CompTIA Security+ guideHigh-value skills
Security+ PBQs: How to Prepare for Performance-Based Questions
Performance-based questions reward a repeatable read of a rule, a log, or a sequence. These patterns are original. They are not recalled exam items.
Short answer
CompTIA includes performance-based questions on SY0-701 and does not publish how many you will see or where they sit in the form. Prepare a method: name the asset, name the failure, then pick the control that changes that failure. The examples below are original teaching patterns. They are not recalled exam items. Passy’s free web set cannot draw a PBQ. It can only ask the same kind of decision in multiple choice.
What you can know in advance
SY0-701 includes multiple-choice and performance-based questions. CompTIA does not state that a fixed number of PBQs always appear first, and this page will not pretend otherwise. Candidate forums are full of people describing screens they think they saw. Those descriptions are not a source for practice content. Anything below was written for this guide.
The method is the same even when the screen changes.
- Say what asset is in front of you (a host, a rule list, a person, a log).
- Say what is going wrong, in one clause.
- Reject controls that would fix a different clause.
- Apply the smallest change that answers the clause you named.
Five original patterns
Firewall rule. A rule list allows any address to reach TCP 443 on a web server, and a later rule denies everything. An attacker is reading a file share that was never meant to be public. The 443 allow rule is not the hole. Look for an allow that matches the file-share service, or a rule ordered so that a broad allow wins. Changing the web server’s certificate does not close a file share.
Log line. A synthetic sequence shows two failed logins and then a new administrator account. The failed logins are context. The new administrator is the decision. More of this kind of read is in the log guide.
Identity choice. A contractor needs access to one shared folder for a week. The wrong completion is a standing domain-admin account. The fitting completion is a time-bounded, least-privilege grant, then removal. Two passwords are not multi-factor authentication. A password plus a possession factor is.
Segmentation. A compromised point-of-sale register can reach the office file server. The fix that matches is a boundary between those networks, not a longer email disclaimer. Segmentation limits paths. It does not remove the malware by itself, so you still isolate the register.
Incident order. You have a spreading encryption process and a leader who wants a statement to customers. Contain the host before you draft the statement. Communication matters, and it is not the first technical action while the process is still writing files. This is a teaching order for that scenario, not a claim that every incident uses the same list.
What to do with the clock
Give the simulation a bounded block, as the format guide suggests. If the interface is unfamiliar, use the first minute to see what you can change. Do not spend the sitting hunting for a remembered answer.
Try the decision in multiple choice when you want another original stem. Say this plainly when you click: the web player will not open a simulated desktop, a drag-and-drop rack, or a live firewall. It will ask you to choose the best written action. That is useful practice for the judgment. It is not a PBQ.
Trust the source
Official sources
Exam policies can change. Use these primary sources for the most current details.