A couple of weeks ago I had the pleasure of taking (and passing!) the CompTIA Security+ certification exam. I had my eye on this certification for a while now, but the last few months I really decided to hunker down, study and finally take it. It was quite the journey with lots of lessons learned, which I will be happy to share with you.
Starting point
At this point, I had already been working as a Security Engineer for a few years after a three year apprenticeship, so I had a good amount of experience under my belt. I had a good grasp on network technologies and services, various operating systems, cryptography as well as information security frameworks like ISO27001 and CIS Benchmarks for hardening. Thus, I probably had a better starting point than most people who take this entry-level exam. Nevertheless, I was convinced that it was a worthwhile undertaking to fill most of the gaps in my knowledge and make me a more well-rounded security professional. Two of my closest colleagues were interested in the certification as well, so we quickly formed a study group and went at it.
Our study method
The exam consists of five different domains:
1.0 Attacks, Threats, and Vulnerabilities (24%)
2.0 Architecture and Design (21%)
3.0 Implementation (25%)
4.0 Operations and Incident Response (16%)
5.0 Governance, Risk, and Compliance (14%)
We planned to tackle one domain each week for a total of five weeks of study (and ended up taking an extra week for the Implementation domain since that one is massive and all three of us did not get to study quite as much as we would have liked that week). This made a nice round six weeks total of study time, which worked out great. I have heard reports from people who have completed Security+ in two to three weeks, and honestly if you are able to study full-time you can probably get away with that. But since we studied alongside our regular job we allowed a bit more time. Every domain we divided up evenly amongst the three of us and got to work on our assigned chapters.
Since neither of us was a blank slate in terms of IT or security know-how, we figured it would be best to work out the material in the respective chapters that was previously unknown to us. This turned out to be quite a bit more than we had hoped, but still cut down the workload by a significant margin. We met up twice a week, once to discuss our findings, and once after we had time to catch up with the remaining chapters to discuss questions. Towards the end we increasingly incorporated practice tests to get a feel for the questions and identify blind spots.
As Europeans, we found it a bit alienating that the certification is unquestionably very US-centric. Many frameworks and legal requirements are US or North America only and did not apply to us. Also, the concept of mandatory holiday as a security measure to detect illicit work practices and not as a means to ensure your employees are well-rested just seemed wild.
I personally made an effort not to blindly memorise, but to jot down questions that arose while going through the chapter and answering them afterwards, for example “What is the difference between a rogue access point and an evil twin?”. This greatly improved understanding and made the knowledge stick. Some things you just have to sit down and memorise, though (Hello, order of acquisition in forensics!).
Study material
Two of us had access to a bunch of books through an O’Reilly subscription, which we supplemented with some additional material. Through this subscription we also had access to some official Pearson practice tests. One of the biggest problems we faced was that all of the books we used had some flaw of another, some of which were considerable:
CompTIA Security+ All-in-One Exam Guide by Conklin et al. – This was our main source and overall quite good to work with. It goes through the objectives one-by-one and gives concise explanations as well as helpful exam tips. Every chapter has practice questions at the end which can be helpful, albeit sometimes confusing.
Be careful though: The definition of crypto-malware in this book is wrong! It confuses crypto-malware with cryptominers or cryptojackers. We only found this out through our discussion,. Quite embarrassing.
CompTIA Security+ SY0-601 Cert Guide by Omar Santos et al. – This I used as a second source to cross-reference the material of the Conklin book after the crypto-malware fiasco. The text is well written and researched and each chapter has a “do I know this?”-quiz at the beginning so you can gauge how much you should invest into this chapter. However, the text is often too detailed and doesn’t follow the exam objectives closely enough. Also the review questions at the end of each chapter were not very helpful. There were some minor inaccuracies, especially in the cryptography chapters, but nothing too serious.
CompTIA Security+ SY0-601 Exam Cram by Diane Barrett and Martin M. Weiss – this one I used towards the end for some quick referencing and summary. Nothing I would spend money on if I didn’t have the subscription.
CompTIA Security+: SY0-601 Certification Guide by Ian Neil – The colleague without the subscription bought this one. I am very sorry, but it’s awful. There were many inaccuracies, missing objectives and it literally gives the wrong definition of RPO! Steer clear of this one!
Prof. Messer’s well-known videos – On occasion we also used these for cross-reference. If you’re on a budget this is probably the only source you need. His explanations are very clear and easy to follow and he covers almost all of the objectives. Just make sure you don’t just mindlessly consume but actively study, ask yourself questions and take notes.
The exam
For the exam I chose an PearsonVUE test centre close to my workplace, as luckily I was allowed to take the exam during working hours. The test centre staff was very polite and certainly less pedantic than I had feared, although they did make sure that proper procedure was followed. The centre itself was decent, very little to complain about here. The only issue I had was that the exam room had a window cracked, which allowed me to hear the noisy conversation of the people of the neighbouring office buildings in the yard. This was quite distracting, but not enough to do anything about.
Obviously, the exam terms prohibit dissemination of exam content, so I cannot mention any concrete questions. What I can mention, though, is that many questions were quite different to the practice tests I had done before, even though those were also by Pearson. Many featured inquiries as to the “most likely” or “best way” to do something, with several plausible answers. This certainly stumped me and I definitely left a few points behind because of it. Nevertheless, it was enough to pass, even though the score was a bit lower than I had hoped.
My recommendations
- Set yourself a schedule and stick to it. It helps to have a set exam date, be it already booked or just a mental target. Keep in mind though that the course material is fairly wide, so don’t underestimate the scope of this exam. Also, allow yourself enough buffer to counteract busy weeks or illness
- While studying, don’t just blindly read and re-read the same material over and over again. Dissect the material, write down problems and questions and try to answer them yourself. With every iteration, try to identify the parts you still struggle with and work on these specifically
- When taking notes, don’t just paraphrase what you read or hear. Try to put things in context for yourself, this will help with memorisation
- Remember that this is not just for a shiny badge but for your own professional education, so try to put what you learn into practice if you can
- Limit your study material. Just Prof. Messer’s videos or 1-2 books should be plenty
- There probably will be questions that completely catch you off-guard. Don’t let this get to you. If you have studied well you will be able to pass the exam regardless
- Don’t panic and remember to have fun!
Conclusion
I can whole-heartedly recommend Security+. It certainly fulfilled my expectations of making me a more well-rounded security engineer and giving me a good overview of cybersecurity topics. It is an entry-level certification, so the topics don’t go super deep. But in my opinion it is worth it even for more seasoned individuals. I believe our methods were sound and our success speaks for itself. I would certainly choose to do the certification again and wouldn’t change too much about my process.
I hope this helped you on your way towards Security+. Best of luck and all the best for your security journey.
Any questions, comments or remarks? Feel free to interact with me on Mastodon.
