What does a Security+ PBQ test?
A Security+ PBQ tests whether you can apply knowledge to a practical task. That could involve interpreting evidence, choosing appropriate controls or completing a configuration in an exam interface. The official SY0-701 objectives.pdf?sfvrsn=204179cc_6) confirm a mix of multiple-choice and performance-based questions.
You’re preparing to use the topics, not memorise a provider’s exact screen. A firewall exercise can test traffic direction, ports and least privilege together. An investigation exercise can require you to connect several clues and choose a response.
The examples in this guide are original practice scenarios, not recalled exam items. They teach the decisions that help you work with an unfamiliar interface.
Evidence tasks are easier to interpret when you distinguish scanning, testing, hunting and risk assessment by the question each answers.
What should I read before making any changes?
Read the required outcome, the systems you may change and the constraints before making changes. A task might require allowing one service while keeping a sensitive subnet isolated. Opening all traffic would satisfy only part of that need.
Turn the task into a short checklist. Name the approved source, destination and service. Identify any explicitly forbidden path. Read the interface instructions, including whether changes need saving and how you may move between questions.
Then examine the supplied diagram, logs or settings. If the evidence shows a workstation talking directly to a database, trace that path rather than changing unrelated settings. Work from the evidence you have; don’t invent an extra incident.
For access-control tasks, separate identity checks, permission checks and activity records before changing a role or login setting.
For a suspicious-login task, use the channel and credential pattern to classify the attack.
How would I solve an original firewall practice task?
Solve a firewall practice task by translating each requirement into a narrow rule, then checking rule order and the default action. Consider this simplified exercise: internet users may reach a public web server over HTTPS; that web server may reach its database over TCP 5432; internet users must have no direct database access.
The two required allowances are public-client-to-web-server TCP 443 and web-server-to-database TCP 5432. A deny policy must block the direct public-to-database path. TCP 5432 is used here for the example database service; use the port stated in your actual task.
If the rule engine uses first match, put required narrow rules before a broad deny. If it is stateful, return traffic for an allowed connection may already be covered. Follow the model the task supplies rather than assuming every product works the same way.
Scroll sideways to see every column.
| Source | Destination | Service | Action |
|---|---|---|---|
| Public clients | Public web server | TCP 443 | Allow |
| Public web server | Database server | TCP 5432 | Allow |
| Public clients | Database server | Any | Deny |
Should I skip a PBQ and come back later?
Consider returning later only if the exam interface permits it and the task is consuming time you need elsewhere. Read the on-screen navigation instructions first. Don’t assume every task or exam format allows the same movement.
SY0-701 allows up to 90 questions in 90 minutes, so spending a large part of the session on one unclear task can leave other questions unanswered. A personal practice strategy might reserve a final review window and mark a difficult task for return where available. That is a planning aid, not an official per-question time limit.
During preparation, time yourself on original exercises and notice where you stall: reading the diagram, recalling a port, interpreting a log or operating the interface. Fix the skill that caused the delay.
How should I check a completed PBQ?
Check a completed PBQ against each requested outcome, including any requirement to preserve access or deny a path. A configuration that blocks everything can be secure-looking and still fail the task.
For a firewall exercise, test the allowed and denied paths in your reasoning. For a sequencing exercise, check dependencies: collect needed evidence before a destructive action, unless immediate containment is required by the stated situation. Incident response isn’t always a rigid list.
Inspect every requested field and any save or apply control. Complete what you can justify, but don’t rely on a promised partial-credit amount or a fixed PBQ count. Scoring and item selection shouldn’t be inferred from a practice provider’s marks.
An investigation task may ask you to select IDS, SIEM, SOAR or EDR capabilities from the requested action and evidence location.
If the task includes a file comparison or a protected value, identify whether hashing, encryption or encoding is involved.
For a cryptography task, name who signs, who verifies and who decrypts before selecting a public or private key.
- 01Read the goalIdentify required and forbidden outcomes
- 02Use the evidenceTrace the relevant systems and events
- 03Make narrow changesMatch each change to a requirement
- 04Check the resultReview all requested parts and navigation
How should I practise before the exam?
Practise by doing tasks and explaining why each decision works. Use safe labs or original exercises to configure narrow firewall rules, read sample logs, assign least-privilege access and connect controls to a network diagram.
Start with how the network controls work together, then recall the ports and protocols without looking at a table. Change the scenario and check whether your reasoning still works.
CompTIA Security+ Practice includes a firewall exercise alongside concept lessons and explained questions. Its app preview shows the current learning tools and store availability.
For numerical tasks, practise loss formulas, recovery targets and reliability averages with the units shown explicitly.