All AppsNeuron Trainer HealthNeuron Trainer TradesNeuron Trainer TechNeuron Trainer NextNeuron Trainer MotionStudy GuidesTechnologyRoadmapPricingReviewsAboutFAQFor OrganizationsSupportGet the Apps →
Free CompTIA Security+ practice · Tech

CompTIA Security+ practice test: 4 free SY0-701 questions and the verified facts

CompTIA Security+ (SY0-701) is a maximum of 90 questions in 90 minutes, and you pass at 750 on a 100–900 scale, above the 720 CompTIA publishes for Network+. Security operations is the largest domain at 28%. CompTIA recommends Network+ and two years of experience, lists Security+ under DoD Manual 8140.03, and renews it every three years.

Formally the CompTIA Security+ (SY0-701). Awarding body: CompTIA. Neuron Trainer is an independent study app and is not affiliated with, endorsed by or sponsored by the organization that owns this exam.

CompTIA Security+ at a glance, with the source for every line

Every row below is quoted from a document published by CompTIA and carries the date we checked it. Where CompTIA publishes nothing, the row says so instead of quoting a number from somewhere else.

Exam code
SY0-701 (V7).Source: CompTIA, Security+ certification page, verified 7 August 2026
Questions
Maximum of 90, a mix of multiple choice and performance-based questions.Source: CompTIA, Security+ certification page, verified 7 August 2026
Time limit
90 minutes.Source: CompTIA, Security+ certification page, verified 7 August 2026
Passing score
750 on a scale of 100–900.Source: CompTIA, Security+ certification page, verified 7 August 2026
Recommended experience
CompTIA Network+ and two years of experience in a security or systems administrator role.Source: CompTIA, Security+ certification page, verified 7 August 2026
How long it lasts
Three years from your certification date, renewable with continuing education units.Source: CompTIA, Certification Renewal Policy, verified 7 August 2026
Version lifecycle
CompTIA retires a Security+ version roughly three years after launch, and lists SY0-701’s estimated retirement as 2026. Confirm the live exam code on CompTIA’s page before you book.Source: CompTIA, Security+ certification page, verified 7 August 2026
DoD approval
CompTIA lists Security+ among the seven CompTIA certifications approved under DoD Manual 8140.03, mapped to work roles including Cyber Defense Analyst, System Administrator and Network Operations Specialist.Source: CompTIA, Framework Alignment, verified 7 August 2026
If you fail
No waiting period between the first and second attempt. Before a third or any later attempt you must wait at least 14 calendar days from your last attempt. CompTIA states you pay the exam price each time, with no free retests or retake discounts.Source: CompTIA, Certification Retake Policy, verified 7 August 2026
Network+ passing score, for comparison
CompTIA publishes 720 on a scale of 100–900 for Network+ (N10-009), against 750 for Security+.Source: CompTIA, Network+ certification page, verified 7 August 2026
A+ passing scores, for comparison
CompTIA publishes 675 for A+ Core 1 (220-1201) and 700 for Core 2 (220-1202), on a scale of 900.Source: CompTIA, A+ Core 1 and Core 2 V15 page, verified 7 August 2026
Pass rate
Not published by CompTIA. CompTIA does not publish a Security+ pass rate. Figures quoted on prep sites are estimates with no CompTIA source behind them.Checked against: CompTIA, Security+ certification page, verified 7 August 2026
Raw number of correct answers needed
Not published by CompTIA. CompTIA does not publish the raw number of correct answers this exam requires. It publishes the scaled passing score only, and gives no conversion between that scaled score and a number of questions.Checked against: CompTIA, Security+ certification page, verified 7 August 2026
Exam price
Not published by CompTIA. CompTIA states no exam price on the Security+ certification page. Vouchers are sold separately through the CompTIA Store rather than priced on the certification page, so there is no single published figure to quote.Checked against: CompTIA, Security+ certification page, verified 7 August 2026

Always verify: CompTIA lists SY0-701’s estimated retirement as 2026 and sets voucher pricing per region. Confirm the live exam code and price at comptia.org before you book.

What CompTIA publishes as the official CompTIA Security+ blueprint

These weights are CompTIA's, quoted from the source below. They are the only weights on this page that describe the real exam.

Published by CompTIA and verified on 7 August 2026.
AreaWeight CompTIA publishes
General security concepts12%
Threats, vulnerabilities and mitigations22%
Security architecture18%
Security operations28%
Security program management and oversight20%

Scroll the table sideways to see every column.

Source: CompTIA, Security+ certification page, verified 7 August 2026.

What our CompTIA Security+ question bank covers

What this app's question bank covers — our own category shares across 650 questions, not CompTIA's published blueprint.
CategoryQuestions in our bankShare of our bank
General Security Concepts
CIA triad, AAA, zero trust, control types, change management
7812%
Threats, Vulnerabilities & Mitigations
Threat actors, attacks, IoCs, mitigations, malware, social engineering
14322%
Security Architecture
Secure design, encryption, PKI, segmentation, cloud/IoT/OT, resilience
11718%
Security Operations
Hardening, SIEM, EDR, IR, digital forensics, vulnerability management
18228%
Security Program Mgmt & Oversight
Governance, risk management, compliance, audits, awareness
13020%

Scroll the table sideways to see every column.

Try it

4 questions from our CompTIA Security+ bank

Questions from our Security+ bank, weighted the way CompTIA weights SY0-701, with a full explanation on each.

CompTIA Security+ · Free practice Every answer explained. No signup, no email wall.
  1. Question 1 of 4

    A hospital's disaster recovery plan specifies that its electronic health records system must be back online within 4 hours of an outage, and that no more than 15 minutes of transaction data can be permanently lost. The 15-minute figure represents which metric?
    Answer and explanation

    Correct answer: Recovery point objective (RPO)

    RPO defines the maximum acceptable amount of data loss measured in time, dictating how frequently backups or replication must occur; 15 minutes means backups must run at least that often. RTO, the 4-hour figure in this scenario, measures how quickly the system itself must be restored to operation, not data loss. MTTR measures the average time to fix a failed component after it breaks, an operational metric rather than a planning target. MTD is the total time a business process can be unavailable before causing unacceptable harm, distinct from the data-loss-focused RPO.

  2. Question 2 of 4

    An accounts payable clerk receives an email from the CFO's actual, unspoofed email address instructing an urgent wire transfer to a new vendor account. Investigation later reveals the CFO's mailbox had been compromised by an attacker. Which attack does this scenario MOST closely describe?
    Answer and explanation

    Correct answer: Business email compromise

    Business email compromise (BEC) occurs when an attacker gains control of a legitimate corporate email account and uses that trusted access to issue fraudulent financial instructions, as happened when the CFO's real mailbox was hijacked. Typosquatting relies on look-alike domain names, not a compromised legitimate account. Smishing is delivered via SMS text messages, not email. A watering hole attack compromises a website frequented by the target group, which is unrelated to hijacking an executive's mailbox directly.

  3. Question 3 of 4

    A browser needs to verify in near real-time whether a website's certificate has been revoked without downloading a large list of revoked certificates. Which protocol BEST fulfills this need?
    Answer and explanation

    Correct answer: Online Certificate Status Protocol (OCSP)

    OCSP allows a client to query a certificate's revocation status in real time from an OCSP responder, returning a quick good, revoked, or unknown answer without downloading an entire list. A CRL requires downloading and parsing a potentially large, periodically updated list, introducing latency and staleness. SSL is the deprecated predecessor to TLS and is unrelated to revocation checking. LDAP is a directory access protocol, not a revocation-checking mechanism.

  4. Question 4 of 4

    Which element of the CIA triad ensures that data is accurate and has not been altered by an unauthorized party?
    Answer and explanation

    Correct answer: Integrity

    Integrity guarantees that data remains accurate, consistent, and unmodified except by authorized processes, typically verified with hashing (SHA-256) or digital signatures. Confidentiality is wrong because it protects data from unauthorized viewing, not tampering. Availability is wrong because it ensures systems and data are accessible when needed, unrelated to accuracy. Non-repudiation is wrong because it prevents a party from denying an action; it is a separate security goal built on integrity and authentication, not part of the core CIA triad.

What actually trips people up on Security+

Security operations is 28% and it is the boring half

The biggest domain is hardening, SIEM, EDR, incident response, forensics and vulnerability management. Candidates arrive wanting to learn attacks and spend their time on threats, which is only 22%. Give operations the largest share of your study time because it has the largest share of the exam.

RPO and RTO get swapped under time pressure

Recovery point objective is how much data you can afford to lose, measured in time, so it sets your backup frequency. Recovery time objective is how long you have to get the system back. If the question mentions a quantity of data, it is RPO. If it mentions being back online, it is RTO.

Program management is a fifth of the exam and it is not technical

Governance, risk, compliance, audits and awareness training carry 20%. There is no packet capture here. It is policy vocabulary, and the answers reward the choice that documents a decision and assigns an owner.

Tool categories overlap on purpose

SIEM aggregates and correlates logs from many sources. EDR watches endpoints and can isolate one. SOAR automates the response playbook. DLP stops exfiltration. Every one of those will appear as a distractor for the others, and the question turns on one verb.

The attack that uses a real, uncompromised-looking account

Business email compromise is not phishing with a lookalike domain and it is not typosquatting. It is a genuine mailbox that an attacker now controls. When the scenario says the address was real and unspoofed, stop looking for a spoofing answer.

A 5-week study plan

Five weeks. Our Security+ bank holds 650 questions distributed across the five official domains, with 182 of them in security operations because that is where the exam is heaviest.

Week 1: general concepts and vocabulary

Only 12% of the exam, but everything else is built on it. CIA triad, AAA, zero trust, control types, change management. Get the vocabulary exact, because the distractors are built from near-synonyms.

Week 2: threats, vulnerabilities and mitigations

22%. Threat actors, attack types, indicators of compromise, malware families and social engineering. This is the fun part, and it is not the biggest part.

Week 3: security architecture

18%. Secure design, encryption and PKI, segmentation, cloud and OT, resilience. OCSP versus CRL, RAID levels and where a certificate revocation check actually happens.

Week 4: security operations, the 28%

Give this domain a full week on its own. Hardening, SIEM and EDR, incident response phases, digital forensics, vulnerability management lifecycle.

Week 5: program management, then simulate

Drill the governance material, then sit 90-question, 90-minute simulations until the per-domain breakdown stops finding a weak spot. Book the exam for the day your readiness score goes green.

Is Security+ hard?

Security+ is a breadth exam with a higher bar than its neighbors: 750 out of 900, against the 720 CompTIA publishes for Network+ and the 675 for A+ Core 1. It is not conceptually hard. It is unforgiving about coverage, because 28% is security operations and 20% is governance and risk, so a candidate who has only studied attack technique walks in prepared for less than half of it.

CompTIA does not publish a Security+ pass rate, and the percentages that circulate on prep sites have no CompTIA source behind them. We are not going to invent one either.

What we can tell you honestly is our own bank’s shape. Of its 650 questions, 216 sit at difficulty 3 and 181 at difficulty 4, and the largest category is security operations with 182 questions, followed by threats and vulnerabilities with 143, mirroring the real 28% and 22% weightings.

Cost is the other pressure, and it is the argument for drilling before you book. CompTIA sets no waiting period before a second attempt, but a third or any later attempt means waiting at least 14 calendar days, and it states you pay the exam price each time with no free retests and no retake discounts.

How the CompTIA Security+ differs from the exams beside it

Security+ is on CompTIA’s list of certifications approved under DoD Manual 8140.03, mapped to work roles from Cyber Defense Analyst to System Administrator, which is why it turns up in so many job specs and HR filters. It passes at 750, higher than the 720 CompTIA publishes for Network+ and the 675 for A+ Core 1, on the same 900-point scale. And unlike CySA+, which assumes you already work in a SOC, Security+ is written for someone about to. Half the exam is operations and program management, not attack technique.

Questions people actually ask about the CompTIA Security+

What is a passing score on CompTIA Security+?

750 on a scale of 100 to 900. The scale does not start at zero, so 750 is not 83%. CompTIA does not publish how many questions that equals.

How many questions is the Security+ exam?

CompTIA publishes a maximum of 90 items in 90 minutes. The word doing the work is “maximum”: some forms run shorter, and the paper mixes performance-based simulations in with the multiple choice.

Is Security+ hard?

It is a broad first security certification rather than a deep one. The difficulty is coverage: 28% is security operations and 20% is governance and risk, so a candidate who only studies attacks walks in underprepared for half the paper.

Do you need Network+ before Security+?

No. CompTIA recommends Network+ and two years of security or sysadmin experience, but neither is enforced. You can book Security+ as your first CompTIA exam.

How long does Security+ last?

Three years from your certification date. You renew with continuing education units, and earning a higher CompTIA certification such as CySA+ renews it automatically.

How long should you study for Security+?

Five weeks is a realistic plan from a standing start: roughly one week per domain, with the last spent on timed simulations. Give security operations a full week of its own, because it is 28% of the paper and the half most candidates skim.

What happens if you fail Security+?

CompTIA sets no waiting period between your first and second attempt. Before a third or later attempt you wait at least 14 calendar days, and you pay the exam price every time: CompTIA offers no free retests and no retake discounts. That cost is the argument for drilling to a green readiness score before you book.

Are these real Security+ exam questions?

No. Every one of the 650 is written in-house from CompTIA’s published SY0-701 objectives. Recalled live items breach the candidate agreement and can get a certification revoked, so we do not use them. Ours carry an explanation covering why each distractor fails, which a real exam never gives you.

Practice another Tech exam

IT, cloud & cybersecurity. Every one of these pages is built the same way: sourced facts, an honest admission where the sponsor publishes nothing, and free practice questions.

The app

The CompTIA Security+ app is still in development

The Security+ app carries 650 questions across the five SY0-701 domains at CompTIA’s own weights, each with an explanation covering why the right answer is right and why each distractor fails. It includes Smart Quiz, Topic Drill, a fixed-length 90-question Exam Simulator on a 90-minute clock, and an AI tutor set up for security material. It is not on the App Store yet.

  • Smart Quiz — keeps returning to the categories you keep missing
  • Topic Drill — one category at a time, on its own
  • Exam Simulator — a fixed-length timed paper (90 questions in 90 minutes, as this app sets it). It does not get harder as you go; the length and the mix are fixed.
  • AI tutor — re-explains any question in plain English
  • Progress tracking, reported per category
  • Study reminders
  • Light and dark themes

The app calls you ready at 83% on its own simulator. That is an in-app practice target we chose, not CompTIA's passing standard.

Not on the App Store yet. This one is still in development, so there is nothing to download today. The practice questions above are the whole of what we can give you right now, and they are free and complete. See where it sits in the queue, or browse the apps that are live.

Walk in knowing operations, not just attacks.

The Security+ app is in development. The practice questions and verified SY0-701 facts on this page are free now, with no signup and no email wall.

See the apps that are live

Sources, and when we last checked them

This page was last reviewed on . The 11 facts quoted above were last checked against their sources on . Where CompTIA publishes nothing, the table above says so rather than guessing.

CompTIA and Security+ are trademarks of CompTIA, Inc. Neuron Trainer is an independent study aid and is not affiliated with, endorsed by, or sponsored by CompTIA.