CredenTrek
Independent roadmaps for accredited credentialsEdition 2026.2 · Register verified 9 October 2026
Library / Security+ / Guide 07 of 8
Security+ · Practice questions

Ten Security+ scenario questions, and why the runner-up answer loses

By Mustafa K. Al-Dori · Checked against official documents on 9 October 2026 · 6 min read

The short answer

Security+ questions reward reading the evidence before naming the answer. Both V7 (SY0-701) and V8 (SY0-801) give you up to 90 questions in 90 minutes, mixing multiple choice with performance-based tasks, and a scaled score of 750 on a 100 to 900 scale passes. Below are ten original scenario questions across all five domains, each explaining why the runner-up loses.

Many Security+ candidates who run short of time are not short of knowledge. They sink twenty minutes into one performance-based question, or pick an answer that is true but misses the problem. Either habit can cost a full-price retake.

How is the exam scored, and how do performance-based questions work?

Both V7 (SY0-701) and V8 (SY0-801) give you up to 90 questions in 90 minutes. You pass with a scaled score of 750 on a scale of 100 to 900. It is not a percentage, so ignore any online "percentage needed to pass".

CompTIA names three formats for both versions:

Format What you do
Multiple choice, one answer Choose the single best answer
Multiple choice, several answers Choose every correct answer asked for
Performance-based Solve a task in a simulated environment, such as ordering rules, matching items or reading a log

Performance-based questions often appear early and take longer. Many candidates flag them and return once the multiple-choice questions are done. Practise them in a home lab, because reading alone will not prepare you.

The ten questions below are original, each mapped to its V8 objective and closest V7 one. V8 is expected on or around 17 November 2026; English V7 retires on 11 June 2027. Allow 10 minutes. Facts were checked against CompTIA's documents in October 2026.

General Security Concepts and threats: four questions

Question 1 · General Security Concepts

A new sign-in page must verify passwords but never be able to recover them, even for administrators. How should they be stored?

A. Encrypted with AES-256, with the key on the application server
B. Hashed with a unique salt and a slow key-stretching algorithm
C. Encoded in Base64
D. Hashed once with SHA-256, without a salt

Show answer
Answer: B. V8 objective 1.3 (V7 1.4): hash when you only need to compare. Salting defeats precomputed tables; key stretching slows guessing. A is the runner-up: encryption is reversible, so whoever steals the key recovers every password.

Question 2 · General Security Concepts

VPN users can reach every internal server. An attacker hijacks a contractor's laptop mid-session and moves freely between systems. What would most have limited the damage?

A. Stronger encryption on the VPN tunnel
B. Zero trust, verifying every request to each resource
C. Hiding internal server names from VPN users
D. Digital signatures on internal email

Show answer
Answer: B. V8 objective 1.1 (V7 1.1 and 1.2) covers zero trust: nobody is trusted because of where they connect from. A is the runner-up: encryption protects traffic in transit, but the attacker was already inside the tunnel.

Question 3 · Threats, Vulnerabilities and Attacks

Within an hour, 400 accounts each record one failed sign-in, all with the same password from one IP address. None reaches its lockout threshold. What is the most likely attack?

A. Brute force
B. Password spraying
C. Credential stuffing
D. A dictionary attack on one account

Show answer
Answer: B. V8 objective 2.5 (V7 2.4) covers indicators. One common password tried once per account stays under lockout limits. C is the runner-up: credential stuffing also hits many accounts, but replays different username and password pairs stolen elsewhere.

Question 4 · Threats, Vulnerabilities and Attacks

In an authorised test, typing ' OR 1=1 -- into a web form's username field logs the tester in as the first user in the database. What has she found?

A. Cross-site scripting
B. SQL injection
C. Buffer overflow
D. Directory traversal

Show answer
Answer: B. V8 objective 2.4 (V7 2.2 and 2.3) covers application weaknesses. The input rewrote the database query, which parameterised queries prevent. A is the runner-up: it also abuses unvalidated input, but runs script in another user's browser.

Security Architecture: two questions

Question 5 · Security Architecture

A company moves its file servers to infrastructure as a service (IaaS) virtual machines. Who must patch their operating systems?

A. The cloud provider
B. The company
C. Both equally, by default
D. Nobody, as the hypervisor isolates them

Show answer
Answer: B. V8 objective 3.1 (V7 3.1) compares architecture models. In IaaS the provider secures hardware and virtualisation; the customer secures the operating system upwards. A is the runner-up: it fits software as a service, where the provider runs the whole stack.

Question 6 · Security Architecture

Ransomware encrypts a file server, including the nightly backups stored on a share on the same server. Which change best protects the next recovery?

A. Nightly full backups instead of incremental ones
B. An offline or immutable backup copy, with regular test restores
C. Rebuilding the server's disks as RAID 5
D. Hourly snapshots on the same volume

Show answer
Answer: B. V8 objective 3.4 (V7 3.4) covers backups and recovery testing. A copy the attacker cannot reach survives, and testing proves it restores. D is the runner-up: an attacker with administrator rights on that server can delete the snapshots.

Security Operations, the heaviest domain: three questions

Question 7 · Security Operations

An access review finds that an employee who moved from finance to marketing six months ago still has payroll access. What should the team do?

A. Disable her account until her manager confirms her role
B. Remove the finance access and fix the role-change process
C. Require multifactor authentication on payroll
D. Note the finding for next year's review

Show answer
Answer: B. V8 objective 4.5 (V7 4.6) applies least privilege: access follows the current role. C is the runner-up: multifactor sign-in stops stolen passwords, but the problem is access she no longer needs.

Question 8 · Security Operations

A SIEM rule raises hundreds of daily alerts, all administrator sign-ins by a documented backup service account in its scheduled window. Analysts now skim the queue. What should you do?

A. Disable the rule
B. Tune the rule to exclude that account on its known host and schedule
C. Route the alerts to a weekly mailbox
D. Add another analyst to the queue

Show answer
Answer: B. V8 objective 4.4 (V7 4.4) covers alerting and tuning. Removing documented noise restores attention to real alerts. A is the runner-up: it ends the noise, but blinds you if any administrator account is misused.

Question 9 · Security Operations

A server suspected of running malware is isolated from the network, and legal action against an insider is possible. What should the analyst do next?

A. Reimage the server to restore service
B. Capture memory, then image the disk, recording the chain of custody
C. Restart the server
D. Run a full antivirus scan on the live system

Show answer
Answer: B. V8 objective 4.8 (V7 4.9) covers evidence. Collect volatile memory first, since shutdown erases it, and record who handles each item. A is the runner-up: it restores service but destroys the evidence.

Security Program Management and Oversight: one question

Question 10 · Security Program Management and Oversight

Next week your company signs with a payroll provider that will hold every employee's personal and bank details. What should happen first?

A. Accept the provider's own security statement
B. Assess its security evidence and add audit and breach-notification clauses
C. Run an unannounced penetration test against its systems
D. Sign now and assess it next year

Show answer
Answer: B. V8 objective 5.3 (V7 5.3) covers vendor assessment, contracts and monitoring. An independent audit report plus contract rights gives assurance and a remedy. C is the runner-up: it sounds rigorous, but testing systems you do not own without written permission is unlawful.

What your score tells you

Count first answers only, then sort misses by habit, which repeats across domains.

If you missed The habit to fix
1 or 6 Choosing a strong-sounding tool for the wrong job
2 or 7 Trusting location or an old role instead of verifying access
3 or 4 Naming the attack before reading the evidence
5 or 10 Misplacing responsibility between you and a provider
8 or 9 Easing today's pain at the cost of detection or evidence

How many hours you need turns your misses into a dated plan, and the exam map explains every objective.

Chapter 5 of the book has you rate yourself on all 27 V8 objectives, and Appendix G adds 16 more timed questions mapped to them.

Your next step
  1. Answer all ten questions in 10 minutes, counting only your first choice.
  2. Write down the V8 objective behind each miss and rate yourself from 1 to 5 on it.
  3. Check that your practice-test source names SY0-701 or SY0-801 and includes performance-based practice.
  4. Set up two virtual machines and a log viewer for performance-based practice.

Questions readers ask

Are these real Security+ exam questions?
No. They were written for this page and are not CompTIA questions. Each is mapped to a V8 objective and its closest V7 objective, so they suit either version. Use them to find weak objectives, not to predict the wording you will see.
What practice-test results show I am ready?
No single score does. Look for consistent results across two or three full practice exams, no domain far behind the others and confidence with performance-based tasks. Book when that pattern holds, not after one good result.
How do I choose a practice-test source?
Choose one and use it thoroughly. Before paying, check that it names your exam code, SY0-701 or SY0-801, follows the official objectives, includes performance-based practice as well as multiple choice and states its refund policy in writing.
Do V7 practice questions still work for V8?
Many individual questions still apply, because most objectives map across. A V7 bank still uses V7 weights and misses two changes. V8 adds objective 2.6 on AI threats, and mitigation moves to objective 4.1. For V8, use a bank built on SY0-801.
Sources

This guide is independent and is not endorsed by CompTIA. Facts change: confirm them on the official page before you act.