev. 5, PS-4, AC-2(3).

Sourcelearn.microsoft.com

Security Operations2 / 5

In a wired 802.1X deployment, an access switch relays a workstation's EAP exchange to a central AAA server before opening the port. Described in RADIUS terminology, what role does the access switch perform?

AlexFull explanation from Alex

The confusion here is real, and it comes from the switch wearing two hats. In the 802.1X vocabulary there are three roles: the workstation is the supplicant, the access switch is the authenticator, and the central server is the authentication server. In the RADIUS vocabulary there are only two, and the network access server, which here is the switch, operates as a client of RADIUS. It passes user information to the designated servers and then acts on the response returned, which in practice means opening the port, assigning a VLAN, or leaving the port unauthorized.

So the same box is a server from the workstation's point of view and a client from the point of view of the authentication infrastructure, and the question asks specifically for the RADIUS terminology.

The distractors map onto the other roles. The authentication server is the one that validates credentials and returns configuration attributes, which the switch never does. The supplicant is the workstation presenting credentials. The certificate authority signs and vouches for certificates ahead of time and is not a participant in the live exchange at all, even when certificate-based authentication is in use.

Exam tip: when a question names a vocabulary explicitly, translate the device into that vocabulary before answering. The same box has different names in 802.1X and in RADIUS, and the exam tests exactly that seam.

Sourcecomptia.org

Threats, Vulnerabilities, and Mitigations3 / 5

A threat intelligence analyst receives an indicator of compromise (IoC) containing a SHA-256 hash of a malware sample. On which layer of the Pyramid of Pain does this indicator fall, and why is it considered easy for an attacker to change?

AlexFull explanation from Alex

David Bianco's Pyramid of Pain (2013) ranks threat indicators by how much difficulty changing them causes attackers. From bottom to top: Hash Values → IP Addresses → Domain Names → Network/Host Artifacts → Tools → TTPs. Hash values sit at the base because changing even a single byte in a malware binary produces a completely different hash. Attackers can recompile, repack, or add junk data to instantly evade hash-based detection, making hash IOCs extremely short-lived. In contrast, TTPs at the apex represent fundamental attacker behaviors requiring significant retooling to change. Effective threat intelligence focuses detection on higher pyramid levels for more durable defenses. While hash-based indicators are useful for immediate blocking, they provide minimal long-term defensive value. Ref: Bianco, D. (2013) The Pyramid of Pain; MITRE ATT&CK framework.

Sourcecsrc.nist.gov

Security Program Management and Oversight4 / 5

A security team needs to develop a user awareness training program. Which topic should be included to help users recognize and report a common social engineering attack vector used in data breaches?

AlexFull explanation from Alex

User awareness training exists to change what a person does in the seconds after a suspicious message arrives, so the topic has to be one where the user is the control. Phishing identification and reporting is exactly that: criminals send messages designed to get someone to open a harmful link or attachment, or to hand over personal information, and no technical filter catches all of them. Teaching people the recognizable signs, such as urgency, a request for credentials or payment details, and a sender address that is almost but not quite right, and teaching them where to report it, gives the security team early warning across the whole organization.

The other three topics all belong in a security program, but none of them is about recognizing a social engineering message. Password complexity is a credential-hygiene rule, and it is increasingly enforced by policy and password managers rather than by user vigilance. A clean desk policy addresses physical information exposure in the office. Badge procedures address physical access and tailgating. Someone trained only in those three would still click the link.

Exam tip: match the control to the attack vector named in the stem. When the stem says social engineering and asks what users should be taught, reporting is the half candidates forget, because recognition without a reporting path leaves the organization blind.

Sourcecomptia.org

Security Architecture5 / 5

A network engineer implements 802.1X port-based authentication on all switch ports. Which component acts as the supplicant in the 802.1X architecture?

AlexFull explanation from Alex

802.1X defines three roles in port-based network access control: The supplicant is the client device (laptop, phone, IoT device) running software that communicates authentication credentials via EAP (Extensible Authentication Protocol). Common supplicant software includes the built-in 802.1X clients in Windows, macOS, and Linux. The authenticator is the network device (switch or wireless access point) that controls physical or logical access to the network. Before authentication succeeds, the port only allows EAP traffic. After successful authentication, the port opens for normal traffic. The authentication server (typically a RADIUS server like FreeRADIUS, Cisco ISE, or Microsoft NPS) receives the credentials from the authenticator and verifies them against a directory (Active Directory, LDAP). It returns accept/reject to the authenticator. The authenticator acts as a proxy — it does not evaluate credentials itself but forwards them to the authentication server. Exam tip: 802.1X roles: supplicant (client requesting access), authenticator (switch/AP controlling the port), authentication server (RADIUS verifying credentials).

Sourcecisco.com

523 practice questions

The Pass-IT question pool gives you material to practice for SY0-701. A Pass-IT mock exam uses 90 questions and a 90-minute time limit; these are practice settings.

Pool details: SY0-701

Exam details checked against CompTIASeptember 5, 2026

date of the last check against the official CompTIA source

Passing score750 / 900

as published by CompTIA

Objectives in the guide28 objectives listed in the official guide

across 5 domains in the official exam guide

Pool size523 questions

= The pool size is equivalent to 5 sets of 90 questions; this does not mean that each mock exam uses a separate set.

Blueprint domains5 domains in the exam blueprint

General Security Concepts 64 · Threats, Vulnerabilities, and Mitigations 117 · Security Architecture 97 · Security Operations 143 · Security Program Management and Oversight 102

Recorded as checked against sources505 of 523

questions recorded as having their answer, options, and explanation checked against official CompTIA documentation

What's on the exam

Security Operations carries the most weight at 28%, covering baselining, hardening, vulnerability management, and the identity, monitoring, and incident-response work that fills a security team's day. Threats, Vulnerabilities, and Mitigations follows at 22%, then Security Program Management and Oversight at 20% and Security Architecture at 18%. General Security Concepts is the smallest domain at 12%, but it sets the vocabulary (the CIA triad, AAA, Zero Trust) that questions in every other domain assume you already have.

The exam leans operational: more than a quarter of the questions sit in Security Operations alone, testing day-to-day execution over conceptual definitions. Security Program Management and Oversight is worth a full fifth of the exam despite covering governance and risk rather than technical configuration, which is where candidates with a purely hands-on background tend to lose the most points.

Exam blueprint: SY0-701

General Security Concepts12%

Compare categories and types of security controls, summarize core security concepts such as the CIA triad, AAA, and Zero Trust, explain how change management affects security, and describe cryptographic solutions including PKI, encryption, and hashing.

≈ 12 h
Threats, Vulnerabilities, and Mitigations22%

Compare threat actor types and motivations, common attack vectors and vulnerabilities across applications, operating systems, and the cloud, and analyze indicators of malware, network, and password attacks alongside mitigation techniques such as segmentation, patching, and hardening.

≈ 22 h
Security Architecture18%

Compare security implications of architecture models such as cloud, on-premises, and IoT, apply security principles to enterprise infrastructure and network segmentation, and explain data protection methods and resilience and recovery strategies such as high availability and backups.

≈ 18 h
Security Operations28%

Apply security baselines and hardening techniques to computing resources, manage hardware, software, and data assets, and run vulnerability management, monitoring, and alerting activities using tools such as SIEM and EDR. Also covers identity and access management, security automation, incident response procedures, and using log and data sources to support investigations.

≈ 28 h
Security Program Management and Oversight20%

Summarize security governance elements such as policies, standards, and roles, and explain the risk management process including risk analysis, treatment, and business impact analysis. Also covers third-party risk assessment, compliance and audit requirements, and running security awareness programs.

≈ 20 h

Exam format and question types

Maximum of 90 questions in 90 minutes, mixing multiple-choice and performance-based questions (PBQs) that put you in a security scenario — configuring a firewall, reading logs, or identifying attack indicators. The passing score is 750 on a scale of 100 to 900, and the pacing leaves roughly a minute per question if you want spare time for the PBQs.

Question types: SY0-701

Multiple Choice72%

Select the single answer that best meets the question’s requirements.

Drag & Drop12%

Move items into the slots, groups, or sequence specified by the task.

Multiple Response10%

Select multiple answers. Follow the question’s instructions on how many to choose.

Performance-based6%

Complete a practical task in a simulated environment, following the stated requirements.

See CompTIA for official question-format information. The shares shown describe the Pass-IT practice pool; they do not establish the proportions on the official exam.

Preparing for SY0-701

Delivered at Pearson VUE testing centers or online with a proctor. The exam is available in English, Japanese, Portuguese, Spanish, and Thai. The certification is valid for three years and renews with 50 CEUs or by passing a higher-level security certification.

Preparation and logistics: SY0-701

Preparation

Illustrative study time60–150 h

illustrative planning range: 60 h with relevant experience to 150 h when starting out; your needs may fall outside this range

LevelIntermediate
Recommended backgroundNo formal prerequisites. CompTIA Network+ and 2 years of IT administration with security focus recommended.

Taking and maintaining the certification

DeliveryOnline-proctored (Pearson VUE) or onsite at testing centers
Retake policyNo waiting period for first retake. 14-day wait for subsequent retakes.
Certification validity3 years

Valid for 3 years. Renew with 50 CEUs in 3 years or pass a higher-level security cert (CySA+, PenTest+, SecurityX).

Common pitfalls

Topics to review: SY0-701

  1. 01Acronym Overload

    Hundreds of security acronyms (SIEM, SOAR, DLP, IDS, IPS, WAF, PAM) — create flashcards

  2. 02Attack Types

    Distinguishing between similar attacks: phishing vs spear phishing vs whaling vs vishing vs smishing

  3. 03Cryptography

    Confusing symmetric vs asymmetric encryption, hashing algorithms, and certificate concepts

  4. 04Governance Questions

    The new Security Program Management domain catches technical-only candidates off guard

Frequently asked questions

How long is the CompTIA Security+ exam?

The SY0-701 exam has 90 questions and a 90-minute time limit.

What is the passing score for CompTIA Security+?

The passing score for the SY0-701 exam is 750 / 900.

Which pitfalls should I review when preparing for CompTIA Security+?

Topics to review include Acronym Overload, Attack Types, Cryptography, Governance Questions. Work through examples to check that you understand the distinctions and can explain your answer.

Do you need Network+ before Security+?

No. CompTIA sets no formal prerequisites and recommends Network+ plus around two years of security-focused IT administration. That recommendation describes the level the questions pitch at rather than a gate, so plenty of people take Security+ first.

How do you renew Security+?

Security+ is valid for three years. You either collect 50 continuing-education units across the cycle, or renew automatically by passing a higher-level CompTIA security certification such as CySA+, PenTest+ or SecurityX.

Which Security+ domains carry the most weight?

Security operations is the largest at 28%, followed by threats, vulnerabilities and mitigations at 22% and security programme management at 20%. Security architecture sits at 18% and general security concepts at 12%. CompTIA publishes the split directly.

What happens if you fail Security+?

There is no waiting period before your second attempt. From the third attempt onwards CompTIA requires a 14-day wait between sittings.

What should you take after Security+?

CySA+ if you are moving towards analysis and detection, PenTest+ for offensive work, or SecurityX for senior architecture roles. Each of them also renews Security+ automatically, so the next exam doubles as your renewal.

One certification, 12 months

Practice for SY0-701

Focus your practice on one certification, or choose Pro to practice across all certifications.

Start a free practice sessionTry the first 20 questions without a card to see whether the practice suits you.

For eligible purchases: money-back guarantee if you fail your exam.

View guarantee terms →