Fact check · PBQs
What CySA+ performance-based questions ask you to do
CySA+ performance-based questions (PBQs) hand you data, such as SIEM alerts, logs or scan results, and ask you to do an analyst's work with it, where a multiple-choice item asks for one pick. CompTIA's CS0-004 FAQ names six kinds of task they may set.
- Checked October 9, 2026
On CS0-004, performance-based questions may ask you to analyze SIEM alerts, review logs and security events, investigate indicators of compromise, prioritize vulnerabilities, support incident response and recommend remediation. CompTIA does not publish how many appear or where.
Source: CompTIA blog: The New CompTIA CySA+ (V4), Your Certification Questions Answered · checked
The six tasks CompTIA lists
- Read SIEM alerts and decide which ones matter
- Review logs and security events
- Investigate indicators of compromise (IoCs)
- Rank vulnerabilities by priority
- Support incident response steps
- Recommend a remediation
Each task, and how to practice it
Alerts and logs
The task: separate signal from noise in an alert queue or a block of raw events, the skills behind objectives 1.2 and 1.3. Practice by reading real formats until the fields stop being strange: Windows event logs (EVTX), syslog, web server logs, JSON exported from a SIEM. The trap is trusting the severity label, which is only the tool's opinion; the evidence sits in the events behind it. Tip: line up the timestamps first, then read the story they tell. Security analysis tools for CySA+ covers the tools whose output you will be reading.
Indicators of compromise
The task: decide whether an address, domain, file hash or process is malicious, and what to do about it. Practice by running one indicator through the lookups objective 1.3 names, such as WHOIS, reputation services and a sandbox. The trap: an atomic indicator such as an IP address is cheap for an attacker to change, so a behavior seen across several events usually carries more weight. Tip: before you decide, write down what would prove you wrong.
Vulnerability prioritization
The task: put scan findings in order of real risk. Practice on a scan export, ranking it by CVSS severity, EPSS probability, exposure to the internet and patch availability, the criteria objective 2.3 lists (CVSS vs EPSS explains the two scores). The trap: the highest CVSS base score does not automatically go first; an isolated internal host with no sign of exploitation can wait behind a lower score on an exposed server. Tip: give every rank a one-line reason.
Incident response and remediation
The task: order response actions, pick the next step, or recommend the fix. Practice CompTIA's seven-step process, preparation through post-incident, until the order is automatic, then attach concrete actions to each step. The trap: eradicating before you contain lets an attacker watch the cleanup and adapt; containment vs eradication vs recovery draws the lines. Tip: for any remediation, name what proves it worked, such as a clean rescan, a closed port or a quiet log. Writing that result up is objective 4.1, covered in vulnerability reporting for CySA+.
Reading data the way a PBQ asks
Oct 3 02:14:07 web01 sshd[4121]: Failed password for invalid user admin from 203.0.113.45 port 51122 ssh2Oct 3 02:14:09 web01 sshd[4121]: Failed password for invalid user oracle from 203.0.113.45 port 51130 ssh2Oct 3 02:14:12 web01 sshd[4127]: Failed password for deploy from 203.0.113.45 port 51141 ssh2Oct 3 02:14:15 web01 sshd[4127]: Failed password for deploy from 203.0.113.45 port 51148 ssh2Oct 3 02:14:19 web01 sshd[4133]: Accepted password for deploy from 203.0.113.45 port 51160 ssh2Oct 3 02:14:19 web01 sshd[4133]: pam_unix(sshd:session): session opened for user deploy by (uid=0)Oct 3 02:15:02 web01 sudo: deploy : TTY=pts/0 ; PWD=/home/deploy ; USER=root ; COMMAND=/usr/bin/crontab -eOct 3 02:31:40 web01 sshd[4133]: Received disconnect from 203.0.113.45 port 51160:11: disconnected by userRead it in order: guesses against accounts that do not exist (lines 1–2), then a real account (3–4) that gets in (5), then a root crontab edit a minute later (7), a common way to keep access. The follow-up decisions are the PBQ part: which account to lock, what to inspect in the crontab, which address to block. Invented for this page; 203.0.113.0/24 is a documentation range under RFC 5737.
What CompTIA does not publishNote
No PBQ count, no fixed position in the exam and no weight per item (checked October 2026). Claims otherwise come from individual candidates' reports. Plan your time around the CS0-004 question limit and clock instead of a guessed PBQ count.
Practicing for PBQs
Do this site's questions work like PBQs?
They are multiple-choice, so they train judgment rather than the hands-on format. Some items in the CySA+ practice test include a data exhibit to read, which exercises the same reading skill. For hands-on work, CompTIA sells CertMaster Labs, a live virtual lab; the CySA+ prep comparison lists it with other options.
Which objectives should I practice first for PBQs?
CompTIA does not map PBQs to objectives. Six CS0-004 objectives are framed as scenarios (1.2, 1.3, 2.1, 2.2, 2.3 and 3.3), and their skills match the tasks listed above, which makes them a sensible place to start. That is our reading of the CS0-004 objectives, not a CompTIA statement.
Are PBQs the reason CySA+ feels demanding?
They are one part of it, along with scenario wording and the breadth of tool output. The page on how hard the CySA+ exam is goes through each part.
Sources
- CompTIA blog: The New CompTIA CySA+ (V4), Your Certification Questions Answered · published June 12, 2026 (checked October 9, 2026)
- CompTIA CySA+ CS0-004 exam objectives, version 2.0 (PDF) (checked October 9, 2026)
- IETF, RFC 5737 (IPv4 address blocks reserved for documentation) (checked October 9, 2026)
Facts checked. Now practice.
Take CySA+ practice questions with you in our app for iPhone and Android.