Ad slot · leaderboard (728×90 / responsive)Manual unit, below nav — clear of every quiz tap target
Home/ CompTIA Security+/ Domain 4: Security Operations
Free · SY0-701 · Domain 4 of 5

CompTIA Security+ Domain 4: Security Operations

28% of the SY0-701 exam — the largest domain
Practice — Domain 4

Interactive Domain 4 practice questions load here — covering incident response, monitoring, IAM. Each answer is revealed with a full explanation and its source after you respond.

JavaScript is required for the interactive quiz. You can still browse all of CompTIA Security+ while JavaScript loads.

Want all five domains under exam conditions? Take a full 90-question mock →

Ad slot · in-content rectangle (336×280 / responsive)Below the quiz card, inside the article body — well clear of answer buttons

About this domain

Security Operations is where the day-to-day work of defending an enterprise actually happens, and on the SY0-701 exam it carries the most weight of any single area at 28% of your score. That makes Domain 4 the one section you cannot afford to coast through. Expect questions that put you in the analyst's chair: deploying a secure baseline to 200 fresh Windows workstations, deciding how to sanitize drives that held regulated data before they move to a test lab, or reading a CVSS v3.1 base score to decide which finding gets patched first.

The domain spans a wide and practical set of skills. You will hardening computing resources and mobile deployment models, asset management from acquisition through certified disposal, vulnerability management with CVE and CWE catalogs, and alerting and monitoring built on SIEM log aggregation, flow data, and agent versus agentless collection. It also folds in identity and access management — authentication factors, federation, SSO, and SAML — plus automation and orchestration through SOAR playbooks and CI/CD guardrails.

Incident response ties it together: knowing the process phases, respecting order of volatility when collecting evidence, and pulling firewall logs and other data sources to support an investigation. The questions below mirror that scenario-driven style so you build the judgment the exam rewards.

What Domain 4 covers

Domain 4 quick glossary

The terms that show up most on Domain 4 questions — one line each.

Secure baselineA known-good, hardened configuration enforced consistently across systems before they go live.
Data sanitizationSecurely wiping or destroying data on retired media so it cannot be recovered.
CVSSScoring framework whose base metrics (like Attack Vector) rank a vulnerability's severity for prioritization.
CVE vs CWECVE catalogs specific known vulnerabilities; CWE catalogs the underlying weakness types behind them.
SIEMA platform that aggregates and correlates logs from many sources to surface security alerts.
DLPData loss prevention controls that detect and block unauthorized exfiltration of sensitive data.
Federation / SSOTrust between identity providers (often via SAML) that lets one login grant access across multiple services.
SOARSecurity orchestration, automation, and response tooling that runs playbooks to handle alerts at machine speed.
Order of volatilityThe sequence for collecting evidence, capturing the most fleeting data (memory, cache) before stable storage.

Keep going

Practice the other domains, or go deeper with the full study materials.