TDM

How I got the CompTIA Security+ (701) certification?

As part of a project that is not the subject of this article, I prepared for and obtained the CompTIA Security+ 701 certification.

I prepared for the exam over two months. During the first month, I had at most one hour a day to dedicate to preparation. The second month, I did almost nothing else and spent about three hours a day on it.

Given that there are very few French-language testimonials, I’d like to share mine.

My background

I wasn’t starting from scratch, as I have the advantage of having a two-year technical degree in computer science and nearly 15 years of experience in the web field. Not directly in technical roles, but I’ve always liked getting my hands dirty: writing scripts, reading logs, setting up web servers, … which proved very useful. It’s much easier to understand what an SQL injection is if you’ve already had the chance to run queries on a database.

Similarly, you’ll save a lot of time on all the cryptography sections if you know what a hash function is, are familiar with private key/public key concepts, or are interested in blockchain, for example.

On the downside: no experience in cybersecurity and an average level of English. I scored 790 on the TOEIC two years ago for those who want to compare. However, all the learning material is in English. And the exam is also in English (it’s also possible to take it in Japanese, but that won’t help most of you). Since it’s technical English and not Shakespeare, it didn’t seem insurmountable to me. And it’s an opportunity to get started and improve.

Two important tips

Two tips I “borrowed” from others that seem very relevant:

  • Buy the exam voucher and book your test date now! This gives you a deadline and will reduce your natural tendency to procrastinate. In the worst case, you can reschedule.
  • Download the “Exam Objectives”: this is the list of topics that are likely to be on the exam. There are exactly 662 of them. The Security+ exam offers no surprises; all questions refer to these Exam Objectives, no more, no less. If you can explain each of them in a few words (without going into technical detail) … you’re ready for the exam.

My study method

I started by watching videos from the famous “Professor Messer” on YouTube. His videos are highly appreciated by many candidates because they are 100% free and cover all the “Exam Objectives”. Some people just watch all his videos before taking the exam and pass!

If I watched many of his videos, it wasn’t my favorite. I found some videos too dense, others not detailed enough.

So I decided to read the book “Security+ Study Guide” by Mike Chapple. It’s a hefty tome, over 1,000 pages. The first book I’ve read entirely in English! It’s an effort, but at a chapter a day, it goes well, and it’s worth it.

After finishing that reading, I was still far from solid on all chapters, so I took Andrew Ramdayal’s Udemy video course, which I highly recommend. He offers a program to pass the exam after 30 days of study, and I really think it’s doable.

I then read a second book: “Security+ Get Certified Get Ahead” by Darril Gibson. But this time, really skimming, only stopping on the parts I didn’t feel comfortable enough with.

In parallel with all that, whenever I came across a new concept or acronym I needed to remember, I made little flashcards to add to the spaced repetition learning app Anki. I had discovered the principle of spaced repetition a few months earlier while randomly watching this YouTube video. I used it for the first time for the Security+ certification, and it’s absolutely deadly! Anki will definitely become a routine whenever I have new knowledge to memorize.

Finally, I did tons of practice tests. Some on Udemy (Jason Dion’s) which have the advantage of simulating exam conditions: you have a limited time, you go through all the questions, and you get the result and answers at the end.

And through the book “CompTIA Security+ Practice Tests” by David Seidl which offers 1,000 questions/answers (1,000 according to the unions, slightly less according to the police). Anh had copy-pasted everything and rigged up an Excel spreadsheet to create PDF files of 100 questions covering all chapters, allowing me to calculate my pass score. As soon as you consistently score above 80% correct answers, you’re probably ready!

The downside of all this is that it remains very academic. You’ll gain knowledge in cybersecurity, but by no means skills. If you’re like me and need to understand more deeply how things work and what they’re for, a good solution might be to do “labs”. A few months before preparing for the exam, I spent many hours on TryHackMe and think it was very useful.

The remote exam

The Security+ exam can be taken in person at a test center or remotely.

There are centers all over the world. I was in Buenos Aires, Argentina, and there were three centers available.

However, I preferred to take the test remotely. I had fast and reliable internet and preferred to spare myself the additional stress of commuting.

Please note that if you don’t take the test in your country of residence, as was the case for me, you need to get authorization from CompTIA before scheduling your exam date. In my case, I got the authorization quickly, within 24 hours.

For a remote exam, I recommend preparing your exam space the day before. You need to install and test the software on your computer. Plug your computer into a power source if it’s a laptop. On your desk, you should have your computer, your keyboard, your mouse, and absolutely nothing else! If you have a second screen, you must remove it.

The “check-in” for your exam can start 30 minutes before the exam time. You’ll receive a link to open from your phone, and you’ll need to:

  • Take a selfie
  • Take a photo of your ID
  • Take three photos of the room you’re in

Once that’s done, you go back to your computer, a sound, microphone, and webcam test is performed, and then you enter the “waiting room”.

From that point on, it’s no joke: if you leave the webcam’s field of view, you’re disqualified; if someone else walks into the webcam’s field, you’re disqualified; if you speak, you’re disqualified…

When I entered the waiting room, it said I had five people ahead of me. I think this waiting room is just for a supervisor to check your photos and authorize you to start the exam.

I went through a bit of every emotion. I was already stressed by the wait, then after a few moments, a message appeared saying the process was taking longer than usual.

Then, when there were only 3 people ahead of me, a message appeared saying my exam couldn’t start, that I had to click a link to contact support to fix the issue or reschedule the exam. I never figured out how to contact support… Eventually, going back to the waiting room window, I only had one person ahead of me, and the exam was able to start!

If English isn’t the official language of your nationality, you automatically get an extra 30 minutes, making it 120 minutes total, for about 80 questions (it varies; you might have a few more or fewer). In my case, it was more than enough; I was able to go through all the questions again and still had time left.

The first questions are the PBQs (Performance-Based Questions), which take more time than the multiple-choice ones. I had three on my exam, but it can vary. I recommend skipping them and coming back later (there’s a flag icon you can click to mark questions for review).

Overall, I found the questions easier than those I’d done in my many practice tests. There was one question that really stood out because, in my opinion, there was no correct answer. But CompTIA says there can be “test” questions that don’t count, and I think that was one.

After taking the time to go through all the questions a second time, it’s time to finalize the exam. At that moment, your heart rate is at its peak. CompTIA is sadistic because right after you confirm your answers, they ask you to fill out a survey of about fifteen questions… And your score only appears after you complete that survey… which I rushed through as fast as possible.

The result appears: I passed!

Final score: 782/900 (the minimum score needed is 750), which is almost 87% correct answers, whereas I usually scored between 80% and 85% on my practice tests. So happy! Huge relief! It’s not as easy to get back into exam mode at 37, you’re out of practice!

One last stress factor: I couldn’t take screenshots of the result, and you have to wait 24 hours before getting the confirmation email! There’s no way to see the result again, and you start to get paranoid wondering, “Did I really read the result right??”

That’s my experience for you; it was my very first certification, and it certainly won’t be my last!

Comments Off on How I got the CompTIA Security+ (701) certification?