← All exams
Home · CompTIA Security+ Practice

CompTIA Security+ Practice

Practice for the CompTIA Security+ (SY0-701) cert.

Pass mark 50/65 90 minutes CompTIA How many can I get wrong?
Weak on a topic? Drill just that one till it clicks, then move on.
Free practice questions
Try 3 real CompTIA Security+ Practice questions
Have a go, then reveal the worked explanation. A taster from a bank of 316 original questions — unlock for unlimited drills and full timed mocks.
Q1. Which of the following best describes the security concept of 'non-repudiation'?
  • A.  A user cannot deny having performed an action they took
  • B.  Data is only accessible to authorised parties
  • C.  A system remains available during a failure
  • D.  Data has not been altered in transit
Show answer & explanation
✓ Answer: A. A user cannot deny having performed an action they took
Non-repudiation ensures a party cannot later deny an action, typically achieved through digital signatures and logging. Confidentiality and availability are separate CIA-triad concepts, and integrity refers to data not being altered.
Q2. An attacker sends a flood of TCP SYN packets with spoofed source addresses to a web server, never completing the handshake, until the server's connection table is exhausted. What is this attack called?
  • A.  SYN flood
  • B.  Smurf attack
  • C.  DNS amplification
  • D.  ARP poisoning
Show answer & explanation
✓ Answer: A. SYN flood
A SYN flood abuses the TCP three-way handshake by sending many SYN packets without completing the ACK, exhausting the server's half-open connection queue. A smurf attack instead abuses ICMP broadcast replies, and DNS amplification abuses open DNS resolvers to magnify traffic toward a victim.
Q3. In a serverless (Function as a Service) architecture, which security concern is most unique compared to traditional server-based deployments?
  • A.  Securing ephemeral, short-lived execution environments and function-level permissions
  • B.  Patching the operating system kernel
  • C.  Configuring RAID for storage redundancy
  • D.  Managing physical rack access
Show answer & explanation
✓ Answer: A. Securing ephemeral, short-lived execution environments and function-level permissions
Serverless functions spin up and tear down quickly, so security focuses on least-privilege execution roles, event source validation, and code-level controls rather than OS patching, which the provider manages. RAID and physical rack access are entirely abstracted away from the customer in serverless models.
Exam format (pass mark, question count, timing) verified against CompTIA. Questions are our own, not the official paper.
Start here
Ten questions to see where you stand
Two minutes, no timer, marked the moment you finish with every answer explained. Then you'll know which topics need the work before you sit a full mock.
Exam mode
Full mock exam
65 random questions, real timing, marked against the official pass mark. Different every time.
Create a free account for a full mock
No card needed. A free account unlocks a full timed mock and 3 drills on every exam.
Try it free
Topic drills
Ten quick questions on one topic, marked instantly with explanations.
1 free drill left — then a free account unlocks 3 + a full mock.
General security concepts · 45
Threats, vulnerabilities & mitigations · 46
Security architecture · 53
Security operations · 45
Identity & access management · 49
Cryptography & PKI · 78
CompTIA Security+ Practice — common questions
Frequently asked
How many questions are in the CompTIA Security+ Practice?
The exam has 65 questions. Every Revision Robin mock uses the same 65-question format so your practice matches the real thing.
What is the pass mark for the CompTIA Security+ Practice?
You need 50 out of 65 correct to pass, which is about 77%. Our mocks mark you against this exact threshold.
How long do you get?
The test is timed at 90 minutes. Our full mock runs on the same clock so you can practise your pacing.
Are these the real exam questions?
No. Our questions are original and written to match the current syllabus, so they give realistic practice without copying the official paper. Every answer comes with a plain-English explanation. Always confirm current rules and content with CompTIA.