The questions that unsettle CompTIA Security+ candidates most are not the multiple-choice ones. They are the performance-based questions (PBQs), the hands-on tasks that ask you to do something rather than pick an answer. The good news: they are predictable, and once you know how they work you can turn them from a threat into easy marks. Here is exactly what they are and how to handle them.
What Security+ actually is
CompTIA Security+ (current exam SY0-701) has "a maximum of 90 questions, a mix of multiple-choice and performance-based questions", a duration of "90 minutes", and a passing score of "750 (on a scale of 100-900)". CompTIA's recommended experience is "CompTIA Network+ and two years of experience working in a security/systems administrator job role", though that is advice, not a hard requirement.
The exam is the recognised baseline for security roles, which is why the PBQs matter: they are CompTIA's way of checking you can apply knowledge, not just recall it.
What a performance-based question is
A PBQ is an interactive task that presents a scenario and asks you to complete or solve it: configuring a firewall rule set, matching attack types to their descriptions, placing controls in the right order, reading log output to identify an incident, or setting permissions. Instead of four options, you get an environment to manipulate.
Two things about PBQs shape your whole strategy:
- They usually appear first. Most candidates meet the PBQs at the very start of the exam, before the multiple-choice questions.
- They take longer. A single PBQ can eat several minutes, far more than a multiple-choice question, and there is a real risk of sinking twenty minutes into two tasks and then rushing the rest.
The single most important tactic: skip and return
Because PBQs come first and consume time, the biggest mistake is grinding through them in order while the clock drains. Do the opposite.
- On the exam, flag every PBQ and move past it to the multiple-choice questions first. Bank all the fast, certain marks while your mind is fresh and the clock is kind.
- Then come back to the PBQs with your remaining time, knowing exactly how many minutes you can spend on each.
This one habit protects you from the classic Security+ failure: a strong candidate who knew the material but ran out of time because two early PBQs swallowed half the exam.
How to prepare for the tasks, not just the facts
PBQs reward familiarity with how things are actually configured, which reading alone does not build.
- Practise the common PBQ types. Firewall and ACL rule ordering, matching malware or attack types to descriptions, interpreting logs, and configuring secure settings come up repeatedly. Get comfortable doing them, not just recognising them.
- Learn to read for the ask. PBQs often contain more information than you need. Identify precisely what the task wants before you touch anything, so you are not second-guessing a working answer.
- Get hands-on where you can. Even a basic lab or simulator that makes you configure and interpret rather than memorise builds the muscle memory the PBQs test.
If you are weighing Security+ against a gentler starting point, our comparison of ISC2 CC and CompTIA Security+ covers which suits your experience level.
Practise under real exam conditions
Because Security+ front-loads the questions that cost the most time, the exam is as much a test of pacing as of knowledge, and pacing is exactly what untimed reading fails to build. Full, timed mock exams that mirror the real structure, including hands-on style tasks, train the skip-and-return discipline and show you how long a PBQ really takes you. CandidatesPrep's simulator runs timed, scored practice so you rehearse the clock as well as the content, and trainers preparing security cohorts can track readiness across a whole group.
Exam-day tactics
- Flag the PBQs, do all the multiple-choice questions first, then return to the PBQs with time budgeted.
- Read each PBQ twice and identify the exact task before making changes.
- If a PBQ stalls you, secure your best partial answer and move on; part-marks beat a blank.
- Answer every question. There is no penalty for guessing on the multiple-choice items.
The bottom line
Performance-based questions are the most feared part of Security+ and the most manageable once you have a plan: they come first, they eat time, so skip them, clear the multiple-choice marks, then return. Practise the common task types under real timed conditions, and the PBQs stop being the thing that fails good candidates.
Preparing for Security+, or training a security cohort? Rehearse under timed exam conditions, or book a demo to see how trainers track readiness on CandidatesPrep.
