CompTIA SecOT + SOT-001 (V1) Exam Practice Test 5

Reviewed by Editorial Team
The ProProfs editorial team is comprised of experienced subject matter experts. They've collectively created over 10,000 quizzes and lessons, serving over 100 million users. Our team includes in-house content moderators and subject matter experts, as well as a global network of rigorously trained contributors. All adhere to our comprehensive editorial guidelines, ensuring the delivery of high-quality content.
Learn about Our Editorial Process
| By Thames
T
Thames
Community Contributor
Quizzes Created: 11201 | Total Attempts: 9,875,275
| Questions: 25 | Updated: Sep 28, 2026
Please wait...
Question 1 / 26
🏆 Rank #-- ▾
0 %
0/100
Score 0/100

1. A control system device has its unused USB and serial ports physically blocked with locking inserts, preventing anyone from connecting an unauthorized device without a specific removal key. What hardware control does this represent?

Explanation

Hardened physical interfaces, using port blockers or port lockers, physically prevent unauthorized devices from being connected to unused ports without a specific removal key, directly addressing a common and historically significant OT threat vector involving removable media and rogue device connections. Drive encryption instead protects data at rest if a drive is removed, which is a different protection goal from physically preventing a port connection in the first place. Physically hardening unused ports is a simple, low-cost control that can meaningfully reduce the risk of an unauthorized device connection, particularly in physically accessible OT environments where unauthorized personnel access cannot always be perfectly prevented.

Submit
Please wait...
About This Quiz
CompTIA SecOT + Sot-001 (V1) Exam Practice Test 5 - Quiz

This practice assessment focuses on key concepts related to the CompTIA SecOT + SOT-001 (V1) certification. It evaluates your understanding of security operations, incident response, and threat management strategies. This resource is essential for anyone preparing for the certification, helping you to reinforce your knowledge and identify areas for improvement.

2.

What first name or nickname would you like us to use?

You may optionally provide this to label your report, leaderboard, or certificate.

2. During an incident investigation, analysts compare current system documentation and behavior against previously established normal operating parameters, looking for meaningful differences that might indicate compromise. This comparison is described as looking for a ____ from baseline.

Explanation

Looking for a deviation from baseline compares current system documentation and behavior against previously established normal operating parameters, which is exactly why maintaining an accurate baseline in the first place, as part of ongoing security operations, pays off so directly during incident investigation. Without a well-established baseline to compare against, analysts would have a much harder time distinguishing a genuinely meaningful deviation from ordinary variation that might simply reflect normal operational changes over time. This is the same underlying baselining concept used proactively in network security monitoring, now applied retrospectively during an actual incident investigation to help pinpoint exactly when and how a compromise may have begun affecting the system.

Submit

3. A team documents specific step-by-step response procedures for a ransomware scenario, and separately documents step-by-step procedures for routine operational tasks unrelated to incidents. Which two documentation types, respectively, does this describe?

Explanation

A playbook documents step-by-step response procedures for a specific incident scenario, such as ransomware, providing responders with a structured, scenario-specific guide during a high-pressure security event. A runbook instead typically documents step-by-step procedures for routine operational tasks, which may or may not be related to security incidents at all, making it a broader operational documentation tool rather than one specifically focused on incident response. Maintaining both playbooks for likely incident scenarios and runbooks for routine tasks ensures responders and operators alike have clear, pre-established guidance rather than needing to improvise procedures under pressure.

Submit

4. During a major OT incident affecting a manufacturing plant, the response effort must coordinate not just with cybersecurity staff but also with operations, engineering, and maintenance personnel from the affected facility. What incident management consideration does this reflect?

Explanation

Coordination with facilities personnel, including operations, engineering, and maintenance, reflects the reality that a major OT incident's response effort typically cannot be handled by cybersecurity staff alone, since restoring and validating the actual physical process requires deep involvement from the people who understand that specific facility's equipment and operations. This differs from mutual aid, which instead addresses assistance from external peer organizations, rather than coordination with internal facility personnel at the affected site itself. Recognizing upfront that facilities personnel are essential incident response participants, not just cybersecurity staff, helps ensure the response plan actually accounts for how physical operations recovery will be coordinated alongside the cybersecurity response.

Submit

5. A security team notices unusual behavior in control system logs and begins investigating whether this represents an actual security incident or a benign anomaly. Which phase of the PICERL model does this represent?

Explanation

The identify phase of the PICERL model involves investigating unusual behavior to determine whether it actually represents a genuine security incident or a benign anomaly, occurring after the earlier prepare phase but before any containment action is taken. Prepare instead addresses readiness activities completed before any specific incident occurs, such as drafting response plans and conducting exercises, which is a distinct earlier phase from actively investigating a specific suspicious observation. Correctly identifying a genuine incident, rather than either dismissing a real threat as benign or overreacting to a false alarm, is a critical judgment call that shapes everything that follows in the response process.

Submit

6. An asset inventory records not just that a device exists, but specifically which site and which electrical panel it is physically located in, supporting faster response during an incident. What key asset attribute category does this represent?

Explanation

Physical location attributes, including specific site and panel information, support faster response during an incident by allowing responders to quickly locate a specific device physically, rather than only knowing it exists somewhere within a large facility or across multiple sites. Vendor and function attributes instead describe who made the device and what role it performs, which are useful but do not by themselves help a responder physically find the device during a time-sensitive incident. Maintaining detailed physical location attributes as part of routine asset inventory work pays off specifically during high-pressure incident response, when time spent searching for a physical device can meaningfully extend overall incident duration.

Submit

7. A field technician's specialized calibration equipment, used to periodically verify sensor accuracy, must connect to OT systems just like a laptop or tablet would, and therefore requires the same kind of security consideration. What category of device does this represent?

Explanation

Mobile devices in an OT security context extend beyond just phones and tablets to include specialized equipment like calibration tools, which connect to OT systems just as a laptop would and therefore require the same kind of security consideration, such as authentication and posture validation, before being allowed to connect. Overlooking specialized equipment like calibration tools simply because it does not look like a typical mobile device risks leaving a genuine connection point without appropriate security controls. Recognizing the full breadth of what counts as a mobile device in an OT environment, rather than narrowly focusing only on phones and tablets, supports a more complete mobile device security program.

Submit

8. A vulnerability management program uses a software bill of materials to know exactly which open-source components and versions are embedded within a vendor's control system application. Which two statements about this practice are correct?

Explanation

An SBOM provides visibility into embedded components that might not otherwise be apparent from a vendor's product name alone, since a single application can bundle numerous open-source libraries a customer would have no way of knowing about without this kind of disclosure. This visibility directly helps the team quickly determine whether a newly disclosed vulnerability in a specific embedded component actually affects their deployed systems, rather than needing to guess or wait for the vendor to separately confirm applicability. Without an SBOM, a vulnerability buried within an embedded component is often far from obvious, since it would not appear anywhere in the vendor's own marketed product description or version number.

Submit

9. A critical patch requires taking a production line offline, so the team coordinates with operations to schedule this downtime during a planned maintenance window rather than during active production hours. What remediation coordination element does this represent?

Explanation

Scheduling planned downtime coordinates exactly when a production line will be taken offline for a required patch, aligning the disruption with an already-planned maintenance window rather than during active production hours, which minimizes the operational impact of an otherwise necessary security remediation. This differs from testing, which instead validates the patch itself works correctly, and from rollback plan availability, which ensures a recovery path exists if the patch causes a problem, both of which are related but distinct remediation coordination elements. Proactively scheduling downtime around existing maintenance windows, rather than treating every patch as requiring its own separate unplanned outage, reflects mature coordination between security and operations teams.

Submit

10. After noticing an excessive volume of low-value alerts from an intrusion detection system, a security team adjusts its detection rules to reduce noise while still catching genuinely suspicious activity. What activity does this represent?

Explanation

Security management system tuning adjusts detection rules, such as IDS or firewall rules, to reduce excessive low-value alert noise while still catching genuinely suspicious activity, which is an ongoing operational necessity since poorly tuned detection systems can bury genuinely important alerts under a flood of low-value ones. This differs from initially creating an asset inventory, which is a foundational activity that happens earlier and separately from ongoing detection rule tuning. Neglecting to regularly tune detection systems risks a security team becoming desensitized to alerts entirely, potentially causing a genuinely critical alert to be overlooked simply because it is buried among too many low-value ones.

Submit

11. An organization defines a structured approach for deciding what asset and threat data actually needs to be collected, from where, and how often, rather than collecting data ad hoc without clear priorities. What does this structured approach represent?

Explanation

A collection management framework defines a structured approach for deciding what data actually needs to be collected, from where, and how often, ensuring collection efforts are deliberately prioritized rather than ad hoc and potentially missing critical sources or wasting effort on low-value ones. A CMDB instead stores the actual configuration and relationship data once collected, which is a related but distinct concept from the framework that governs collection priorities in the first place. Establishing a deliberate collection management framework helps ensure limited collection and analysis resources are focused on the asset and threat data sources that actually matter most for the organization's specific risk profile.

Submit

12. A security team establishes what normal network traffic patterns look like for a specific OT segment, so that future deviations from this established pattern can be flagged as potentially suspicious. What monitoring practice does this represent?

Explanation

Baselining establishes what normal traffic patterns look like for a specific network segment, providing the reference point needed to recognize future deviations as potentially suspicious, which is especially valuable in OT environments where traffic patterns are often far more predictable and stable than in typical IT networks. This predictability actually makes baselining a particularly powerful OT security monitoring technique, since even a subtle deviation from an established, highly stable pattern can be a meaningful signal of a problem. DNS security and out-of-band management instead address different specific monitoring and management concerns, which are related but distinct from the broader practice of establishing and monitoring against a traffic baseline.

Submit

13. A security tool ensures that even a compromised standard user account cannot escalate to full administrative privileges on an OT workstation, tightly controlling which specific elevated actions are permitted. What capability does this represent?

Explanation

Endpoint privilege management tightly controls which specific elevated actions are permitted, ensuring even a compromised standard user account cannot simply escalate to full administrative privileges, which significantly limits what an attacker could accomplish even after successfully compromising a lower-privileged account. An EPP instead focuses on preventing and detecting malware broadly, which is a different, though complementary, endpoint protection function from specifically controlling privilege escalation. Layering EPM alongside EDR and EPP provides a more comprehensive endpoint security posture than relying on any single one of these capabilities alone.

Submit

14. Before a technician begins a specific maintenance task, the team documents the steps involved, identifies each potential hazard at every step, and defines the precautions needed for each one. What safety document is being created?

Explanation

A job safety analysis documents the steps of a specific task, identifies potential hazards at each individual step, and defines the precautions needed to address each hazard, providing a structured, task-specific safety planning tool. A safety outbrief instead occurs after a task or shift is complete, reviewing what happened, which is a different point in the safety process than the proactive planning a JSA provides beforehand. Conducting a thorough JSA before beginning an unfamiliar or hazardous task helps surface risks that might not be obvious without this kind of deliberate, structured review.

Submit

15. A facility requires personnel to both badge in using a proximity card reader and additionally scan their fingerprint before a door will unlock. What does combining these two access control methods provide?

Explanation

Combining a proximity card reader with fingerprint biometric verification provides layered physical access control, requiring both something the person possesses, the card, and something inherent to them, their fingerprint, which is significantly harder for an unauthorized person to defeat than either single factor alone. This layered approach does not eliminate the value of surveillance as an additional, complementary physical security layer, since access control and surveillance address somewhat different aspects of physical security. Whether this specific combination satisfies a particular regulatory requirement depends on the specific regulation in question, rather than being an automatic guarantee simply because two factors are being used.

Submit

16. An OT system logs every configuration change and access attempt in a way that allows a security team to later reconstruct exactly what happened and who was responsible. What architectural principle does this reflect?

Explanation

Auditability ensures a system logs configuration changes and access attempts in a way that allows later reconstruction of exactly what happened and who was responsible, which is essential both for security investigations and for demonstrating compliance with governance and regulatory requirements. Simplicity and performance instead address different architectural priorities, namely ease of understanding and operational speed, which are related but distinct concerns from the ability to reconstruct historical activity after the fact. Designing for auditability from the outset, rather than trying to add comprehensive logging after an incident has already occurred, ensures the necessary historical record actually exists when it is needed most.

Submit

17. A threat intelligence platform exchanges structured information about indicators, threat actors, and attack patterns using a standardized format specifically designed for expressing this kind of information consistently between different tools and organizations. This format is commonly abbreviated ____.

Explanation

STIX, Structured Threat Information Expression, provides a standardized format for expressing threat information, including indicators, threat actors, and attack patterns, consistently between different tools and organizations, which enables automated sharing and processing of threat intelligence rather than relying on unstructured text reports alone. This standardization is especially valuable when sharing threat intelligence across organizational boundaries, such as through an ISAC, since a consistent format allows recipient organizations to automatically ingest and act on shared intelligence rather than manually reformatting it. Recognizing STIX as a specific structured format, distinct from a general-purpose file type like YARA rules used for malware detection signatures, helps clarify what role each format actually plays in a threat intelligence workflow.

Submit

18. Historical malware variants were specifically used in coordinated attacks against a national power grid, directly causing widespread electricity outages for civilian populations. Which family of events does this describe?

Explanation

BlackEnergy 2 and BlackEnergy 3 were specifically used in coordinated attacks against a national power grid, directly causing widespread electricity outages for civilian populations, representing a landmark direct-impact demonstration of a cyberattack's ability to cause real-world physical consequences at national scale. Colonial Pipeline instead is typically cited as an indirect-impact event, where IT compromise led to a precautionary operational shutdown rather than the malware itself directly manipulating grid equipment. Recognizing BlackEnergy as a direct grid-targeting attack helps illustrate the genuine, demonstrated real-world stakes that justify the level of security attention critical infrastructure sectors like power generation receive.

Submit

19. An analyst reviews satellite photographs of a facility to assess physical security measures like fencing and vehicle barriers as part of a broader threat assessment. What intelligence type does this represent?

Explanation

Imagery intelligence derives insight from visual imagery, such as satellite photographs, which is exactly what is being used here to assess a facility's physical security measures from an external visual perspective. Signals intelligence instead involves intercepting electronic communications, and human intelligence relies on interpersonal sources, both of which are fundamentally different collection methods from analyzing visual imagery. Combining imagery intelligence with other intelligence types, such as OSINT, can provide a more complete threat assessment picture than relying on any single intelligence type alone.

Submit

20. After careful analysis, a risk team decides to purchase a specific insurance policy to cover potential financial losses from a residual risk they have chosen not to address through additional technical controls. What risk disposition option does this represent?

Explanation

Transferring a risk shifts the financial or operational consequence to a third party, such as through an insurance policy, which matches exactly the scenario of purchasing insurance to cover potential losses from a residual risk. Mitigating instead would involve additional technical controls to reduce the risk's probability or impact directly, which the team explicitly decided not to pursue further in this scenario. Avoiding the risk would mean eliminating the underlying activity or exposure entirely, which is a different and often more disruptive disposition option than simply transferring the financial consequence through insurance.

Submit

21. A risk team develops a specific narrative describing how an attacker might compromise a particular system step by step, and separately analyzes how a specific component's failure would cascade through the broader process. Which two risk assessment methods, respectively, does this describe?

Explanation

Scenario-based risk assessment develops a specific narrative describing how an attack might unfold step by step against a particular system, helping stakeholders understand risk in a concrete, relatable way rather than through abstract numerical scores alone. Failure mode and criticality analysis instead examines how a specific component's failure would cascade through the broader process, which is a more engineering-oriented method focused on physical and operational failure propagation rather than adversary behavior specifically. Both methods provide valuable, complementary perspectives on risk, one focused on adversary-driven scenarios and the other on component failure consequences, regardless of whether that failure was caused by an attack or an ordinary equipment fault.

Submit

22. A cybersecurity program regularly educates control engineers on recognizing phishing attempts and understanding safe practices for connecting external devices to OT systems. What program management element does this represent?

Explanation

Training and awareness regularly educates personnel, such as control engineers, on recognizing threats like phishing and understanding safe practices for their specific operational context, building a more security-conscious workforce as a complement to technical controls. A risk registry instead tracks specific identified risks, and metrics and measures track quantitative program performance indicators, both of which are distinct program management elements from ongoing personnel education. Investing in OT-specific training and awareness, rather than generic IT security training alone, helps address threat vectors like social engineering that specifically target OT personnel's unique operational context.

Submit

23. A proposed security control would meaningfully reduce risk but would also introduce enough latency to potentially affect a time-sensitive physical process. The organization must weigh these competing priorities before deciding whether to implement it. What governance concept does this reflect?

Explanation

Balancing security versus operations reflects exactly this kind of tradeoff, weighing a security control's risk reduction benefit against its potential impact on time-sensitive physical operations, which is a governance consideration especially prominent in OT environments where operational and safety priorities can directly conflict with a security measure's overhead. This differs from a purely compliance-driven decision, since balancing security and operations often involves genuine judgment calls beyond simply satisfying a specific regulatory requirement. Explicitly recognizing and documenting this balancing consideration, rather than treating security recommendations as automatically overriding operational concerns, reflects a mature governance approach to OT risk decisions.

Submit

24. A modern industrial communication standard provides a secure, platform-independent way for different vendors' systems to exchange data, evolving from an earlier standard that lacked built-in security. This newer, security-enhanced standard is commonly abbreviated ____.

Explanation

OPC UA, Open Platform Communications Unified Architecture, provides a secure, platform-independent standard for different vendors' systems to exchange data, representing an evolution from the earlier OPC DA standard, which lacked the same built-in security capabilities. This improvement reflects a broader industry trend toward building security into industrial protocols from the ground up, rather than relying entirely on external network controls to compensate for protocols that were never designed with security in mind. Recognizing whether an OT environment uses the older, less secure OPC DA or the newer OPC UA standard is directly relevant to assessing that environment's inherent protocol-level security posture.

Submit

25. A cybersecurity framework specifically categorizes water treatment, energy, and transportation systems as sectors whose disruption would have a severe impact on public safety and the economy. What general concept does this categorization represent?

Explanation

Critical infrastructure sectors specifically categorize industries like water treatment, energy, and transportation whose disruption would have a severe impact on public safety and the economy, which is why these sectors typically receive heightened regulatory attention and security expectations compared to less critical industries. This categorization helps explain why certain OT environments, such as those in power generation or water utilities, often face specific, sector-tailored regulatory requirements that a less critical industry might not encounter. Understanding which critical infrastructure sector a given OT environment belongs to provides important context for anticipating its specific regulatory and threat landscape.

Submit
×
Saved
Thank you for your feedback!
View My Results
Cancel
  • All
    All (25)
  • Unanswered
    Unanswered ()
  • Answered
    Answered ()
A control system device has its unused USB and serial ports physically...
During an incident investigation, analysts compare current system...
A team documents specific step-by-step response procedures for a...
During a major OT incident affecting a manufacturing plant, the...
A security team notices unusual behavior in control system logs and...
An asset inventory records not just that a device exists, but...
A field technician's specialized calibration equipment, used to...
A vulnerability management program uses a software bill of materials...
A critical patch requires taking a production line offline, so the...
After noticing an excessive volume of low-value alerts from an...
An organization defines a structured approach for deciding what asset...
A security team establishes what normal network traffic patterns look...
A security tool ensures that even a compromised standard user account...
Before a technician begins a specific maintenance task, the team...
A facility requires personnel to both badge in using a proximity card...
An OT system logs every configuration change and access attempt in a...
A threat intelligence platform exchanges structured information about...
Historical malware variants were specifically used in coordinated...
An analyst reviews satellite photographs of a facility to assess...
After careful analysis, a risk team decides to purchase a specific...
A risk team develops a specific narrative describing how an attacker...
A cybersecurity program regularly educates control engineers on...
A proposed security control would meaningfully reduce risk but would...
A modern industrial communication standard provides a secure,...
A cybersecurity framework specifically categorizes water treatment,...
play-Mute sad happy unanswered_answer up-hover down-hover success oval cancel Check box square blue
Alert!