Interactive Domain 4 practice questions load here — covering incident response, monitoring, IAM. Each answer is revealed with a full explanation and its source after you respond.
JavaScript is required for the interactive quiz. You can still browse all of CompTIA Security+ while JavaScript loads.
Want all five domains under exam conditions? Take a full 90-question mock →
Security Operations is where the day-to-day work of defending an enterprise actually happens, and on the SY0-701 exam it carries the most weight of any single area at 28% of your score. That makes Domain 4 the one section you cannot afford to coast through. Expect questions that put you in the analyst's chair: deploying a secure baseline to 200 fresh Windows workstations, deciding how to sanitize drives that held regulated data before they move to a test lab, or reading a CVSS v3.1 base score to decide which finding gets patched first.
The domain spans a wide and practical set of skills. You will hardening computing resources and mobile deployment models, asset management from acquisition through certified disposal, vulnerability management with CVE and CWE catalogs, and alerting and monitoring built on SIEM log aggregation, flow data, and agent versus agentless collection. It also folds in identity and access management — authentication factors, federation, SSO, and SAML — plus automation and orchestration through SOAR playbooks and CI/CD guardrails.
Incident response ties it together: knowing the process phases, respecting order of volatility when collecting evidence, and pulling firewall logs and other data sources to support an investigation. The questions below mirror that scenario-driven style so you build the judgment the exam rewards.
The terms that show up most on Domain 4 questions — one line each.
Practice the other domains, or go deeper with the full study materials.