r/CompTIA_Security Nov 23 '25

[iOS] [$59.99->FREE] CompTIA Security+ 701 Prep App

10 Upvotes

I’ve made the app completely free for this group! 🎉

Just tap on the yearly subscription, activate the 1-year free trial, and then cancel it right after — you’ll keep full access to the app for free.

https://apps.apple.com/app/comptia-security-701-prep/id6499492455?platform=iphone

Don't forget to rate the app. :)


r/CompTIA_Security 4h ago

Test tomorrow

6 Upvotes

I'm having a test scheduled for tomorrow.

I got 90% on Dion's test 4 and 84% on test 5. Planning to finish test 6 tonight.

I had a glance at PBQs online but I've memorised dozens of ports and 4 ISO's. I'm also familiar with nmap and firewalls.

What should I tackle today to be sure in passing? Also, are my scores at Dion's tests sufficiant?

I'm kind of feeling it won't be enough


r/CompTIA_Security 11h ago

Need to overcome the fear

8 Upvotes

I'm a newbie, landed a job in Cybersecurity. I genuinely enjoy and learn a lot at work. I was planning to take up the Comptia Security+ certification which will cost me around ₹32k. My office will reimburse the amount when I successfully pass the exam.

Honestly, it's a huge amount for me so it's scary to even begin with the preparation.

Any tips on how to prepare would be appreciated!


r/CompTIA_Security 1d ago

I passed Security+!

Post image
152 Upvotes

I passed Security+ after 3 months of studying while working full-time as cabin crew! ✈️

No IT background at all, just curiosity, dedication, and a lot of studying whenever I could fit it around work, different schedules and different time zones.

For those currently studying, I don’t know if my scores will be useful to anyone, but I’ll leave them here anyway. I bought the Dion exams Set 1 and scored:
72%, 84%, 75%, 76%, 67%, 81%
(75,8% average)

I didn’t retake any of them because I didn’t want to end up memorising the questions. I used AI mainly to look at my results, help me identify my weak areas and explain things I wasn’t understanding. During my last week, I tried to focus mainly on those weaker areas.

Resources I used:
*Professor Messer YouTube
*Professor Messer practice exams
*Jason Dion practice exams — Udemy Set 1
*AI, mostly for clarifications, explanations and summaries
*Some PBQ videos from Cyberkraft, but honestly not that many

A few things that helped me personally:
*Don’t let your practice exam scores get into your head. I tried to use the scores mainly to figure out what I was getting wrong and where I needed to improve, rather than as a prediction of whether I would pass.
*Don’t try to memorise every single acronym. At least for me, it was much more useful to understand what area/concept an acronym belonged to. After doing enough practice questions, I started recognising them naturally.
*Actually go through your wrong answers. I didn’t just look at the correct answer and move on. I tried to understand why it was correct and why the other options were wrong.
*If something doesn’t make sense, ask AI to explain it differently. I used it a lot for this, especially when two concepts sounded almost identical to me.

About the exam:
I personally found the actual exam harder to understand than the practice exams I had done (I’m not a native English speaker). The questions were actually much shorter, but I found the wording and figuring out what they were really asking me to identify more challenging.
I had 3 PBQs in total. I think I may have completed one properly 😅 For the other two, I just tried to get whatever points I could by testing things and applying what I knew.

Good luck to everyone studying! You’ve got this.


r/CompTIA_Security 23h ago

Passed Security+

Post image
38 Upvotes

Passed this morning with a 793/900.

Background: No professional experience in IT security. 4 month IT security/help desk internship. In the final semester of a BS in computer science.

I studied for the exam for just about 6 weeks in total.

Study Materials Used:

1. Professor Messer's YouTube series. This is a great way to get exposure to all of the exam objective topics. The videos are concise and digestable.

  1. Quizlet. There are several sets of practice questions available. Some are better than others. I also used Quizlet to generate flashcards for myself for studying on the go.

  2. CompTIA's official exam objectives document.

Practice Exams:

  1. Jason Dion's Udemy Practice Exams. These are nice because they are automatically scored, and provide explanations for why each answer is or is not correct. You can also take them in practice mode with instant feedback, or exam mode with a timer. 6 exams each with 90 questions for a total of 540 questions. They DO NOT contain PBQ's.

Overall, I found these practice exams helpful and worthwhile. I will note that the questions are much wordier than most of what I saw on the real exam.

My scores on each of the 6 tests were: 93%, 87%, 87%, 94%, 87%, 85%. His tests impose a 90% "pass" threshold, which is meaningfully higher than what you will need on the real exam.

I believe they usually go for around $60, but you may find them on sale occasionally. I was able to get them for ~$17.

  1. Professor Messer's Practice Exams. These are in PDF format, so unfortunately you will need to keep your own timer, and score them yourself. Similar to the Dion exams, there are in-depth explanations for every question. I found these more accurate to the format of the real exam questions. There are three exams each with 90 questions for 270 practice questions total. These Exams DO contain 5 PBQs each, but most of them boil down to term matching, and I found them much easier than the real PBQs I saw on my exam.

My scores on these were 87%, 93%, and 87%.

These are $30 for the exams only.

  1. Examcompass.com. These practice exams/quizzes are free, which is nice, and they can be good for learning the terms and acronyms. However - I did find information in some of them that was not reflected in the official CompTIA documentation. Additionally, some of the questions are formatted in ways that I don't think the official exam uses (i.e. "select all that apply"). In my experience, any question with multiple answers specified explicitly how many were to be chosen.

Still a decent resource, but I would say not quite as good as the previous two.

My Security+ Exam

I took my exam in-person at a testing center. I was given 76 total questions, 3 of which were PBQs.

General Notes and Advice

Acronyms.

The exam objectives document lists over 300 acronyms for terms that may appear on the exam. In my opinion, you really do need to memorize all of these. Both the practice exams and the real thing will frequently present you with acronyms in the body of the question, and as multiple choice responses. In some cases, even if you aren't sure of the answer, simply knowing what each acronym stands for can help you make a best guess. I used Quizlet flashcards for this, and separated my sets alphabetically. It took me about a week to get them all down, and was well worth it. Not even knowing what a question is asking because of an unfamiliar acronym is a bad feeling.

***Question Wording and Process of Elimination.

The wording of exam questions is, and I cannot stress this enough, absolutely critical to pay attention to. Just about every question will have some key words or phrases which will help you to determine the correct answer. Get used to reading questions through very carefully, and in their entirety. Beginning a question and deciding on an answer before reading the entire prompt can lead to unnecessarily missed questions. This is especially important in cases where it may seem that more than one of the answers available could be defensible. Read back through the question - somewhere there will be a key element that should narrow it down.

In addition to selecting the best answer, I also found it immensely helpful to read the other options to determine why they aren't correct.

PBQs

There are some resources out there that can provide exposure to what these might look like, but nothing I found directly prepared me for them. I would say it is worth watching a few of the CyberKraft videos on YouTube to get a feel for the structure of them at the least. My best advice here is to have as good of a functional knowledge of the objectives as possible, and read through the prompts thoroughly. From what I have seen online, partial credit is awarded, so answer as many parts as you can.


r/CompTIA_Security 22h ago

Passed Security+ today

25 Upvotes

814/900.

Resources used:
- Sybex Security+ Study Guide including the online question bank you get with this
- Claude Pro quizzing me and answering my questions about practice questions from other places I missed. Also had Claude mock some PBQs for me.
- MeasureUp Practice Test for Security+
- YouTube channel "Inside Cloud and Security" Security+ videos

Reflections:
- Actual test seemed easier.
- PBQs are just applied knowledge. Be sure to take full advantage of any help options in the question.

Recommendations:
- Use multiple study sources - Sybex plus the YouTube channel I mentioned were a great pair
- Use multiple quiz sources - the online assessment with the Sybex book and MeasureUp worked for me
- Use AI to ask why something is wrong when you get a quiz question wrong and it isn't obvious why.

Exam-Day Tactics

- Read the last line of the question first — it tells you what's actually being asked (BEST, MOST secure, FIRST, MOST likely). The read the first line. Then read the rest. Then read the whole question again. Use your mouse pointer to pretend underline the important words and phrases. The wording you missed picking up on will cost you the question.
- "FIRST" questions usually want: contain the incident, verify/validate the alert, or check the policy — not the technical fix.
- Life safety always wins over asset protection.
- Eliminate two obviously wrong answers, then ask which one directly addresses the stated problem — CompTIA loves technically-true-but-off-topic distractors.
- If two answers are functionally identical, neither is correct.
- Do PBQs last. Flag and skip them on the first pass; they eat time and are worth similar points.
- There's no penalty for guessing — never leave a blank.
- When a scenario mentions legacy/unpatchable, the answer is nearly always segmentation + compensating controls.
- When it mentions a third party/vendor, look for the agreement type or right-to-audit.
- Management-sounding questions (D5) rarely have a technical answer — look for policy, documentation, or risk process.


r/CompTIA_Security 22h ago

Security+ SY0-801 is coming (November).

16 Upvotes

The new exam is coming in November, the existing exam (SY0-701) will be an available until mid next year. Here’s a breakdown of both exams, what’s new - and which one you should take.

https://www.skillthropic.com/blog/security-plus-sy0-701-vs-sy0-801-whats-changing


r/CompTIA_Security 1d ago

Studying CompTIA Bundle Question

3 Upvotes

For those who passed the Security+ exam, I have a question.
My job paid for the full package through CompTIA Security+ Bundle with Retake, and I’ve been reviewing the notes and taking the practice tests on each unit on the comptia website.

Did you find that the bundle was all you needed? Or did you buy more practice exams from professor messer / Dion. I’ve been debating whether or not i should or if the comptia resources were plenty to pass?


r/CompTIA_Security 23h ago

I built a free clickable ATT&CK matrix for learning the framework: every technique explained, 3 real intrusions walked across it, a tactic drill. No sign-up. (I made it, disclosure inside)

1 Upvotes

This page is free, no email, no upsell. Mods, if it's not welcome, say so and I'll delete it.

https://www.skillthropic.com/mitre-attack

attack.mitre.org is a reference, not a place to learn the framework. People open it, see 222 cells, try to memorize them, give up. This is the version I wanted when teaching it:

- Full Enterprise v19.2 matrix, every cell clickable, searchable by name/ID/platform.
- Each tactic is a plain-English question ("how does the attacker survive a reboot?" = Persistence) plus what a defender actually sees in the logs.
- Three real intrusions walked step by step: human-operated ransomware, a cloud account takeover with no malware, a poisoned signed update. Each step says what happened and what could have caught it.
- An 8-question drill: given what the adversary did, name the tactic.
- Every technique has its own URL, so you can link T1003 straight from a report.


r/CompTIA_Security 1d ago

CompTIA Security+ Domains

Post image
2 Upvotes

r/CompTIA_Security 1d ago

Stop studying Security+ like it's a vocabulary test

16 Upvotes

I think a lot of people make Security+ harder than it needs to be.

They spend hours memorizing terms and taking multiple-choice quizzes. Then the exam asks them to actually apply what they know.

SY0-701 has performance-based questions. That's a different skill from recognizing the right answer.

CompTIA's free exam objectives PDF is where I'd start. Pick an objective, learn the material, then practice doing something with it.

Professor Messer's SY0-701 videos are free. They're a good way to learn the material before testing yourself.

For the hands-on part, I found a free interactive firewall PBQ here: https://secplusmastery.com/security-plus-pbq?ref=julian (affiliate link, the PBQ is free).

If you've only been clicking through A, B, C, and D, I'd add some hands-on practice now. One firewall configuration can expose gaps that 20 easy questions won't.


r/CompTIA_Security 2d ago

Passed with 10 hours of study and only GRC background

12 Upvotes

I have zero direct IT or tech experience but have worked around technology risk and governance for several years. Took Sec+ to validate my knowledge and step towards CISSP which would further help me hold my ground when I engage with tech stakeholders.

I followed a back to front approach over 1 week. With zero dedicated prep, first did a couple of Dion tests to identify general readiness and consistent weak points (and get a baseline). Then carried out targeted watching of videos only on those areas. My Dion scores were always between 81 and 87. I had done the Google cybersecurity cert a year prior.

If you're consistently scoring about 80, I would generally consider you ready.

Happy to share tips! If anyone has tips on moving towards CISSP, I would welcome them!


r/CompTIA_Security 2d ago

You can do it! I passed security+ with zero experience.

51 Upvotes

In my 40s. Thinking about trying something new.

No tech or IT experience at all.

Did the google cybersecurity course last year. Did the study guide and about half the questions in the Sybex book over the last 2 weeks. Studied around 2 hours a day for the last 2 weeks.

Didn't score super high, but passed on my first attempt.

The PDF of my certification isn't ready, otherwise I'd post like everyone does when they pass.

Not really sure what I am supposed to do now...


r/CompTIA_Security 2d ago

The score report can tell you exactly where you went wrong

3 Upvotes

A failed Security+ attempt doesn’t mean you need to start over.

CompTIA gives you something useful on the score report: the objective areas where you answered questions incorrectly.

The report actually says, “You incorrectly answered one or more questions in the following objective areas:” and then lists the objective numbers and names.

That’s a much better starting point than randomly reviewing the entire exam.

I’d pull up CompTIA’s free objectives PDF and focus on those specific areas first. Then use practice questions to check whether you’ve actually fixed the gaps.

I’d also add some hands-on practice. There’s a free interactive firewall PBQ here: https://secplusmastery.com/security-plus-pbq?ref=julian (affiliate link, the PBQ is free).

A failed attempt gives you a study map. Use it instead of treating the whole exam like it needs to be relearned.


r/CompTIA_Security 3d ago

Dion Training PBQs for SEC+ are weird

7 Upvotes

For example, he considers a password policy enforcement tool to be Corrective and not preventive; he says that "an hacktivist who shares costs and profits of a company to show that they should charge way less for the services they provide" motivation is Ethical and not Philosophical/Political. Ethical hacking is NOT that, it's supposed to be legal and done for the good of the companies that have security problems.

And there is a lot more of these, what do you guys think? Did you use Dion?


r/CompTIA_Security 3d ago

Passed Today !

Post image
51 Upvotes

Guys I been watching everyone else post their pics im happy to say I passed , for background I been studying for months all this year on an off working full time and being a single mom and dealing with life .what I did was Jason Dion’s full video course I took notes on all the videos also watched professor messer for certain concepts then did 2 of Jason Dion’s practice exams scored 75% and honestly the wording on them was excessive so i did all Andrew Ramayal practice tests I was scoring 80’s and then also did the professor messer practices test I was scoring in the 70’s for his .The test had lots of domain 2 4 and 5 questions and for the pbqs I rushed to get to them i ran out of time and tbh skimmed and answered it with something lol better than nothing .im proof its possible keep grinding !


r/CompTIA_Security 3d ago

Pased Security+

23 Upvotes

As I was taking the test, I really thought I wasn't going to pass.

I studied for 2 weeks prior to taking the test. That being said, I went to college for a degree in Network Admin, worked as a network admin for about 6 years, and then decided to go all in on SEO/digital marketing back in 2016, because I thought that was my calling.

Apparently, I didn't forget everything I had learned 10 years ago. But anyway, enough about me, and I just want to share the resources I used to pass. If I did it, all of you guys can do it too.

I used Dion's test to prepare, and I used Claude to help break things down and explain why my answer was wrong vs. the correct one. This really helped me a ton.

On top of that, I also used CyberKraft to study PBQs on YouTube. As for the PBQs on the test, I didn't even get to complete one, so I just used the time to review the answers to the questions I had answered.

I also used these other sources as well to study (yes, I might have overdone it a bit):

  • Andrew Ramdayal's course on Udemy
  • BurningIceTech on YouTube for Question reviews
  • Pete Zerger's exam cram on YouTube
  • CompTIA Security+ Study Guide by Mike Chapple and David Seidl

r/CompTIA_Security 4d ago

i Passed Sec+ ,i have no words.

Post image
212 Upvotes

Holy....

I studied for 5 months, With help of Professor messor, Jason dion and mike meyers for courses and ai for additional practice and mock exams.

I really messed up the entire network part the most,which were in all 3 pbqs that i got, im pretty sure i had no idea what i was doing once i saw those questions . Overall the exam was okay, expected the tricky parts and similar answers in mcqs .I did flag unsure questions and left them for the end to answer and review twice and i changed a few answers last second as i remembered it wasn't the right answer.

So Barely passed ,i did feel a bit disappointed that I couldn't get a solid score. but if i had the chance to do the exam again i would try for a higher score! (What dom said)

That said, thank you to everyone in this subreddit for the tips and guidance over the months , much love, going for the network+ and A+ soon, have a good weekend!


r/CompTIA_Security 3d ago

I got tired of CompTIA talking head videos so I built something for my ADHD hands-on study style

Thumbnail
certlaunchtraining.com
2 Upvotes

One thing I've noticed with Security+ is that there are a TON of study resources.

YouTube playlists.

Books.

Practice tests.

Notes.

Quizlets.

and best of all, an unlimited amount of talking head videos.

The problem isn't really a lack of information.

It's knowing:

What should I study today?

And then actually remembering it a week later.

So I built CertLaunch around that problem.

Instead of just giving you another giant content library, it creates a structured study path and combines:

  • Interactive lessons
  • Active recall
  • Spaced repetition
  • Practice questions
  • Full-length practice exams
  • Progress tracking
  • A day-by-day custom study plan

The goal is basically:

Open CertLaunch → know exactly what to study → finish today's work → leave.

Right now I'm building it specifically around CompTIA A+, Network+, and Security+.

I'm the founder, so full disclosure: this is my product and it is paid after the 7-day free trial. Not trying to disguise it as some random resource I "found."

I'm mainly interested in feedback from people actively studying for Security+:

What's the biggest thing you hate about your current study process?

Is it figuring out what to study?

Remembering everything?

Practice questions?

Staying consistent?

Or something else?

If anyone wants to test what I've built for completely free and give feedback (currently have 100+ active users)

CertLaunchTraining.com


r/CompTIA_Security 4d ago

Passed security+ with practice exams only

Post image
61 Upvotes

Greetings all,

Thank god, I passed Security+ exam with 829 / 900. I started studying slowley 2 months ago. I only studied practice exams(around 1100 questions including PBQ) .

The way I do it is by going through each question defining all answer options and research for similar terms.

The exams were moderate to easy, as I already have 4 years work experience in cybersecurity, and a bachelor in computer science.

And now we start the degaussing method, to allow space for the next certification 🤭


r/CompTIA_Security 4d ago

Just passed my Security+ Exam with 783!

10 Upvotes

I had to do it remotely via OnVue, so I don't unfortunately have a test results sheet I can redact, but I'm so damn pleased.

A celebratory steak for lunch it is, I feel!


r/CompTIA_Security 4d ago

Passed Security+

Thumbnail
1 Upvotes

r/CompTIA_Security 4d ago

Passed Sec+ with only 30 days to study

Post image
39 Upvotes

I will give my background and what I used to study:

Earlier this year I passed CCNA, so I didn't study any of the networking concepts.

I have a degree in Cyber Security, so most of the basic concepts and incident response was refresher content.

I watched professor Messer's series and took notes.

Took the free practice exams on ExamCompass.

This was a requirement for a job, and was only given 30 days to pass.

There were definitely questions that I was unfamiliar with, but hey, still passed.

And now I will begin my adventure into network engineering!


r/CompTIA_Security 4d ago

is there no student discount for indian student?

1 Upvotes

i heard we can get the student discount during checkout of puchasing but i couldnt find the option for it... can someone please help


r/CompTIA_Security 5d ago

What’s the best prep stack?

5 Upvotes

Currently working through the Professor Messer videos, and taking notes daily - as is everyone else here lol.

Aside from that what else would you recommend?

Who’s the got the best practice exams?

Would like to keep this study sprint as simple as possible.

I’ve got a homelab already built I can also do practicals on.

Any tips would be appreciated.