Castmark PressIndependent study guides
Guides · August 2026

Security+ PBQs: what they look like and how to practise them on paper

Security+ performance-based questions come in four recognisable shapes: matching, sequencing, configuration and calculation. All four can be practised on paper, because what they test is the reasoning, not the interface. Work them slowly, write down why each choice is right, and they stop being the part of the exam you dread.

Ask candidates which part of Security+ worries them and most say the performance-based questions. Ask how much time they have spent practising them and the answer is usually almost none.

That gap has a cause. PBQs feel like they need a lab, a simulator or a subscription, so candidates postpone them until a week before the exam and then meet them cold. Meanwhile the multiple-choice questions — the part they were already comfortable with — get practised to exhaustion.

The premise is wrong. A performance-based question is a reasoning problem wearing an interface, and the reasoning is what is being marked. This guide covers the four shapes PBQs take, how to work each one on paper, and the practice habit that removes the fear.

What a PBQ actually is

CompTIA states that the exam contains a mix of multiple-choice and performance-based questions. A PBQ presents a situation and asks you to do something with it rather than to pick a letter — drag items into place, order steps, complete a configuration, or produce a value.

What it is testing is not dexterity. It is whether you can apply a concept to a specific situation rather than recognise it in a list. That is why PBQs feel harder: multiple choice lets you work backwards from the options, and a PBQ does not give you that ladder.

It is also why they can be practised on paper. Take away the drag-and-drop and what remains is: here is a scenario, here are the elements, put them in the right relationship. A page does that perfectly well.

The one thing paper cannot rehearse is the clock and the interface. That is worth one session in an official practice environment near the end — but it is a familiarisation exercise, not where the learning happens.

The four shapes

Matching. A set of items and a set of slots: attacks to defences, log entries to attack types, controls to control categories, ports to services, tools to phases. What is being tested is discrimination — whether you can tell two similar things apart. These reward knowing why the near-miss is wrong, not just why the answer is right.

Sequencing. Put steps in order: an incident response sequence, a forensic acquisition order, a change process, a certificate enrolment. What is being tested is whether you understand dependency — why step three cannot happen before step two. Memorised orders collapse when the scenario varies; understood dependencies do not.

Configuration. Complete or correct a setting: firewall rules, access control entries, a hardened configuration, an authentication policy. What is being tested is applying a principle to a specific case — usually least privilege, defence in depth, or fail-safe defaults. The trap is a rule that works but is broader than it needs to be.

Calculation. Produce a number and then say what it means: risk figures most commonly. Single loss expectancy is asset value multiplied by exposure factor; annualised loss expectancy is single loss expectancy multiplied by the annualised rate of occurrence. The V8 draft lists these explicitly under business-level considerations in Domain 5, so expect to compute rather than recognise.

How to work each shape on paper

Matching: cover the answer bank and write what each slot needs before you look. If you can describe the required item from the scenario alone, you know it; if you can only recognise it in the bank, you do not.

Sequencing: write the steps in the order you think, then justify each transition in one clause — "contain before eradicate, because eradicating first destroys the evidence". A sequence you can justify survives a reworded scenario. A sequence you memorised does not.

Configuration: write the rule, then attack it. What does this allow that it should not? What does it block that it should not? Nearly every configuration PBQ has a distractor that works but is too permissive, and this habit finds it.

Calculation: write the formula before the arithmetic, and write a sentence after the number saying what it means for the decision. Domain 5 questions rarely stop at the figure — they ask what to do about it.

The four shapes and what each rewards

If you are short of time, this table tells you which habit fixes which weakness.

ShapeTypical contentWhat it testsPaper drill
MatchingAttacks to defences, logs to attack types, controls to categoriesTelling near-identical things apartCover the answer bank; describe the slot first
SequencingIncident response, forensic order of volatility, change processUnderstanding dependency, not orderJustify each transition in one clause
ConfigurationFirewall rules, ACLs, hardening, authentication policyApplying least privilege to a specific caseWrite the rule, then attack it for over-permission
CalculationSLE, ARO, ALE and the decision that followsComputing, then interpretingFormula first, then a sentence on what it means

The practice habit that works

Do PBQs early and in small doses, not late and in bulk. Two a week from the start of your study beats twenty in the final fortnight, because the reasoning they need is built slowly and the confidence they destroy is rebuilt slowly.

Work them without a timer at first. A PBQ done slowly and understood is worth ten done quickly and half-remembered. Add the clock in the last two weeks.

Write down your reasoning even when you get it right. The point is not the answer; it is being able to reconstruct why, when a variant of the same question appears with different numbers.

And check what your study material actually gives you. Ours prints twenty paper-based PBQ sets with step-by-step walkthroughs covering all four shapes — matching, sequencing, configuration and calculation — because a walkthrough that shows the reasoning is what makes these learnable from a book. A guide that lists PBQ topics without working any is not teaching the format.

One caution on the exam itself: the V8 draft does not publish a question count or a duration, so nobody can tell you how many PBQs to expect or how long to budget for them. Practise so that they are not the thing you are budgeting around.

The book for this exam

Cover of CompTIA Security+ Study Guide 2027 CompTIA Security+ Study Guide 2027 Written line by line against the CompTIA Security+ V8 objectives for exam SY0-801, while most guides on the shelf are still SY0-701 books. Everything is… See the book →

More on this exam

Common questions

How many PBQs are on the Security+ exam?

CompTIA does not publish a number, and the V8 draft marks both the question count and the exam duration as to be determined. Any source giving you a figure for SY0-801 is guessing. Prepare so the count does not matter.

Can I practise PBQs without a lab or a simulator?

Yes. What a PBQ tests is the reasoning, not the interface. All four shapes — matching, sequencing, configuration and calculation — work on paper. Use an official practice environment once near the end for interface familiarity.

Should I do PBQs first or last in the exam?

Many candidates leave them until the multiple-choice questions are done, so that no PBQ can consume time the rest of the exam needs. Whatever you choose, decide before you sit rather than in the moment.

What kind of calculations appear?

Risk figures, most commonly: single loss expectancy as asset value multiplied by exposure factor, and annualised loss expectancy as SLE multiplied by the annualised rate of occurrence. The V8 draft lists these explicitly under business-level considerations.

Why do configuration PBQs feel like there are two right answers?

Because there usually are two that work, and one is broader than it needs to be. The distractor typically violates least privilege while still achieving the stated goal. Write your rule, then ask what it allows that it should not.

Sources

  1. CompTIA, "Security+ (Plus) Certification" — the statement that the exam contains a mix of multiple-choice and performance-based questions — https://www.comptia.org/en-us/certifications/security/
  2. DRAFT CompTIA Security+ V8 Exam Objectives, exam number SY0-801 V8 — single loss expectancy, annualised rate of occurrence and annualised loss expectancy listed under business-level considerations in Domain 5; question count and duration marked TBD
  3. NIST SP 800-61 Rev. 3 — the incident-response phases underlying sequencing questions

Rules change. Where a figure or a procedure can move, the issuing agency’s current published instructions win over anything here.