SASERÁ Academy
Security+ SY0-801 · V8 · free practice

Free Security+ SY0-801 practice questions for the new V8 exam

Eight sample questions from the course: EDR alerts, pen test reports, risk tables and access reviews. Answer, then read why every option is right or wrong.

  • V8 objectives
  • AI & LLM threats
  • PBQ-style exhibits
Security+ SY0-801 V8 exam prep course cover

8 free SY0-801 practice questions

Samples taken from the SY0-801 course. Click an option to answer; the explanations appear under every option.

0 of 8 answered · 0 correctEvery option is explained after you answer
Threats, Vulnerabilities, and AttacksQuestion 1 of 8

A SOC analyst reviews the following EDR alert, raised minutes after an accounts payable clerk opened an emailed invoice on workstation WS-2291:

Parent: word processor opened invoice_7781.docm (email attachment)
Child: powershell.exe -nop -w hidden -enc SQBFAFgAIAAoAE4A...
Network: child process connected to 198.51.100.44:443
Persistence: encoded command stored in registry Run key "Updater"
Disk: no executables written; no other documents modified

Which of the following BEST describes this malware?

  • The only network activity is one outbound connection to a single external address, not scanning or spreading to internal hosts. Nothing indicates self-propagation.
  • The alert records that no other documents were modified, so nothing shows the macro infecting files; it simply launched a hidden, encoded command. The document was the delivery method, not a self-replicating virus.
  • Correct. A trusted built-in interpreter ran an encoded command in memory, connected to a remote host, and stored its code in a registry Run key, all without writing an executable to disk. Living off the land this way is the hallmark of fileless malware, which evades file-based antivirus.
  • The hidden-window flag only keeps a console from appearing on screen; it does not hide files or processes from the OS the way a rootkit does. The EDR tool saw the whole process chain.
Why it matters: Fileless malware abuses built-in tools such as scripting shells, runs in memory, and persists in places like the registry, so detection relies on behavior rather than file scans.
Security OperationsQuestion 2 of 8

A security team is reviewing a penetration test report. The findings table and attack narrative include:

P-1 | Default credentials on intranet wiki | Medium
P-2 | SMB signing not required on file servers | Medium
P-3 | Service account with weak, crackable password | High
P-4 | Web TLS certificate expires in 45 days | Low
Narrative: testers logged in to the wiki with default credentials, found the service account's name on a page, cracked its password, and gained domain administrator access within four hours.

Which action should the team prioritize FIRST?

  • SMB signing is worth enforcing, but it played no role in the demonstrated compromise. The number of affected servers does not outweigh a proven path to domain administrator.
  • Correct. Reviewing a penetration test report means reading the attack narrative, not just the ratings. P-1 and P-3 together gave testers domain administrator access in four hours, so breaking that chain addresses the most serious demonstrated risk.
  • Ratings are assigned per finding. Treating P-1 as routine ignores that it was the entry point for the chain, which makes its real impact far greater than a standalone Medium.
  • An expiring certificate needs attention before the deadline, but it is low risk and was not part of the path to domain compromise.
Why it matters: Prioritize findings that chain together into a proven path to critical access, even if their individual ratings are moderate.
Security OperationsQuestion 3 of 8

An auditor asks for evidence that the domain enforces the corporate password policy. The administrator generates this policy report:

Setting | Corporate policy | Domain actual
Minimum length | 14 | 12
Password history | 24 | 12
Lockout threshold | 10 attempts | 15 attempts
Store passwords using reversible encryption | Disabled | Enabled

Which deviation represents the GREATEST risk and should be remediated first?

  • A 12-character minimum is weaker than policy and should be corrected, but 12-character passwords still resist most brute-force attacks. It is a moderate gap compared with recoverable passwords.
  • A threshold of 15 instead of 10 slightly increases the guesses allowed before lockout. That is a small change in online guessing risk.
  • Correct. Reversible encryption stores passwords in a form that can be decrypted back to plaintext, so anyone who obtains the directory database and key can recover every user's actual password. Fix it first, then reset passwords.
  • A shorter history lets users return to old passwords sooner, which is a minor weakening. It does not expose any current passwords.
Why it matters: Settings that make stored passwords recoverable are the most severe deviations from a password policy.
Security Program Management and OversightQuestion 4 of 8

A risk analyst scores four risks. Score = likelihood x impact, each rated 1 to 5. 15 or higher is High, 8 to 14 is Medium, 7 or lower is Low.

Risk | Likelihood | Impact
R1 Phishing leads to BEC | 4 | 3
R2 Flood at the data center | 1 | 5
R3 Unpatched VPN exploited | 3 | 5
R4 Stolen unencrypted laptop | 3 | 2

Which risk should be categorized as High?

  • R2 scores 1 x 5 = 5, which is Low. Maximum impact combined with very low likelihood does not produce a high score.
  • R4 scores 3 x 2 = 6, which falls in the Low band. It would be monitored rather than prioritized.
  • Correct. R3 scores 3 x 5 = 15, which meets the threshold for High. Scoring combines likelihood and impact, and categorization groups the scores so the highest risks are treated first.
  • R1 scores 4 x 3 = 12, which falls in the Medium band. Its high likelihood alone does not make it High.
Why it matters: Risk scoring multiplies likelihood by impact, and categorization groups the scores into bands that drive treatment priority.
Security Program Management and OversightQuestion 5 of 8

During a security assessment, an analyst reviews an EDR alert that the tooling has already mapped to a framework:

Host: FIN-WS-22 (10.4.8.22)
Process: rundll32.exe reading LSASS memory
Tactic: Credential Access
Technique: OS Credential Dumping
Follow-on: Lateral Movement via Remote Services

The assessor wants to use the same framework to measure which adversary techniques the company can detect. Which reference source is being used?

  • CVSS scores the severity of vulnerabilities. The alert describes attacker behavior, not a vulnerability severity score.
  • The Diamond Model analyzes an intrusion through adversary, capability, infrastructure, and victim. It does not catalog named tactics and techniques for measuring detection coverage.
  • The Cyber Kill Chain describes seven sequential phases of an intrusion. It does not use tactic and technique labels such as Credential Access and OS Credential Dumping.
  • Correct. MITRE ATT&CK organizes real-world adversary behavior into tactics (goals) and techniques (how). Assessors use it to map detections and find coverage gaps technique by technique.
Why it matters: MITRE ATT&CK is a knowledge base of adversary tactics and techniques used to map observed behavior and measure detection coverage.
Security ArchitectureQuestion 6 of 8

A cloud engineer runs a drift report against a production environment that is deployed from approved Infrastructure as Code templates:

Resource: sg-web-prod (security group)
Template ingress: tcp/443 from 0.0.0.0/0
Live ingress: tcp/443 from 0.0.0.0/0; tcp/22 from 0.0.0.0/0
Last modified by: console user jdoe
Change ticket: none

Which of the following is the BEST response?

  • Correct. The live security group drifted from the approved code through an untracked console change that exposes SSH to the internet. Reapplying the template restores the secure baseline, and routing changes through the reviewed pipeline prevents repeat drift.
  • Abandoning the template removes the consistency, review, and version history that IaC provides. Manual management is what caused the drift in the first place.
  • Updating the template to match would make an unapproved change permanent and leave SSH open to the entire internet. Drift is corrected toward the approved baseline, not the other way around.
  • SSH would stay open to the internet until the next deployment, and the untracked change would go unaddressed. Drift that creates exposure should be corrected right away.
Why it matters: IaC makes configuration drift detectable; the fix is to restore the approved code and block untracked manual changes.
General Security ConceptsQuestion 7 of 8

During a quarterly access review of a company's ERP system, a reviewer sees the following:

User | Current role | Permissions
akim | AP clerk | Create invoices, View vendors
bsole | AP supervisor | Approve invoices, View vendors
cdiaz | Payroll analyst | View payroll, Run payroll reports
dfox | Sales rep (moved from AP clerk in March) | Create invoices, View vendors, View CRM

Which of the following should the reviewer flag as a least privilege violation?

  • A supervisor approving invoices needs to confirm the vendor being paid, so View vendors supports the approval task.
  • Running payroll reports is a normal duty for a payroll analyst. Restricting it would block legitimate work without removing any unnecessary access.
  • An AP clerk who creates invoices needs to look up the vendors being billed, so View vendors is appropriate.
  • Correct. dfox moved to Sales but still holds Create invoices and View vendors from the old AP role, a classic case of privilege creep. Access reviews exist to catch exactly this.
Why it matters: Least privilege must be maintained over time; access reviews catch privilege creep when users keep permissions from previous roles.
Security ArchitectureQuestion 8 of 8 · choose two

A company is redesigning how its database administrators receive elevated rights. Today, each administrator's single account holds permanent sysadmin rights on every production database.

Which of the following changes BEST align with least privilege access accounts? (Choose TWO.)

  • Correct. Just-in-time elevation grants privileged rights for a defined task and window, with approval and logging, so no account holds standing administrative access.
  • A shared privileged account removes individual accountability and makes it impossible to tell who did what.
  • Correct. Limiting each account to the databases its owner actually supports reduces the blast radius if the account is compromised. Least privilege applies to scope as well as duration.
  • Longer passwords make the accounts harder to guess but leave permanent sysadmin rights in place. The standing privilege is the problem.
  • Adding more sysadmin rights, even on test systems, expands privileges instead of reducing them.
Why it matters: Least privilege access accounts limit both the scope and the duration of elevated rights, often through just-in-time elevation and narrowly scoped admin accounts.

Two courses, 900 SY0-801 questions

No question repeats between the two sets.

SY0-801 Exam Prep: 540 Questions course cover
Set 1 · start here

SY0-801 Exam Prep: 540 Questions

Six timed exams across all five V8 domains, weighted like the real exam.

See the course on Udemy →
SY0-801 Exam Prep Set 2: 360 Questions course cover
Set 2 · second round

SY0-801 Exam Prep Set 2: 360 Questions

Four more timed exams with new scenarios for your final weeks.

See the course on Udemy →

SY0-801 FAQ

What is Security+ SY0-801?

SY0-801 is the V8 version of CompTIA Security+, replacing SY0-701. It keeps five domains, shifts their weights and adds objectives on large language models and AI in threats and vulnerabilities.

What are the SY0-801 domain weights?

General Security Concepts 16%, Threats, Vulnerabilities and Attacks 24%, Security Architecture 19%, Security Operations 27%, Security Program Management and Oversight 14%.

When does SY0-801 launch?

CompTIA is releasing V8 in late 2026. Check CompTIA's site for the exact date in your region before you book.

How many questions and what passing score?

CompTIA has not published final numbers for V8. SY0-701 uses up to 90 questions in 90 minutes with a 750 pass mark, and V8 is expected to follow a similar format.

Should I buy Set 1 or Set 2?

Start with Set 1 (540 questions, 6 exams). Set 2 adds 360 new questions for a second round once you have worked through Set 1.

Not sure which version to take? Read the SY0-701 vs SY0-801 comparison.