Security+ PBQ practice: read the exhibit, make the call
Twelve free exhibit questions in the style of performance-based items: firewall rules, SIEM and EDR logs, DLP alerts, VPN profiles, backup designs and incident response order. Every option is explained.
- Logs & rule tables
- Incident response order
- Choose TWO items

How to read a PBQ exhibit fast
Read the question first. Know what you are looking for before you read twelve log lines.
Find the anomaly. In logs, look for the line that breaks the pattern: a new source address, a time that does not fit, one success after many failures, an unusual process parent.
Rules are read top-down. In firewall tables the first matching rule wins, so a broad allow or deny above a specific rule decides the outcome.
Map it to the objective. Ask which Security+ concept the exhibit is testing: an attack type, a control, a design principle or a response step. The options usually differ on exactly that concept.
12 free Security+ exhibit questions
These are extra questions, not taken from the course. Click an option to answer; the explanation under every option appears as soon as you do.
Review the zero trust access log entry:
MFA=passed
device=unmanaged laptop
posture=failed (no EDR agent)
resource=HR-portal
decision=DENY
enforced by=PEP-07
Which statement BEST explains the outcome?
- The log shows MFA=passed. The denial was not caused by the authentication challenge.
- The enforcement point applies the verdict from the policy decision point. It does not make the decision on its own.
- Correct. MFA passed, but the unmanaged device failed posture, and the policy denied access on that basis.
- The request never reached the portal. The log shows it was denied at PEP-07 before any application sign-in.
Review the TLS client debug output:
validity dates=OK
hostname=match
CRL download=timeout after 10s
revocation policy=soft-fail
connection=established
What is the MOST significant security risk?
- The output shows chain=valid. The trust path is complete.
- The output shows hostname=match. There is no name mismatch.
- Correct. The CRL could not be fetched and the soft-fail policy allowed the connection, so revocation was never actually checked.
- The output shows validity dates=OK. The certificate is within its validity period.
Review the EDR events on a file server:
01:12 powershell.exe -enc SQBFAFgA...
01:15 vssadmin.exe delete shadows /all /quiet
01:16 wbadmin delete catalog -quiet
No unknown executables were written to disk. Which conclusion is BEST?
- Correct. Native binaries were abused to download a payload, run encoded commands and destroy recovery points, which is typical pre-ransomware living off the land.
- Administrators do not normally delete every shadow copy and the backup catalog at 1 a.m. after an encoded script.
- Worms self-propagate between hosts; these events show hands-on commands on one server with native tools.
- Bloatware is unwanted preinstalled software and would not issue commands to delete recovery data.
Review the log:
02:14 login fail user=jsmith src=203.0.113.9
02:15 login fail user=pnguyen src=203.0.113.9
02:15 login fail user=kbrown src=203.0.113.9
02:16 login ok user=tdavis src=203.0.113.9
Every attempt used the password Winter2026!. Which attack is this?
- Brute force tries many passwords against one account; here one password is tried against many accounts.
- Credential replay reuses a captured credential or token for a specific account, not guesses across users.
- A dictionary attack on one user tries many words against that account; these attempts span many users.
- Correct. A single common password tried against many different usernames is password spraying.
Review the DNS log from one workstation:
query mb81vtr0qe.net NXDOMAIN
query zq7hy1c2kw.org NXDOMAIN (hundreds per hour)
query p4nb0x8rty.com resolved 203.0.113.77
Which conclusion is MOST likely?
- Cache poisoning plants false answers for real names; here the queried names themselves are random.
- People mistype real brand names, not hundreds of random ten-character strings per hour.
- Correct. Hundreds of random names failing until one resolves is the typical footprint of DGA-based command and control.
- A misconfigured forwarder would fail real domains, not produce random strings that no one would type.
Review the API log for user id 2231:
GET /api/accounts/2232/statements 200
GET /api/accounts/2233/statements 200
GET /api/accounts/2234/statements 200
Accounts 2232 to 2234 belong to other customers. Which issue does this BEST indicate?
- Correct. A normal customer reached other customers' data at the same privilege level by changing the object ID.
- Vertical escalation means gaining higher rights, such as admin; this user only reached peers' data.
- CSRF uses another user's browser; this user is making the requests directly.
- The user presents their own valid session; the flaw is the missing ownership check.
Review the container deployment settings:
hostPath mount: / (read-write)
runAsUser: 0
hostNetwork: true
Which risk is the MOST serious?
- CPU use is controlled by resource limits, which these settings do not address. Host takeover is the far greater risk.
- Nothing in these settings refers to the image source, so registry trust cannot be judged from them.
- Correct. Root in a privileged container with the host filesystem mounted read-write can easily escape to the host.
- hostNetwork does not make the service unreachable. It removes network isolation, which adds to the escape risk.
Review the perimeter firewall rules. The web server 172.16.10.5 sits in the screened subnet and the database 10.1.5.20 sits on the internal network:
Rule 2 ALLOW TCP 1433 ANY to 10.1.5.20
Rule 3 DENY ANY ANY
Which change BEST reduces risk without breaking the application?
- Moving to plain HTTP weakens web security and leaves the database exposure untouched.
- Correct. Restricting the source to the web server keeps the application working and blocks direct internet access to SQL.
- Placing the deny-all rule first would block all traffic, including the legitimate web service.
- Removing Rule 1 takes the website offline and leaves the database exposed.
Review the backup design for an order database:
Incremental backup daily at 01:00
Backups stored offsite
Business RPO: 15 minutes
Which change BEST meets the RPO?
- Nightly full backups still leave up to 24 hours of orders unprotected.
- Differentials change what a restore needs, not how often data is captured, so the gap stays at 24 hours.
- Another copy of the weekly full backup adds location resilience, not a better recovery point.
- Correct. Shipping the transaction log every 15 minutes limits data loss to the RPO.
A DLP console shows:
action=upload
destination=personal-drive.example
file=Q3_payroll.xlsx
match=SSN pattern x412
policy action=monitor
Which change BEST prevents this from recurring?
- Correct. Blocking stops the upload instead of just recording it.
- The rule already matched; a threshold change does not stop the upload.
- Allow-listing the site would permit exactly the behavior to prevent.
- A summary is after the fact and still lets the data leave.
An incident response trainer lists these steps:
B) Containment
C) Detection and analysis
D) Recovery
E) Eradication
Which order is correct?
- Containment must come before eradication to stop the spread first.
- You cannot contain an incident before detecting and analyzing it.
- Correct. Detection, containment, eradication, recovery, then lessons learned.
- Recovery before eradication risks restoring systems that are still compromised.
A workstation baseline requires:
Firewall=On (all profiles)
BitLocker=Off
LocalAdmins=Domain Admins, jdoe
Which two findings need remediation? (Choose TWO.)
- Domain Admins membership is the normal domain default and the baseline does not prohibit it.
- An enabled firewall on all profiles meets the baseline.
- Correct. The baseline requires full-disk encryption.
- Correct. A standard user with local admin rights breaks the baseline.
PBQ FAQ
What are PBQs on the Security+ exam?
Performance-based questions ask you to do something rather than recall a fact: read a log, fix firewall rules, order incident response steps or match controls to scenarios. They usually appear at the start of the exam.
How many PBQs are on Security+?
CompTIA does not publish an exact number. Candidates commonly report a small handful at the start of the exam, alongside up to 90 questions in total.
Should I answer PBQs first?
Many candidates flag PBQs and return to them after the multiple-choice questions, so a long simulation does not eat the time they need for the rest of the exam. Either way, practice reading exhibits quickly.
Are these the real PBQs?
No. They are original practice items written from the public CompTIA objectives in a PBQ style: an exhibit to read and a decision to make. Real exam content is protected.
More practice: free SY0-701 questions · free SY0-801 questions · SY0-701 vs SY0-801