CompTIA Security+ guided activity library
Practice Applied Reasoning, Not Just Definitions.
Every activity is a scored, step-by-step guide using real (fictional or sanitized) logs, scan output, headers, and scenarios — reading authentication logs, triaging a vulnerability scan, sequencing an incident response, and more. Nothing here targets, evades, or attacks a real system.
General Security Concepts
Inspecting a Certificate Chain
Real troubleshooting and security reviews constantly involve reading certificate details — expired certificates and broken chains are among the most common real-world causes of 'why won't this connection work' tickets.
Preview →Comparing File Hashes to Verify Integrity
Verifying a download's hash against the vendor's published value is one of the simplest, most direct real-world applications of hashing — and a skill most IT professionals never actually practice.
Preview →Classifying Security Controls at a Regional Retailer
The exam constantly asks you to classify a NEW, never-seen-before control on two independent axes at once — this only works if you can apply the definitions to unfamiliar examples, not recall a memorized list.
Preview →Diagnosing CIA and AAA Failures at a Financial Company
Nearly every scenario question on this exam is secretly asking which leg of CIA or which AAA function is actually in play — practicing this diagnosis on realistic incidents is exactly the applied skill being tested.
Preview →Reviewing a Change Ticket for Missing Controls at a School District
Recognizing exactly which element of change management is missing from a real ticket — not just knowing the checklist exists — is the applied skill the exam's scenario questions test.
Preview →Threats, Vulnerabilities, and Mitigations
Reading Authentication Logs to Spot an Attack Pattern
Recognizing an attack pattern from raw log evidence — not just a term definition — is exactly the applied-reasoning skill the exam's scenario questions test, and the exact skill a real SOC analyst uses every shift.
Preview →Recognizing Phishing Indicators in a Raw Email
Most real-world compromises still start with a human clicking something — reliably recognizing phishing indicators is one of the highest-leverage individual skills anyone in IT or security can have.
Preview →Profiling the Threat Actor Behind a Government Contractor Intrusion
The exam almost never tells you the actor type outright — it describes behavior and expects you to infer the profile, exactly the skill a real analyst uses when triaging an incident with an unknown source.
Preview →Categorizing Vulnerabilities Found in a Manufacturing Company's Security Audit
Correctly categorizing a vulnerability points directly at how to fix it — a misconfiguration and a zero-day require completely different responses, even though both might show up as 'a finding' on the same scan.
Preview →Choosing Mitigations for a Hybrid Cloud Organization's Risk Register
The exam tests choosing the RIGHT mitigation for a specific described problem, not reciting the whole toolbox — this is exactly the applied decision a security analyst makes when prioritizing remediation work.
Preview →Security Architecture
Building Firewall Rule Logic for a Small Retailer
Firewall rules are evaluated top-to-bottom with first-match-wins logic, and a rule set that looks correct at a glance can still have a dangerous ordering mistake — this is a genuinely common, genuinely serious real-world error.
Preview →Designing a Segmented Network for a Small Medical Clinic
Designing segmentation from scratch — not just recognizing a diagram — is exactly the kind of applied, decision-making skill Security+ scenario questions test, and a genuinely common real consulting task.
Preview →Classifying a Small Business's Data Inventory
You can't protect data you haven't first classified — this exercise builds the practical judgment behind an activity every real data-protection program depends on.
Preview →Building a Recovery Plan for an MSP's Client Portal
RTO and RPO numbers only matter if you can actually evaluate whether a real backup/recovery plan satisfies them — the exam tests this evaluation directly, not just the definitions.
Preview →Security Operations
Triaging a Vulnerability Scan Report
Real vulnerability management teams face far more findings than they can fix at once — prioritizing correctly (not just by raw score) is a genuinely high-stakes, frequently tested judgment call.
Preview →Sequencing an Incident Response for a Ransomware Outbreak
Getting the SEQUENCE right during a real incident is often more important than any single technical action — reconnecting a still-infected system too early can undo hours of correct work.
Preview →Building an Access-Control Matrix by Role
Building an access-control matrix from scratch — deciding what each role actually needs, not just what's convenient to grant — is a genuinely common real IAM task and a direct, practical application of least privilege.
Preview →Evaluating HTTP Security Headers on a Web Response
Security headers are a fast, free, and commonly-overlooked application-hardening layer — this is a genuinely practical skill for reviewing any web application's basic security posture in minutes.
Preview →Auditing Asset Disposal at a Manufacturing Company
A huge share of real-world data breaches trace back to improperly disposed hardware — recognizing exactly which lifecycle step failed is the applied skill that prevents the next one.
Preview →Triaging SIEM Alerts at an MSP's Security Operations Center
SIEM and SOAR are tested together constantly, and confusing 'detects and alerts' with 'automatically responds' is one of the most common mix-ups on the exam — and in real SOC operations.
Preview →Hardening Email Security for a Remote Workforce Organization
SPF, DKIM, and DMARC are tested together constantly, and business email compromise remains one of the costliest, most common real-world attack categories — getting this exactly right matters far beyond the exam.
Preview →Designing Automation Guard Rails for a Managed Service Provider
The exam tests an honest, two-sided view of automation — real benefits AND real costs — and this is exactly the judgment call a security team makes before automating any sensitive process.
Preview →Building a Defensible Investigation from Multiple Data Sources
The exam consistently presents a single data source and asks whether it's enough to prove a conclusion — recognizing the limit of one source, and what additional source would close the gap, is exactly the applied skill being tested.
Preview →Security Program Management and Oversight
Performing a Basic Risk Assessment
Turning 'this seems risky' into an actual quantified business case is the exact skill that lets a security recommendation survive a conversation with finance leadership.
Preview →Building a Governance Hierarchy for a Government Contractor
An auditor asking 'show me evidence this is followed' is exactly why the governance hierarchy exists — a policy alone, with nothing measurable or executable beneath it, gives an auditor nothing concrete to check.
Preview →Building a Vendor Risk Questionnaire for a Retailer
Your security posture is only as strong as your weakest connected vendor — this is a leading real-world source of major breaches, and this exercise mirrors the real due-diligence work that prevents it.
Preview →Diagnosing a Compliance-Versus-Security Gap at a Medical Clinic
Passing a compliance audit and being fully secure are related but genuinely different claims — conflating them is one of the most consequential, common misunderstandings in real security programs.
Preview →Choosing the Right Audit or Assessment for a Financial Company
Audits, internal self-assessments, and penetration tests answer genuinely different questions — choosing the wrong one for a stated goal wastes real budget and gives leadership false confidence.
Preview →Redesigning a Security Awareness Program at a School District
Security awareness is one of the highest-leverage, most consistently under-invested parts of a security program — recognizing WHY a training program isn't working is the applied skill that actually fixes it.
Preview →