This is a rather difficult part of the exam. Each exam section typically has 3 to 7 questions, usually 5 (but one PBQ question is like dozens of other questions combined). CompTIA has also started including practical questions, though I only saw one in the recent SecurityX exam, a lab-style question asking to find malware, thoroughly terminate processes, or delete a file... What's strange is that this question didn't seem to allow for review, or maybe I forgot to mark it for review, I can't remember. For future reference, always mark questions for review to be safe, especially PBQ and Lab questions. Security365 has prepared a set of PBQ questions for its students and trainees to practice with, which are very similar to the actual exam. If you want something exactly like the real thing, refer to the Security+ CertMaster Learn + Lab study material.
Ask anyone who has just taken the Security+ exam what surprised them the most, and the answer is often the same: PBQ. Not because they are difficult, but because they appear at the very beginning of the exam and take more time than anticipated.
What are PBQs?
PBQ (performance-based question) is a simulated practical question. Instead of choosing A/B/C/D, you have to do something in a simulated interface: drag and drop, fill in configurations, arrange in order, classify, or analyze data and draw conclusions.
CompTIA's objective is quite clear: to distinguish between those who understand the problem and those who simply memorize definitions.
The Security+ exam has a maximum of 90 questions in 90 minutes, including some PBQ questions—which usually appear at the beginning of the exam.
Why do PBQs cause many people to fail?
They consume time disproportionately to the score. A single PBQ can take 8–10 minutes if you try to complete it thoroughly. Meanwhile, 10 minutes is enough to answer 10 multiple-choice questions.
They appear at the beginning of the exam. This design creates strong psychological pressure: you just entered the exam room, still tense, and immediately encounter the most difficult part. Many people lose their composure here and fail to regain their rhythm.
They do not allow for guessing. If you answer a multiple-choice question incorrectly, you still have a 25% chance of being right. Leaving a PBQ blank means definitely losing points.
Purely self-taught individuals who only study theory have never encountered this type of question. Reading books and watching videos does not prepare you for drag-and-drop operations in an unfamiliar interface under time pressure.
Common types of PBQs
Classification and drag and drop. Given a list of concepts, drag each one into the correct group. For example: classify control measures into preventive / detective / corrective, or technical / managerial / operational / physical groups.
This type tests exactly what Domain 1 teaches. If you have a solid grasp of control classification systems, this is the easiest point to earn in the entire PBQ section.
Ordering. Given disparate steps, arrange them in the correct sequence. Most commonly, this involves incident response procedures.
Tip: learn processes in order from the start, don't learn individual steps separately. Knowing all 6 steps but not remembering the order will still result in lost points.
Configuration. Given a simulated interface (firewall, permissions, authentication setup) and asked to configure it according to the scenario description.
This type is the most challenging for those who have never worked with real systems. This is also why labs are far more important than many people realize.
Log or scan result analysis. Given a log snippet or vulnerability scan report, asked what happened or how to handle it.
Secret: don't try to understand every line. Look for anomalies—unusual timestamps, repeated IPs, a sharp increase in failed attempts, accounts that shouldn't appear.
Matching. Match attack types with corresponding mitigation measures, or terms with definitions.
Exam room strategy
This is the most important part of the article, and it's so simple that many people overlook it.
The 3-minute rule.
Start the exam, encounter the first PBQ. Read the question. If you can't figure out how to do it within 30 seconds, mark the question and skip it immediately.
If you know how to do it, allow yourself a maximum of 3 minutes. If you're not done after 3 minutes: mark it, skip it, and move on.
Why this strategy is effective:
You complete the multiple-choice section first—this section makes up most of the questions and you can answer them much faster. Once done, you know exactly how many minutes you have left to allocate to the marked PBQs.
Additionally, answering multiple-choice questions helps you calm down. Returning to PBQs with a focused mind will be very different from when you first entered the room.
Never leave anything blank. Before time runs out, go back and fill in all unfinished PBQs, even if you're unsure. PBQs are often graded in parts—getting half right still earns points, leaving it blank earns none.
Don't be a perfectionist. Many people fail the exam because they try to perfectly complete one PBQ and don't have time for the last 15 multiple-choice questions. A partially completed PBQ is better than 15 unanswered questions.
How to practice PBQs
This is the biggest weakness of free self-study: you can barely practice PBQs using only books and videos.
Three approaches, in order of effectiveness:
1. Official simulated labs. CompTIA's CertMaster Learn & Labs materials include a lab section that runs in a browser with an interface close to the actual exam environment. This is the closest method, and also the most compelling reason to invest in official materials.
2. Build your own practice environment. Virtual machines, install Windows Server and Linux, experiment with permissions, firewalls, logs. Time-consuming but free and its long-term value far exceeds the exam itself.
3. Practice critical thinking on paper. Not a substitute for the first two methods, but better than nothing: write down the steps of an incident response process, classify control measures, draw authentication flow diagrams.
Four weeks before exam day
- Week 1: complete at least 10 PBQs, untimed. The goal is to familiarize yourself with the interface and question types.
- Week 2: repeat, timed at 5 minutes per question. Note which types you are slowest at.
- Week 3: focus on the slowest types. If it's configuration, do more labs.
- Week 4: practice PBQs in the context of a full mock exam, applying the 3-minute strategy.
By exam day, PBQs should feel familiar, not a surprise.
One important note
PBQs are the only part of the Security+ exam that tests what you will actually do in a job. Multiple-choice questions test what you remember; PBQs test what you can do.
So don't view practicing PBQs as an extra cost for the exam. It's the only part of your study process that you will reuse on your first day of work.
See more: 90-day self-study roadmap for Security+ · What is CompTIA Security+? · How to retake Security+ if you fail?