security+ pbqEnglish8 min read

Security+ Performance-Based Questions (PBQs): What They Are and How to Practice Them

Security+ PBQs are interactive tasks that come first and eat time. Here is what they look like on SY0-701, how many to expect, and a worked example you can practice from.

Marcus Chen
Marcus Chen
July 23, 20268 min readUpdated July 23, 2026

Performance-based questions are the part of the Security+ exam that catch people off guard. They are not pick-one-of-four. They are interactive tasks where you configure something, drag items into place, or put steps in the right order, and they usually show up first, before the multiple-choice questions. On SY0-701 there are typically a handful of them, and they eat time out of all proportion to their count.

If you have only ever drilled flashcards, PBQs are the format most likely to cost you the exam. This is what they are, how many to expect, a worked example you can actually practice from, and the time-management play that keeps them from wrecking your pacing. PrepClubs writes original PBQ-style practice items; nothing here reproduces live exam content, which is against CompTIA policy and can get a certification revoked.

Quick takeaways

  • PBQs are interactive, scenario-based tasks (configure, drag-and-drop, order, match), not multiple-choice. They test whether you can do the thing, not just define it.
  • Expect a small number, commonly 3 to 6, and they usually appear at the very start of the exam, per candidate reports and CompTIA's description of the format.
  • The single biggest PBQ mistake is spending 15 to 20 minutes on the first one. Skim them, do the quick wins, flag the rest, clear the multiple-choice, then return.
  • PBQs draw most heavily from the hands-on domains, especially Security Operations (28% of the exam) and Security Architecture.
  • PrepClubs' Security+ track includes PBQ-style practice items so the interactive format is not the first time you meet it on test day.
  • PrepClubs is independent prep material and is not affiliated with or endorsed by CompTIA.

What a PBQ actually is

A performance-based question puts you inside a simulated task instead of asking you to recognize an answer. CompTIA describes PBQs as items that test your ability to solve problems in a simulated environment. In practice, on Security+, that looks like one of a few recurring shapes:

  • Configuration tasks. Set firewall rules to allow or block specific traffic, configure a wireless access point securely, or set the right permissions on a file share.
  • Drag-and-drop matching. Match attack types to their correct mitigations, or place security controls onto the right point in a network diagram.
  • Ordering. Put the phases of incident response, or the steps of a hardening procedure, into the correct sequence.
  • Topology and analysis. Read a small network diagram or a log excerpt and identify what is misconfigured or what the indicator of compromise is.

The common thread: recognition is not enough. You have to apply the concept correctly in context, which is exactly why they are harder to fake with memorization.

How many PBQs are on the Security+ exam?

There is no fixed, published number. Based on CompTIA's format description and consistent candidate reports, expect roughly 3 to 6 PBQs on SY0-701, delivered at or near the start of the exam. Treat that as a planning range, not a promise. You might see four, you might see five. What is reliable is that there will be a small cluster of them early, and they will be the most time-expensive items on the exam.

A worked PBQ example (original, not a live item)

Here is an original example in the shape of a real Security+ PBQ, so you can practice the reasoning rather than just read about it.

Scenario. A small office network has one firewall between the internet and an internal LAN. You are given four proposed firewall rules and asked to enable only the ones that follow least privilege while keeping a public web server reachable.

Rule Action
A: Allow inbound TCP 443 to the web server Correct to enable. Public HTTPS to the web server is required.
B: Allow inbound TCP 3389 to all internal hosts Wrong. Exposing RDP to the whole internet is a serious risk; deny it.
C: Allow outbound TCP 443 from the LAN Correct to enable. Internal hosts need HTTPS out to browse and update.
D: Allow inbound ANY to ANY Wrong. An any-any allow defeats the firewall entirely; deny it.

The reasoning that gets you the marks: enable A and C, deny B and D. The exam is not testing whether you know what a firewall is. It is testing whether you apply least privilege under pressure, open only what a real service needs, and refuse the convenient-but-dangerous any-any rule. That judgment is what PBQs are built to measure, and it is why drilling definitions alone does not prepare you for them.

Original example of a Security+ SY0-701 performance-based question showing four firewall rules to enable or deny under least privilege

The time-management play for PBQs

PBQs are where the 90-minute clock gets lost. Here is the routine that protects it.

  1. Do not solve the first PBQ immediately. When the exam opens with PBQs, resist the urge to grind the first one to completion. That is how people burn 20 minutes before they have answered a single scored multiple-choice item.
  2. Skim all the PBQs first. Look at each one, do the ones you can finish in two or three minutes, and flag the rest.
  3. Clear the multiple-choice questions. These are faster and bank you time and confidence. Get through them, flagging anything genuinely hard.
  4. Return to the flagged PBQs with your remaining time. Now you know how much clock you have, so you can commit to the hard tasks without panicking about the questions you have not seen yet.

You cannot execute this on exam day if you have never practiced the format. Meeting your first PBQ live, with the clock running, is the worst possible time to figure out how the interface behaves.

Which domains do PBQs come from?

PBQs cluster in the hands-on domains, because those are the ones where "can you actually do it" is the real question. On SY0-701 that means most PBQs draw from:

  • 4.0 Security Operations (28%): hardening, monitoring, incident response ordering, log analysis.
  • 3.0 Security Architecture (18%): secure network design, placing controls, data protection choices.
  • 2.0 Threats, Vulnerabilities, and Mitigations (22%): matching attacks to the right mitigation.

If you want your PBQ practice to pay off, drill these three domains as interactive tasks, not just as reading. That overlap is one more reason Security Operations deserves the biggest slice of your study time.

FAQ

What are performance-based questions on Security+?

Interactive, scenario-based tasks where you configure, drag-and-drop, order, or analyze something in a simulated environment, rather than picking a multiple-choice answer. They test applied skill, not recall.

How many PBQs are on the Security+ SY0-701 exam?

There is no fixed published number. Expect roughly 3 to 6, typically at the start of the exam, based on CompTIA's format description and candidate reports. Plan for the top of that range.

Are PBQs weighted more heavily than multiple-choice questions?

CompTIA does not publish per-item weighting, so you cannot know exactly. Treat them as significant and time-expensive, and give them the pacing strategy above rather than assuming they are worth the same quick effort as a multiple-choice item.

Where can I practice Security+ PBQs?

Use a bank that includes original, interactive PBQ-style items across the hands-on domains. Avoid anything claiming to reproduce real exam questions; those "dumps" violate CompTIA policy and can cost you your certification.

Do PBQs come first on the exam?

Usually, yes. Candidate reports and the exam's design put the cluster of PBQs at or near the start. That is exactly why a "skim, do the quick ones, come back" strategy matters so much.

Can I skip a PBQ and come back to it?

Yes, you can flag questions and return to them within the 90 minutes. Flagging the hard PBQs and clearing the faster multiple-choice items first is the standard way to protect your pacing.

Meet the PBQ format before test day, not on it

The candidates who lose to PBQs are almost always the ones seeing the interactive format for the first time under the clock. The fix is simple: practice them until they are boring. PrepClubs' Security+ track includes original PBQ-style items across the hands-on domains, each with a written rationale that explains the applied reasoning, alongside 10 full-length practice tests (900 SY0-701 questions total). You start with a free 25-question diagnostic to find your weak domains, then unlock the full bank for a one-time $69. It is a one-time payment with 30 days of access, not a subscription. If you prepare with PrepClubs and do not pass your real test, we extend your access at no extra cost. No fine print. PrepClubs has helped more than 1,600 students prepare for cognitive and certification assessments. Start with the free Security+ diagnostic.

FAQ

Common questions

What are performance-based questions on Security+?

Interactive, scenario-based tasks where you configure, drag-and-drop, order, or analyze something in a simulated environment, rather than picking a multiple-choice answer. They test applied skill, not recall.

How many PBQs are on the Security+ SY0-701 exam?

There is no fixed published number. Expect roughly 3 to 6, typically at the start of the exam, based on CompTIA's format description and candidate reports. Plan for the top of that range.

Are PBQs weighted more heavily than multiple-choice questions?

CompTIA does not publish per-item weighting, so you cannot know exactly. Treat them as significant and time-expensive, and give them the pacing strategy above rather than assuming they are worth the same quick effort as a multiple-choice item.

Where can I practice Security+ PBQs?

Use a bank that includes original, interactive PBQ-style items across the hands-on domains. Avoid anything claiming to reproduce real exam questions; those "dumps" violate CompTIA policy and can cost you your certification.

Do PBQs come first on the exam?

Usually, yes. Candidate reports and the exam's design put the cluster of PBQs at or near the start. That is exactly why a "skim, do the quick ones, come back" strategy matters so much.

Can I skip a PBQ and come back to it?

Yes, you can flag questions and return to them within the 90 minutes. Flagging the hard PBQs and clearing the faster multiple-choice items first is the standard way to protect your pacing.
Security+ Performance-Based Questions (PBQs): SY0-701 Guide | PrepClubs