Skip to content
CompTIA Security+ and PenTest+

Security+ SY0-701 performance-based questions (PBQs): what to expect and how to practise

Security+ SY0-701 PBQ guide: how performance-based questions work, how they are scored, and four original practice scenarios with worked answers.

LearnCyber editorial team, reviewed by Hackrowd Technology’s penetration testers · · 7 min read

Security+ SY0-701 performance-based questions (PBQs) are short simulations where you do something, such as ordering firewall rules, reading logs or matching controls to threats, instead of choosing one answer from four. They test the same objectives as the multiple-choice questions, so the best preparation is practising those objectives hands-on, then rehearsing the PBQ format with original scenarios like the four in this post.

A ground rule first: every scenario below was written for this post. None of it is real exam content, and nothing here comes from or resembles leaked material. If a site offers “actual PBQs from the exam”, that is a dump, and using it can cost you your certification. We explain why in Exam dumps: why they can cost you your certification.

What is a PBQ on Security+?

CompTIA’s own explainer on performance-based questions describes two kinds:

  • Simulations: an approximation of a tool or environment, such as a firewall, a network diagram or a terminal, with limited functionality.
  • Virtual environments: real virtual machines running actual software.

Security+ uses simulation PBQs. CompTIA states that simulation PBQs have a reset button, that you can skip them and come back later, that there can be more than one valid way to solve them, and that partial credit may be given.

The rest of the exam facts you need: SY0-701 has up to 90 questions in 90 minutes, mixing multiple-choice and performance-based items, and the passing score is 750 on a 100–900 scale. CompTIA does not publish how many PBQs you will get, so don’t trust anyone who claims an exact number.

Version check: CompTIA’s Security+ page says Security+ V8 is expected on or around 17 November 2026. This post covers SY0-701. If you are booking near that date, confirm on CompTIA’s page which version you are sitting and when SY0-701 retires.

What do Security+ PBQs usually look like?

Based on the PBQ formats CompTIA describes and the SY0-701 objectives, expect tasks in these shapes:

Format What you do Objectives it tends to draw on
Configure rules Fill or order a firewall/ACL table Security Architecture (18%)
Analyse logs Read log lines, identify the attack or the compromised host Security Operations (28%); Threats, Vulnerabilities and Mitigations (22%)
Match or drag-and-drop Pair controls, attacks or tools with scenarios All domains
Order steps Put a process such as incident response in order Security Operations
Place components Drag devices or controls into the right zone of a diagram Security Architecture

The weightings are the official SY0-701 domain weights; the remaining domains are General Security Concepts (12%) and Security Program Management and Oversight (20%).

Original practice scenario 1: firewall rules for a fictional fintech

Scenario. Acme Fintech (fictional) has three subnets:

  • DMZ web server: 10.0.10.20
  • Internal database: 10.0.20.30 (PostgreSQL, TCP 5432)
  • Admin workstations: 10.0.30.0/24

Requirements:

  1. Anyone on the internet can reach the web server over HTTPS only.
  2. Only the web server may connect to the database.
  3. Admins may manage the web server and database over SSH.
  4. Everything else is blocked.

The firewall processes rules top to bottom; first match wins. Fill the table.

Worked answer:

# Source Destination Protocol/Port Action
1 Any 10.0.10.20 TCP 443 Allow
2 10.0.10.20 10.0.20.30 TCP 5432 Allow
3 10.0.30.0/24 10.0.10.20 TCP 22 Allow
4 10.0.30.0/24 10.0.20.30 TCP 22 Allow
5 Any Any Any Deny

Why:

  • Rule 1 does not allow TCP 80. The requirement says HTTPS only; if you want HTTP to redirect to HTTPS, that is a separate, deliberate decision.
  • Rule 2’s source is the single web server address, not the DMZ subnet. Least privilege.
  • The explicit deny-all goes last. Put it first and nothing works. That ordering mistake is the most common error in rule-table questions.
  • Common traps: using “Any” as the source for SSH, or opening 5432 to the admin subnet “for convenience” when the requirement didn’t ask for it.

If you would like to see real firewall rules behind this, the same logic in Linux iptables looks like:

sudo iptables -A FORWARD -p tcp -d 10.0.10.20 --dport 443 -j ACCEPT
sudo iptables -A FORWARD -p tcp -s 10.0.10.20 -d 10.0.20.30 --dport 5432 -j ACCEPT
sudo iptables -A FORWARD -p tcp -s 10.0.30.0/24 -d 10.0.10.20 --dport 22 -j ACCEPT
sudo iptables -A FORWARD -p tcp -s 10.0.30.0/24 -d 10.0.20.30 --dport 22 -j ACCEPT
sudo iptables -A FORWARD -j DROP

(A production firewall also needs a rule for return traffic, usually -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT near the top. Exam-style rule tables usually focus on the stated requirements; follow the question’s instructions on return traffic.)

Original practice scenario 2: which attack is in the log?

Scenario. The SOC at Acme Fintech exports these authentication events from the VPN portal. What attack is this, and what single control would most reduce the risk?

2026-10-03 02:14:07 FAIL user=adaeze.o   src=203.0.113.45 reason=bad_password
2026-10-03 02:14:09 FAIL user=tunde.b    src=203.0.113.45 reason=bad_password
2026-10-03 02:14:12 FAIL user=finance01  src=203.0.113.45 reason=bad_password
2026-10-03 02:14:15 FAIL user=helpdesk   src=203.0.113.45 reason=bad_password
2026-10-03 02:14:18 OK   user=intern3    src=203.0.113.45 mfa=not_enrolled
2026-10-03 02:14:21 FAIL user=k.musa     src=203.0.113.45 reason=bad_password

(The usernames belong to fictional accounts in a fictional company.)

Worked answer. Password spraying. One source address tries one or a few common passwords across many accounts, a few seconds apart, to stay under per-account lockout thresholds. A brute-force attack would show many attempts against one account. Credential stuffing would usually show many different source IPs and a mix of real username/password pairs from earlier breaches.

The success is the important line: intern3 logged in with no MFA enrolled. The best single control is enforcing MFA on the VPN for every account. Lockout policy helps less, because spraying is designed to avoid it. A good follow-up in the same question might ask what to do first: disable or reset intern3, review what that session did, and block or watch 203.0.113.45.

Original practice scenario 3: put incident response in order

Scenario. An Acme Fintech laptop starts encrypting files on a shared drive. Put these actions in the order the incident response process expects:

  • A. Restore the shared drive from a clean backup
  • B. Disconnect the laptop from the network
  • C. Hold a review meeting and update the ransomware playbook
  • D. Confirm from EDR alerts and file changes that this is ransomware, not a sync bug
  • E. Reimage the laptop and remove the malicious scheduled task
  • F. Keep tested offline backups and an up-to-date contact list

Worked answer: F, D, B, E, A, C.

That follows the incident response phases listed in the SY0-701 objectives: preparation (F), detection and analysis (D), containment (B), eradication (E), recovery (A), and lessons learned (C). Two classic mistakes: restoring before eradicating (you reinfect the restored data), and pulling power instead of the network cable without thinking about volatile evidence. Your organisation’s playbook decides the latter, but the exam wants you to recognise the trade-off.

Original practice scenario 4: match the control to the problem

Scenario. Match each Acme Fintech problem to the best control. Each control is used once.

Problem Control options
1. Developers keep committing API keys to Git a. Data loss prevention (DLP)
2. A stolen laptop held unencrypted customer exports b. Secrets scanning in the CI pipeline plus a secrets vault
3. Staff email customer card data to personal addresses c. Full-disk encryption
4. A former employee’s account was still active after three months d. Automated deprovisioning tied to HR leaver records

Worked answer: 1-b, 2-c, 3-a, 4-d.

Watch for “almost right” options in matching PBQs. Encryption does not stop an authorised user emailing data out (that is DLP’s job), and a vault without scanning does not catch the key already committed.

How should I approach PBQs on exam day?

  • Read the whole question, then every tab. Simulations often hide requirements in a second tab or a scroll area.
  • Decide your skip rule in advance. Because CompTIA allows skipping simulation PBQs and returning, many candidates answer the multiple-choice questions first and come back with the remaining time. Whatever you choose, leave enough time: a PBQ can take several minutes.
  • Use the reset button when you have muddled the state, not as a reflex.
  • Do the parts you are sure of. Partial credit may be given, so a half-complete correct table beats an empty one.
  • Don’t over-engineer. Answer the stated requirements. Adding “extra security” the question did not ask for can break a requirement.

How to practise PBQs without dumps

  1. Download the official SY0-701 exam objectives from CompTIA’s site and use them as your checklist.
  2. Turn each objective into a task. “Given a scenario, apply security principles to secure enterprise infrastructure” becomes “draw a three-zone network and write its firewall rules”.
  3. Build a tiny lab. One Linux VM is enough to practise iptables, read /var/log/auth.log, and run ss -tulpn. Generate your own failed SSH logins against your own VM, then read the log they produce.
  4. Write your own PBQs in the four shapes above and swap them with a study partner. Writing a good question forces you to understand the objective.
  5. Use legitimate practice products. CompTIA sells official practice and lab products; reputable publishers sell practice exams too. Avoid anything claiming to contain real exam questions.

For where PBQ practice fits in your weeks, see our Security+ study plan, and for the full objective breakdown, the SY0-701 study guide.

Questions

How many PBQs are on Security+ SY0-701?

CompTIA does not publish a fixed number. Prepare as if several will appear.

Are PBQs worth more than multiple-choice questions?

CompTIA does not publish per-question weights. Treat PBQs as important, and use partial credit to your advantage.

Can I skip PBQs on Security+?

Yes. CompTIA states that simulation PBQs, which Security+ uses, can be skipped and revisited.

Are free "Security+ PBQ" downloads safe to use?

Original practice questions are fine. Anything claiming to be from the real exam is a dump and puts your certification at risk.