Security+ PBQs: what they are and how to beat them
By SunTzu, founder of CertOwl • Published • 4 min read
Quick answer
Performance-based questions (PBQs) on Security+ SY0-701 are interactive tasks, simulations of tools like firewalls or log viewers, and they usually sit at the start of the exam. CompTIA does not publish how many you get; candidates most often report three to five. They earn partial credit, you can flag them and return later, and they feed the same 750 of 900 scaled score as everything else.
The performance-based questions carry more fear per candidate than any other part of Security+. Forum threads treat them as a separate exam, study plans reserve whole weeks for them, and some people walk in already resigned to losing those marks. That reputation is out of proportion to what the questions are: a small set of interactive tasks, marked with partial credit, that test the same objectives as the multiple choice and punish only one mistake, which is poor time management.
What a PBQ is
A performance-based question drops you into a small working model of a tool instead of offering four options. CompTIA calls these simulations: an approximation of a firewall console, a network diagram, a terminal window or a log viewer, with just enough functionality to complete one task. You might drag attack names onto the scenarios that describe them, order the steps of an incident response, build firewall rules from a short policy statement, or scan a block of log lines and mark the host that has been compromised.
None of that requires knowledge beyond the written objectives. A PBQ about firewall rules tests the same ports and protocols a multiple-choice question would; it simply asks you to place them yourself rather than recognise the right row in a list. The material comes from the same five domains as the rest of the exam, which we break down in our SY0-701 exam guide.
How many you get and how they are scored
CompTIA does not publish a PBQ count, and the number varies between exam forms. Candidates most often report three to five, placed at the front of the exam before the multiple choice begins. The exam stays the same size either way: up to 90 questions in 90 minutes, so a form with more PBQs simply carries fewer multiple-choice questions after them.
Two scoring details matter more than the count. First, PBQs earn partial credit: if a task wants five firewall rules and you configure three correctly, those three count for you. Second, they are not scored as a separate section. Everything folds into one scaled result, passing at 750 on the 100 to 900 scale, and CompTIA keeps the weighting of individual items confidential. We unpack that scoring system in what the passing score really means. The practical conclusion: a PBQ left blank throws away marks that partial credit would have collected, so an educated attempt always beats surrender.
The three shapes worth practising
Most reported PBQs fall into three families, and each can be rehearsed without any special software.
Matching and ordering. Drag attack types onto descriptions, controls onto the risks they address, or steps of a process into sequence. This is flashcard knowledge wearing a different interface.
Configuration. Build or correct firewall rules, access control lists or wireless settings against a stated policy. Practise by reading a requirement and writing the rule yourself on paper before checking a model answer.
Log and output reading. Find the suspicious entry, the source address of an attack, or the misconfigured line in command output. Speed here comes from having seen normal output often enough that the abnormal line stands out.
If you can do these three things slowly, the simulation format stops being scary and the remaining question is pace, which is the same challenge the whole exam poses. Our overview of how hard Security+ is puts that difficulty in context.
A time plan that survives the first ten minutes
Almost every PBQ horror story is a time story: twenty-five minutes gone on the first two questions and a sprint through the multiple choice afterwards. Two plans prevent it. The first is a hard cap: give each PBQ five minutes, take the partial credit you have earned, flag it and move on. The second is deferral: flag every PBQ immediately, clear the multiple choice, then return with everything that remains. Both work, and each simulation has a reset control if your first attempt turns into a mess and you return later.
Whichever plan you pick, decide before exam day. The candidates who lose to PBQs are the ones negotiating with the clock in the moment.
Test yourself: 3 quick questions
What is the difference between phishing, vishing, and smishing?
All three have the same goal (manipulate a person) but a different channel: phishing goes by email, vishing by phone/voice, smishing by SMS/text. Recognizing the channel helps you stay alert.
What is the defense against SQL injection?
SQL injection occurs when an application blindly inserts user input into an SQL statement. The defense is parameterized queries (placeholders $1, $2) where the input is treated as data, not as part of the command. Never concatenate user input into an SQL string.
What are threat feeds (sources of threat intelligence)?
Threat feeds are a continuous stream of threat intelligence. Types: OSINT (public/free, but noisy), proprietary/third-party (paid, curated, reliable), information-sharing (communities/ISACs share indicators), dark web (hidden forums - early warning). They are security's 'early warning' - you can't defend against threats you don't know about.
Score: · Hundreds more with explanations, free in the app: Get CertOwl on the App Store
Frequently asked questions
Do PBQs give partial credit?
Yes. Multi-part tasks credit the parts you complete correctly, which is why an incomplete attempt is always worth leaving on the board.
Can I skip a PBQ and come back to it?
Yes. Flag it, finish the multiple choice, and return in the time you have left. Simulations can also be reset to their starting state.
How many PBQs are on Security+?
CompTIA does not say, and forms differ. Reports cluster around three to five, generally at the start of the exam.
CertOwl trains the knowledge PBQs draw on, ports, protocols, attacks and controls, through scenario questions with every answer explained and spaced repetition that brings your misses back. The A+ and Network+ tracks are completely free.
Get CertOwl on the App StoreFree download · A+ and Network+ completely free
+ daily lessons, flashcards and full exam simulations