Home > Blog > CompTIA CompTIA Security+ Certification Exam > Mastering Security+ PBQs: Analyzing Network Diagrams

Mastering Security+ PBQs: Analyzing Network Diagrams

Exam Tips Cert Sensei Team 2032-03-22 8 min read

To master Security+ PBQ network diagrams, you must identify security gaps by analyzing traffic flow and placing controls like firewalls, IDS/IPS, and ACLs strategically. Focus on isolating public-facing services in a DMZ and ensuring internal zones are protected from external threats through a layered, defense-in-depth architecture.

#Security+ #SY0-701 #Network Security #PBQ Tips #CompTIA

Why are network diagrams so critical for the Security+ PBQs?

Performance-Based Questions (PBQs) are the make-or-break part of the SY0-701 exam. Unlike multiple-choice questions, PBQs require you to apply your knowledge in a simulated environment. When you encounter a network diagram, CompTIA isn't just testing if you know what a firewall is—they are testing if you know exactly where to put it to stop a specific threat vector.

These questions typically fall under Domain 2: Architecture and Design. You'll be asked to drag and drop security appliances or configure settings on a virtual device to secure a topology. If you can't visualize how data moves from a user's browser to a backend database, you'll struggle. We recommend spending at least 15-20% of your total study time specifically on visual topology analysis to ensure you aren't blindsided on exam day.

How do you identify security gaps in a network topology?

The first step in any diagram PBQ is to look for 'flat networks.' A flat network is one where there is no segmentation, meaning once an attacker gains access to one device, they can move laterally to any other device without restriction. If you see a workstation in the same zone as a sensitive SQL database, you've found a major security gap.

Look for direct paths from the internet to internal assets. Any line that connects the 'External' or 'Untrusted' cloud directly to a core switch or a server without passing through a security appliance is a red flag. To fix this, you must apply the principle of least privilege to the network layer. Ask yourself: 'Does this device actually need to talk to that device?' If the answer is no, there should be a boundary in place.

Where should you place firewalls and IDS/IPS for maximum protection?

Placement is everything. Your primary firewall belongs at the edge of the network to act as the first line of defense. However, a single firewall is rarely enough. You should implement a layered approach, placing internal firewalls between different security zones (e.g., between the DMZ and the internal corporate LAN).

When it comes to Intrusion Detection Systems (IDS) and Intrusion Prevention Systems (IPS), remember the difference in their roles. An IPS is typically placed 'inline'—meaning traffic must pass through it—so it can actively block malicious packets. An IDS can be placed out-of-band using a TAP or SPAN port to monitor traffic without slowing it down. In a PBQ, if the goal is to 'stop' an attack, go with an IPS placed behind the perimeter firewall to analyze traffic that has already been filtered for basic port blocks.

What is the correct way to configure a DMZ?

A Demilitarized Zone (DMZ) is a neutral subnet that houses your public-facing services, such as web servers, mail servers, and DNS. The golden rule of DMZ configuration is that no external user should ever have a direct path to your internal network. The DMZ acts as a buffer; external traffic hits the DMZ, and only strictly controlled, authenticated traffic is allowed to move from the DMZ into the internal zone.

In a diagram, you'll often see a 'three-legged firewall' where one interface connects to the internet, one to the DMZ, and one to the internal LAN. Ensure that your rules allow HTTP/HTTPS (ports 80/443) into the DMZ, but block almost everything from the DMZ into the internal network. If you see a web server in the DMZ talking directly to an internal Active Directory controller without a firewall in between, that's a configuration error you need to correct.

How do you determine the best placement for ACLs?

Access Control Lists (ACLs) are your precision tools. While firewalls handle broad zone-to-zone traffic, ACLs manage specific IP addresses and ports on routers and switches. The general rule of thumb is to place extended ACLs as close to the source of the traffic as possible. This prevents unnecessary traffic from traversing your network and consuming bandwidth before it is eventually dropped.

Analyze the traffic flow: is it North-South (client to server) or East-West (server to server)? For East-West traffic, you want ACLs on the VLAN interfaces to prevent lateral movement. Always remember the 'Implicit Deny'—the invisible rule at the end of every ACL that drops any traffic not explicitly permitted. If a PBQ asks you to secure a segment, ensure your ACLs are specific and end with a deny-all statement.

How can practice exams help you master these visual challenges?

You cannot master network diagrams by reading a textbook; you have to actually solve them. This is why we built Cert Sensei to bridge the gap between theory and application. We provide 1,000 expert-curated practice questions for the SY0-701, specifically designed to mimic the complexity of the actual exam.

What sets our platform apart is the detailed expert reasoning. When you get a network placement question wrong, we don't just tell you the right answer—we explain the architectural 'why' behind it. Combined with our domain-level analytics, you can pinpoint exactly whether you're struggling with 'Architecture and Design' or 'Implementation' and focus your study hours where they matter most. Stop guessing and start analyzing with data-driven preparation.

❓ Frequently Asked Questions

Do PBQs carry more weight than multiple-choice questions on the Security+?

While CompTIA doesn't release exact weighting, PBQs are generally considered more challenging and critical because they test synthesis and application. Missing a complex network diagram PBQ can cost you more points than missing a few simple multiple-choice questions.


What is the most common mistake students make on network diagram PBQs?

The most common error is forgetting to isolate the internal network from the DMZ. Many candidates place the web server in the DMZ but leave a wide-open path to the internal database, which is a massive security flaw that CompTIA specifically tests for.


Should I study Cisco-specific diagrams or stay vendor-neutral?

Stay vendor-neutral. The Security+ is not a CCNA exam. Focus on the concepts of zones, boundaries, and the roles of appliances (Firewall vs. IPS vs. Load Balancer) rather than specific vendor command-line interfaces or proprietary hardware.

More from CompTIA CompTIA Security+ Certification Exam

🧠

Test Your Knowledge

Ready to practice CompTIA Security+ Certification Exam? Put what you've learned to the test.

Try 10 Free Questions

⭐ 1,000 expert-curated questions available with Premium

Upgrade Premium
📖 Browse the Glossary

Join thousands of certification students

Sign Up Free