security+ practice test Intermediate Practice Exam: Medium Difficulty 2025
Ready to level up? Our intermediate practice exam features medium-difficulty questions with scenario-based problems that test your ability to apply concepts in real-world situations. Perfect for bridging foundational knowledge to exam-ready proficiency.
Your Learning Path
What Makes Intermediate Questions Different?
Apply your knowledge in practical scenarios
Medium Difficulty
Questions that test application of concepts in real-world scenarios
Scenario-Based
Practical situations requiring multi-concept understanding
Exam-Similar
Question style mirrors what you'll encounter on the actual exam
Bridge to Advanced
Prepare yourself for the most challenging questions
Medium Difficulty Practice Questions
10 intermediate-level questions for CompTIA Security+
A healthcare organization is migrating several internal web applications to a public cloud provider. The security team must ensure that no patient data is stored in regions outside the approved country and that new cloud resources cannot be created in unapproved regions. Which approach best meets this requirement?
A security analyst reviews logs and finds multiple successful logins from a single user account occurring within minutes from two distant geographic locations. Immediately afterward, the account initiates mass downloads from a file repository. Which mitigation is the BEST next step to reduce impact while preserving evidence?
A company wants to reduce the risk of credential reuse attacks across SaaS applications. The solution must provide a single identity source, enforce MFA, and allow rapid user deprovisioning when employees leave. Which solution BEST meets these requirements?
A SOC detects a phishing campaign delivering an attachment that, when opened, attempts to contact a newly registered domain and download a second-stage payload. The organization wants to reduce the likelihood of successful execution if a user opens the attachment. Which control provides the BEST defense-in-depth improvement?
A company is designing network segmentation for a manufacturing site. The OT network includes legacy PLCs that cannot be patched frequently. The IT network hosts user workstations and internet access. Which architecture choice BEST reduces risk of lateral movement from IT to OT while still allowing limited monitoring of OT devices?
An organization stores encryption keys in a centralized key management service. An auditor asks how the organization ensures administrators cannot both manage keys and decrypt sensitive data without oversight. Which practice BEST addresses this concern?
A vulnerability scan shows a critical RCE vulnerability on a customer-facing server. The server hosts a legacy application that cannot be patched for two weeks due to vendor constraints. Which compensating control is MOST appropriate to reduce risk during this period?
A company wants to improve detection of credential dumping and suspicious privilege escalation on endpoints. The security team also wants the ability to isolate hosts quickly during an incident. Which solution BEST meets these goals?
A security manager is updating the organization’s incident response plan. Leadership wants to ensure the plan includes clear criteria for when to involve legal counsel, preserve evidence, and notify regulators. Which document component BEST addresses these requirements?
A SIEM rule generates an alert when a user downloads more than 5GB from a cloud storage service. The SOC reports many false positives caused by legitimate backups and engineering builds. The organization wants to reduce false positives without losing the ability to detect exfiltration. What is the BEST adjustment?
Mastered the intermediate level?
Challenge yourself with advanced questions when you score above 85%
CompTIA Security+ Intermediate Practice Exam FAQs
security+ practice test is a professional certification from CompTIA that validates expertise in comptia security+ technologies and concepts. The official exam code is SY0-701.
The security+ practice test intermediate practice exam contains medium-difficulty questions that test your working knowledge of core concepts. These questions are similar to what you'll encounter on the actual exam.
Take the security+ practice test intermediate practice exam after you've completed the beginner level and feel comfortable with basic concepts. This helps bridge the gap between foundational knowledge and exam-ready proficiency.
The security+ practice test intermediate practice exam includes scenario-based questions and multi-concept problems similar to the SY0-701 exam, helping you apply knowledge in practical situations.
Continue Your Journey
More resources to help you pass the exam