Interactive Simulations

Security+ PBQ Practice

Master performance-based questions before exam day. Practice firewall rules, analyze logs, configure network security, and more with AI-powered explanations.

How to Access PBQ Practice

1

Take the free 15-minute baseline assessment to identify your weak areas

2

Get your personalized study plan that prioritizes concepts you need most

3

Practice PBQs targeted to your weaknesses—not random questions you already know

Take Free Baseline Assessment

15 minutes • Unlock personalized PBQ practice

What Are Performance-Based Questions?

Performance-based questions (PBQs) are interactive simulations that test hands-on skills. Instead of picking A, B, C, or D, you complete actual tasks like configuring a firewall, analyzing a log file, or setting up access controls.

The Security+ SY0-701 exam includes approximately 4-5 PBQs out of 90 total questions. They appear at the beginning of the exam and typically take 5-10 minutes each.

Important

PBQs are worth more than regular questions. Skipping them or guessing randomly can drop your score significantly. You need to practice these specifically.

PBQ Types You'll Encounter

Firewall Configuration

Create, modify, or troubleshoot firewall rules. Configure ACL entries based on security requirements.

Domains 3 & 4

Log Analysis

Review security logs and identify indicators of compromise, attack patterns, or policy violations.

Domains 2 & 4

Certificate Management

Work with PKI scenarios—identify certificate issues or troubleshoot TLS/SSL problems.

Domain 3

Network Security

Configure network segmentation, set up VLANs, or implement wireless security settings.

Domain 3

Email Security

Analyze email headers to identify phishing, configure SPF/DKIM/DMARC records.

Domains 2 & 3

Access Control

Configure user permissions, implement least privilege, set up role-based access control.

Domains 1 & 4

Example PBQ Scenario

PBQ: Firewall Rule Configuration

Scenario

Your organization has a web server that should only accept HTTPS traffic from the internet. Internal administrators need SSH access from the 10.0.1.0/24 subnet. All other traffic should be denied. Configure the firewall rules to meet these requirements.

Interface

# Current Rules (incomplete)
RuleSourceDestPortAction
1AnyWeb-Server443ALLOW
2[Configure][Configure][Configure][Configure]
3AnyAnyAnyDENY

AI Guidance Available

When practicing, our AI tutor explains the correct configuration and why each rule matters. Learn the concepts, not just the answers.

Why PBQ Practice is Essential

15%
of exam questions are PBQs
2-3x
the weight of multiple choice
#1
reason people fail Security+

Most study materials focus on multiple choice. But PBQs are where knowledge meets application. You can memorize port numbers all day—if you can't configure a firewall using them, you'll lose significant points.

Don't Let PBQs Surprise You

Start with the baseline assessment to identify your weak spots, then practice PBQs that target exactly where you need improvement.

Take Free Baseline Assessment

15 minutes • Unlock personalized PBQ practice