CompTIA SecOT + SOT-001 (V1) Exam Practice Test 1

Reviewed by Editorial Team
The ProProfs editorial team is comprised of experienced subject matter experts. They've collectively created over 10,000 quizzes and lessons, serving over 100 million users. Our team includes in-house content moderators and subject matter experts, as well as a global network of rigorously trained contributors. All adhere to our comprehensive editorial guidelines, ensuring the delivery of high-quality content.
Learn about Our Editorial Process
| By Thames
T
Thames
Community Contributor
Quizzes Created: 11201 | Total Attempts: 9,875,275
| Questions: 25 | Updated: Sep 28, 2026
Please wait...
Question 1 / 26
🏆 Rank #-- ▾
0 %
0/100
Score 0/100

1. A control system device verifies that only cryptographically signed, trusted firmware is allowed to load during startup, preventing unauthorized or tampered firmware from running. What hardware security control does this represent?

Explanation

Secure Boot verifies that only cryptographically signed, trusted firmware is allowed to load during a device's startup sequence, preventing unauthorized or tampered firmware from running even if an attacker has managed to modify storage. Drive encryption instead protects data at rest from being read if a drive is physically removed, and port blockers physically prevent unauthorized device connections, both of which are related but distinct hardware controls from verifying firmware integrity at boot. Secure Boot is especially valuable in OT environments where a compromised firmware image could give an attacker persistent, low-level control over a critical device.

Submit
Please wait...
About This Quiz
CompTIA SecOT + Sot-001 (V1) Exam Practice Test 1 - Quiz

This practice assessment focuses on the CompTIA SecOT + SOT-001 (V1) certification, evaluating essential skills in security operations. It covers key concepts such as incident response, threat analysis, and security monitoring. This resource is beneficial for learners preparing for the certification exam, helping to reinforce critical knowledge and enhance readiness... see morefor real-world security challenges. see less

2.

What first name or nickname would you like us to use?

You may optionally provide this to label your report, leaderboard, or certificate.

2. Immediately following the resolution of an incident, the response team holds an informal debrief session to discuss what happened and how the response went, before a more formal lessons-learned report is written. This informal immediate debrief is commonly called a ____ session.

Explanation

A hot wash, sometimes called a debrief, is an informal immediate session held right after an incident's resolution to capture initial impressions and discuss what happened while memories are still fresh, before a more formal postmortem or lessons-learned report is developed later. This immediate informal step complements, rather than replaces, the more thorough formal lessons-learned documentation that typically follows afterward. Holding a hot wash promptly after the incident helps capture details and impressions that might otherwise be forgotten or become less clear by the time a formal report is eventually written.

Submit

3. During an OT incident, an attacker manipulates sensor readings displayed to an operator so the true state of the process is hidden, without necessarily controlling the process directly. What primary impact category does this represent?

Explanation

Manipulation of view specifically describes an attacker altering what is displayed to an operator, such as falsified sensor readings, so the true state of the process is hidden even though the attacker may not be directly manipulating the process itself. This differs from manipulation of control, where the attacker directly alters the actual control commands sent to the process, which is a more direct and often more dangerous form of impact. Recognizing which specific primary impact category an incident represents helps responders correctly prioritize whether operators can currently trust what they are seeing, separate from whether the process itself is currently under attacker control.

Submit

4. During an incident affecting both corporate IT systems and the OT environment, the response team must account for the fact that shutting down an OT system carries physical safety implications that a similar IT shutdown would not. What consideration does this reflect?

Explanation

Coordination between IT and OT during incident response must account for OT-specific nuances, such as the physical safety implications of shutting down a control system, which simply do not apply the same way to a typical IT system shutdown. Failing to account for this difference risks a response action that resolves a cybersecurity concern while inadvertently creating a serious physical safety hazard. This is exactly why OT incident response requires close coordination between cybersecurity responders and OT operations, engineering, and safety personnel who understand these physical consequences.

Submit

5. An OT security team follows a structured incident response model consisting of preparation, identification, containment, eradication, recovery, and lessons learned. What is this model called?

Explanation

The PICERL model structures incident response into preparation, identification, containment, eradication, recovery, and lessons learned, providing a widely recognized sequential framework for managing a security incident from initial readiness through final reflection. The Diamond Model and ICS Cyber Kill Chain instead are threat intelligence frameworks for analyzing an attack's structure, which is a different purpose from PICERL's incident response process orientation. Following a structured model like PICERL helps ensure a team does not skip important steps, such as documenting lessons learned, in the urgency of responding to an active incident.

Submit

6. An asset inventory record for a specific PLC includes its physical location, function, vendor, and whether it is nearing end-of-life support. Which asset management concept does maintaining this level of detail support?

Explanation

Key asset attributes go beyond simple identifiers like an IP address to include details such as physical location, function, vendor, and obsolescence status, providing the detailed context needed for effective risk prioritization and lifecycle planning. Knowing a device is approaching end-of-life, for example, directly informs both vulnerability remediation planning and budget conversations about eventual replacement. Maintaining this level of asset detail is what transforms a simple device list into a genuinely useful asset inventory supporting broader security operations.

Submit

7. Before a USB drive is allowed to connect to any OT system, it is scanned for malware at a dedicated kiosk, and its use is logged and tracked to maintain accountability for where it has been connected. Which two removable media security practices does this describe?

Explanation

Scanning removable media at a dedicated kiosk before it connects to any OT system catches malware before it ever reaches a sensitive control system device, addressing a threat vector that has historically caused real-world OT incidents. Tracking maintains accountability for where a specific piece of removable media has been connected over time, which supports both security investigations and simply understanding how media moves through the environment. Both practices work together as part of a broader removable media security program, alongside other controls like authorization requirements and secure physical storage, to reduce the risk this common threat vector poses in OT environments.

Submit

8. A vulnerability management program cross-references a device's software bill of materials against a government-maintained database of publicly known vulnerabilities to identify applicable risks. Which data source is being used alongside the SBOM?

Explanation

The National Vulnerability Database is a government-maintained repository of publicly known vulnerabilities, and cross-referencing a device's software bill of materials against it identifies which known vulnerabilities apply to the specific components that device actually contains. A risk register instead tracks identified organizational risks generally, and a change control log tracks change requests, neither of which serves as a vulnerability data source the way the NVD does. Combining SBOM data with an authoritative vulnerability database like the NVD is a foundational practice for systematically identifying applicable vulnerabilities across a complex OT environment's many components.

Submit

9. A known vulnerability exists on a legacy PLC that cannot be patched without voiding its safety certification, so the security team instead implements strict network segmentation and enhanced monitoring around that specific device. What remediation option does this represent?

Explanation

Compensating controls address the risk posed by a vulnerability without directly fixing the underlying flaw itself, which is exactly what strict segmentation and enhanced monitoring accomplish when a legacy device cannot actually be patched due to certification constraints. This is a common and necessary remediation approach in OT environments, where patching is often far more constrained than in typical IT environments due to safety certification, vendor support, and uptime requirements. Relying on compensating controls still requires ongoing validation that those controls remain effective, since they do not eliminate the vulnerability itself, only mitigate the risk it poses.

Submit

10. A security analyst reviews logs specifically capturing changes to control system function codes and process values over time, distinct from general network or host security logs. What data source is being analyzed?

Explanation

Control system process logs and change logs specifically capture changes to function codes and process values within the control system itself, providing visibility distinct from general network or host security logs that instead capture network traffic or endpoint activity. Firewall logs and switch syslogs instead reflect network-layer activity, which is valuable but does not directly show what is happening within the control system's own process logic. Reviewing control system logs specifically is essential for detecting unauthorized changes to how the physical process itself is actually being controlled, which general network security logs alone would not reveal.

Submit

11. A security team wants to build an inventory of OT devices on the network without sending any active probes or queries that could disrupt sensitive control system devices. Which discovery method fits this requirement?

Explanation

Passive discovery observes existing network traffic to identify devices without sending any active probes or queries, which is especially important in OT environments where some legacy devices can become unstable or even fail if they receive unexpected active scanning traffic. Active discovery instead sends probes to elicit responses, which can provide more detailed information but carries a higher risk of disrupting sensitive control system devices that were never designed to handle unexpected network traffic. Choosing passive discovery as a first step in sensitive OT environments, only supplementing with careful active discovery where genuinely necessary, reflects a risk-aware approach to asset inventory.

Submit

12. An OT network architecture places a buffer network segment between the corporate IT network and the OT environment, hosting only the specific systems that must communicate across that boundary. What is this buffer segment called?

Explanation

An industrial demilitarized zone is a buffer network segment specifically positioned between the corporate IT network and the OT environment, hosting only the systems that genuinely need to communicate across that boundary while keeping the fully trusted OT network isolated from direct IT exposure. A data diode instead is a specific unidirectional gateway technology that might be used within or alongside an IDMZ architecture, but it is not itself the buffer zone concept as a whole. Implementing a properly designed IDMZ is one of the most fundamental network security architecture decisions for protecting OT environments from threats originating in the more exposed IT network.

Submit

13. A security team deploys a tool on OT endpoints that not only detects suspicious activity but can also automatically isolate an affected host and roll back malicious changes, going beyond simple detection and alerting. Which capability does this represent?

Explanation

EDR provides both detection of suspicious activity and automated response capability, such as isolating an affected host or rolling back malicious changes, going beyond the detection-and-alert-only function of a HIDS. A HIDS instead detects and alerts on suspicious host activity but does not itself take automated remediation action the way EDR does. Deploying EDR on OT endpoints, where careful compatibility and performance testing is especially important given the sensitivity of control system hardware, extends response capability beyond what detection tools alone provide.

Submit

14. A technician needs to perform maintenance on a motor that could unexpectedly restart and cause injury if energized during the work. Which safety procedure specifically addresses this risk?

Explanation

Lockout/tagout procedures physically isolate and lock an energy source, then tag it to warn others, ensuring equipment cannot be unexpectedly re-energized while a technician is performing maintenance. A JSA instead analyzes the job's hazards beforehand to plan safe execution, which is a valuable complementary step but does not itself physically prevent re-energization. PPE reduces injury severity if something goes wrong but does not address the underlying risk of unexpected re-energization the way LOTO directly does.

Submit

15. A facility requires a person to pass through a small enclosed space with two interlocking doors, where the second door cannot open until the first has fully closed, before reaching a sensitive control room. Which two statements about this design are correct?

Explanation

An access control vestibule, sometimes called a mantrap, uses two interlocking doors where the second cannot open until the first has fully closed, specifically to control entry one person at a time. This design directly helps prevent tailgating, since only one person can be present in the vestibule at a time, making it much harder for an unauthorized person to slip in behind someone who has legitimately badged through. A single standard door offers no such control against tailgating, since multiple people can simply walk through together once it is opened.

Submit

16. An OT network design layers multiple independent security controls, including network segmentation, host-based protection, and physical access controls, so that a single control failure does not fully expose the environment. What principle does this reflect?

Explanation

Defense in depth layers multiple independent security controls so that the failure of any single control does not fully expose the environment, which matches combining network segmentation, host protection, and physical access controls together. Compartmentalization is a related but narrower concept specifically about isolating components from each other, which is one contributing technique within a broader defense-in-depth strategy rather than the entire principle itself. Relying on any single control alone, no matter how strong, leaves an OT environment vulnerable if that one control is ever bypassed or fails, which is exactly the risk defense in depth is designed to mitigate.

Submit

17. An attacker initially compromises a corporate IT network, then uses that foothold to move laterally into the OT environment through an inadequately segmented connection between the two networks. This specific threat vector is commonly described as a ____ from IT to OT.

Explanation

Pivoting from IT to OT describes an attacker using an initial foothold in the corporate IT network to move laterally into the OT environment, typically exploiting inadequate segmentation between the two networks. This threat vector highlights why proper network segmentation and monitoring of the IT/OT boundary is such a critical OT security control, since a purely IT-focused compromise can still ultimately threaten physical operations if this pivot path exists. Recognizing this specific threat vector helps security teams justify investment in boundary controls like an industrial demilitarized zone, specifically designed to reduce the risk of this kind of lateral movement.

Submit

18. A historical cyberattack specifically targeted programmable logic controllers to cause physical damage to centrifuges, representing a landmark example of a cyberattack causing direct physical consequences in an OT environment. Which event does this describe?

Explanation

Stuxnet specifically targeted programmable logic controllers to cause physical damage to centrifuges, representing a landmark direct-impact example of a cyberattack causing real physical consequences in an OT environment. Colonial Pipeline and SolarWinds instead are commonly cited as indirect-impact events, where the primary compromise occurred in IT systems but still caused significant operational disruption to OT-dependent operations. Understanding the distinction between direct and indirect historical OT impact events helps illustrate the range of ways a cyberattack can ultimately affect physical operations.

Submit

19. An analyst investigating an intrusion maps out the relationship between the adversary, the infrastructure they used, the capability they employed, and the victim, to better understand the attack's structure. Which threat intelligence framework is being applied?

Explanation

The Diamond Model of Intrusion Analysis structures an intrusion event around four core features, the adversary, infrastructure, capability, and victim, mapping the relationships between them to better understand an attack's structure. The ICS Cyber Kill Chain instead models an attack as a sequence of stages an adversary progresses through, which is a different organizing structure than the Diamond Model's four-part relationship mapping. Choosing the right framework depends on whether the analyst wants to understand relationships between attack elements, as with the Diamond Model, or the sequential stages of an attack, as with a kill chain model.

Submit

20. Before applying a change to a production OT system, the team verifies there is a tested, documented way to revert the system to its prior state if the change causes unexpected problems. What change management element does this represent?

Explanation

Rollback verification during change testing confirms there is a tested, documented way to revert a system to its prior working state if the applied change causes unexpected problems, which is especially critical in OT environments where an untested change could affect physical safety or production availability. This differs from change identification, which instead recognizes that a change is needed in the first place, occurring earlier in the change management process. Skipping rollback verification leaves a team without a reliable recovery path if a change goes wrong, which is a significantly higher-stakes gap in OT environments than in many pure IT contexts.

Submit

21. A risk assessment team rates each identified risk as low, medium, or high based on team consensus and experience, rather than calculating specific probability percentages and dollar-value impact figures. What type of risk assessment does this represent?

Explanation

Qualitative risk assessment rates risks using relative categories, such as low, medium, or high, based on team judgment and experience, rather than calculating precise numerical probabilities and dollar-value impacts the way quantitative assessment does. Quantitative risk assessment instead requires more detailed data to support numerical estimates, which can provide more precise prioritization but demands more effort and data availability to perform well. Choosing between qualitative and quantitative approaches, or blending both, depends on how much reliable numerical data is actually available and how precise the resulting risk prioritization needs to be.

Submit

22. A master service agreement between an OT operator and a security vendor specifies uptime commitments the vendor must meet, and separately references a memorandum establishing mutual understanding of shared responsibilities before the formal contract was finalized. Which two MSA elements, respectively, does this describe?

Explanation

A service-level agreement specifies measurable commitments, such as uptime, that a vendor must meet, providing an enforceable performance standard within the broader master service agreement. A memorandum of understanding instead establishes mutual understanding of shared responsibilities, often preceding or accompanying the formal contract, without necessarily carrying the same binding enforceability as an SLA's specific metrics. Recognizing these as distinct elements within an MSA helps a security program manager understand exactly which commitments are measurable and enforceable versus which reflect a more general shared understanding between parties.

Submit

23. An organization's leadership defines how much risk exposure the company is willing to accept in pursuit of its operational objectives, balancing security investment against business continuity needs. What concept does this represent?

Explanation

Risk appetite defines how much risk exposure an organization is willing to accept in pursuit of its objectives, providing the foundational context that shapes how aggressively the organization invests in security controls versus other priorities. A controls calendar instead schedules recurring control activities, and a maturity assessment evaluates the current state of a security program, both of which are informed by, but distinct from, the organization's underlying risk appetite. Establishing risk appetite explicitly, rather than leaving it implicit, helps ensure security investment decisions align with what leadership has actually agreed to tolerate.

Submit

24. A utility SCADA system uses a serial communication protocol specifically designed for reliable data acquisition across electrical grid and water utility infrastructure, commonly abbreviated ____.

Explanation

DNP3, Distributed Network Protocol 3, is specifically designed for reliable data acquisition across utility infrastructure such as electrical grids and water systems, commonly used between SCADA master stations and remote field devices. It is one of several serial protocols used in OT environments alongside Modbus RTU and Profibus, each suited to particular industry contexts. Recognizing which protocol is in use on a given OT network is important for both interoperability and security monitoring purposes, since each protocol has its own known characteristics and vulnerabilities.

Submit

25. A device in an industrial control system executes a stored program to control machinery based on sensor inputs, cycling continuously in real time. What device type is this?

Explanation

A PLC executes a stored program to control machinery based on real-time sensor inputs, cycling continuously to make control decisions, which is the core function of this device type in an industrial control system. A historian instead archives process data over time for later analysis, and an HMI provides a visual interface for operators to monitor and interact with the process, neither of which directly executes the control logic itself. Recognizing which OT device performs which role is foundational to understanding how an industrial control system actually operates.

Submit
×
Saved
Thank you for your feedback!
View My Results
Cancel
  • All
    All (25)
  • Unanswered
    Unanswered ()
  • Answered
    Answered ()
A control system device verifies that only cryptographically signed,...
Immediately following the resolution of an incident, the response team...
During an OT incident, an attacker manipulates sensor readings...
During an incident affecting both corporate IT systems and the OT...
An OT security team follows a structured incident response model...
An asset inventory record for a specific PLC includes its physical...
Before a USB drive is allowed to connect to any OT system, it is...
A vulnerability management program cross-references a device's...
A known vulnerability exists on a legacy PLC that cannot be patched...
A security analyst reviews logs specifically capturing changes to...
A security team wants to build an inventory of OT devices on the...
An OT network architecture places a buffer network segment between the...
A security team deploys a tool on OT endpoints that not only detects...
A technician needs to perform maintenance on a motor that could...
A facility requires a person to pass through a small enclosed space...
An OT network design layers multiple independent security controls,...
An attacker initially compromises a corporate IT network, then uses...
A historical cyberattack specifically targeted programmable logic...
An analyst investigating an intrusion maps out the relationship...
Before applying a change to a production OT system, the team verifies...
A risk assessment team rates each identified risk as low, medium, or...
A master service agreement between an OT operator and a security...
An organization's leadership defines how much risk exposure the...
A utility SCADA system uses a serial communication protocol...
A device in an industrial control system executes a stored program to...
play-Mute sad happy unanswered_answer up-hover down-hover success oval cancel Check box square blue
Alert!