Ten Security+ scenario questions, and why the runner-up answer loses
Security+ questions reward reading the evidence before naming the answer. Both V7 (SY0-701) and V8 (SY0-801) give you up to 90 questions in 90 minutes, mixing multiple choice with performance-based tasks, and a scaled score of 750 on a 100 to 900 scale passes. Below are ten original scenario questions across all five domains, each explaining why the runner-up loses.
Many Security+ candidates who run short of time are not short of knowledge. They sink twenty minutes into one performance-based question, or pick an answer that is true but misses the problem. Either habit can cost a full-price retake.
How is the exam scored, and how do performance-based questions work?
Both V7 (SY0-701) and V8 (SY0-801) give you up to 90 questions in 90 minutes. You pass with a scaled score of 750 on a scale of 100 to 900. It is not a percentage, so ignore any online "percentage needed to pass".
CompTIA names three formats for both versions:
| Format | What you do |
|---|---|
| Multiple choice, one answer | Choose the single best answer |
| Multiple choice, several answers | Choose every correct answer asked for |
| Performance-based | Solve a task in a simulated environment, such as ordering rules, matching items or reading a log |
Performance-based questions often appear early and take longer. Many candidates flag them and return once the multiple-choice questions are done. Practise them in a home lab, because reading alone will not prepare you.
The ten questions below are original, each mapped to its V8 objective and closest V7 one. V8 is expected on or around 17 November 2026; English V7 retires on 11 June 2027. Allow 10 minutes. Facts were checked against CompTIA's documents in October 2026.
General Security Concepts and threats: four questions
Question 1 · General Security Concepts
A new sign-in page must verify passwords but never be able to recover them, even for administrators. How should they be stored?
A. Encrypted with AES-256, with the key on the application server
B. Hashed with a unique salt and a slow key-stretching algorithm
C. Encoded in Base64
D. Hashed once with SHA-256, without a salt
Show answer
Question 2 · General Security Concepts
VPN users can reach every internal server. An attacker hijacks a contractor's laptop mid-session and moves freely between systems. What would most have limited the damage?
A. Stronger encryption on the VPN tunnel
B. Zero trust, verifying every request to each resource
C. Hiding internal server names from VPN users
D. Digital signatures on internal email
Show answer
Question 3 · Threats, Vulnerabilities and Attacks
Within an hour, 400 accounts each record one failed sign-in, all with the same password from one IP address. None reaches its lockout threshold. What is the most likely attack?
A. Brute force
B. Password spraying
C. Credential stuffing
D. A dictionary attack on one account
Show answer
Question 4 · Threats, Vulnerabilities and Attacks
In an authorised test, typing ' OR 1=1 -- into a web form's username field logs the tester in as the first user in the database. What has she found?
A. Cross-site scripting
B. SQL injection
C. Buffer overflow
D. Directory traversal
Show answer
Security Architecture: two questions
Question 5 · Security Architecture
A company moves its file servers to infrastructure as a service (IaaS) virtual machines. Who must patch their operating systems?
A. The cloud provider
B. The company
C. Both equally, by default
D. Nobody, as the hypervisor isolates them
Show answer
Question 6 · Security Architecture
Ransomware encrypts a file server, including the nightly backups stored on a share on the same server. Which change best protects the next recovery?
A. Nightly full backups instead of incremental ones
B. An offline or immutable backup copy, with regular test restores
C. Rebuilding the server's disks as RAID 5
D. Hourly snapshots on the same volume
Show answer
Security Operations, the heaviest domain: three questions
Question 7 · Security Operations
An access review finds that an employee who moved from finance to marketing six months ago still has payroll access. What should the team do?
A. Disable her account until her manager confirms her role
B. Remove the finance access and fix the role-change process
C. Require multifactor authentication on payroll
D. Note the finding for next year's review
Show answer
Question 8 · Security Operations
A SIEM rule raises hundreds of daily alerts, all administrator sign-ins by a documented backup service account in its scheduled window. Analysts now skim the queue. What should you do?
A. Disable the rule
B. Tune the rule to exclude that account on its known host and schedule
C. Route the alerts to a weekly mailbox
D. Add another analyst to the queue
Show answer
Question 9 · Security Operations
A server suspected of running malware is isolated from the network, and legal action against an insider is possible. What should the analyst do next?
A. Reimage the server to restore service
B. Capture memory, then image the disk, recording the chain of custody
C. Restart the server
D. Run a full antivirus scan on the live system
Show answer
Security Program Management and Oversight: one question
Question 10 · Security Program Management and Oversight
Next week your company signs with a payroll provider that will hold every employee's personal and bank details. What should happen first?
A. Accept the provider's own security statement
B. Assess its security evidence and add audit and breach-notification clauses
C. Run an unannounced penetration test against its systems
D. Sign now and assess it next year
Show answer
What your score tells you
Count first answers only, then sort misses by habit, which repeats across domains.
| If you missed | The habit to fix |
|---|---|
| 1 or 6 | Choosing a strong-sounding tool for the wrong job |
| 2 or 7 | Trusting location or an old role instead of verifying access |
| 3 or 4 | Naming the attack before reading the evidence |
| 5 or 10 | Misplacing responsibility between you and a provider |
| 8 or 9 | Easing today's pain at the cost of detection or evidence |
How many hours you need turns your misses into a dated plan, and the exam map explains every objective.
Chapter 5 of the book has you rate yourself on all 27 V8 objectives, and Appendix G adds 16 more timed questions mapped to them.
- Answer all ten questions in 10 minutes, counting only your first choice.
- Write down the V8 objective behind each miss and rate yourself from 1 to 5 on it.
- Check that your practice-test source names SY0-701 or SY0-801 and includes performance-based practice.
- Set up two virtual machines and a log viewer for performance-based practice.
Questions readers ask
Are these real Security+ exam questions?
What practice-test results show I am ready?
How do I choose a practice-test source?
Do V7 practice questions still work for V8?
- CompTIA Security+ page
- SY0-801 exam objectives
- SY0-701 exam objectives
This guide is independent and is not endorsed by CompTIA. Facts change: confirm them on the official page before you act.