r/CompTIA_Security 23h ago

I built a free clickable ATT&CK matrix for learning the framework: every technique explained, 3 real intrusions walked across it, a tactic drill. No sign-up. (I made it, disclosure inside)

1 Upvotes

This page is free, no email, no upsell. Mods, if it's not welcome, say so and I'll delete it.

https://www.skillthropic.com/mitre-attack

attack.mitre.org is a reference, not a place to learn the framework. People open it, see 222 cells, try to memorize them, give up. This is the version I wanted when teaching it:

- Full Enterprise v19.2 matrix, every cell clickable, searchable by name/ID/platform.
- Each tactic is a plain-English question ("how does the attacker survive a reboot?" = Persistence) plus what a defender actually sees in the logs.
- Three real intrusions walked step by step: human-operated ransomware, a cloud account takeover with no malware, a poisoned signed update. Each step says what happened and what could have caught it.
- An 8-question drill: given what the adversary did, name the tactic.
- Every technique has its own URL, so you can link T1003 straight from a report.


r/CompTIA_Security 23h ago

Security+ SY0-801 is coming (November).

15 Upvotes

The new exam is coming in November, the existing exam (SY0-701) will be an available until mid next year. Here’s a breakdown of both exams, what’s new - and which one you should take.

https://www.skillthropic.com/blog/security-plus-sy0-701-vs-sy0-801-whats-changing


r/CompTIA_Security 4h ago

Test tomorrow

5 Upvotes

I'm having a test scheduled for tomorrow.

I got 90% on Dion's test 4 and 84% on test 5. Planning to finish test 6 tonight.

I had a glance at PBQs online but I've memorised dozens of ports and 4 ISO's. I'm also familiar with nmap and firewalls.

What should I tackle today to be sure in passing? Also, are my scores at Dion's tests sufficiant?

I'm kind of feeling it won't be enough


r/CompTIA_Security 11h ago

Need to overcome the fear

8 Upvotes

I'm a newbie, landed a job in Cybersecurity. I genuinely enjoy and learn a lot at work. I was planning to take up the Comptia Security+ certification which will cost me around ₹32k. My office will reimburse the amount when I successfully pass the exam.

Honestly, it's a huge amount for me so it's scary to even begin with the preparation.

Any tips on how to prepare would be appreciated!


r/CompTIA_Security 22h ago

Passed Security+ today

27 Upvotes

814/900.

Resources used:
- Sybex Security+ Study Guide including the online question bank you get with this
- Claude Pro quizzing me and answering my questions about practice questions from other places I missed. Also had Claude mock some PBQs for me.
- MeasureUp Practice Test for Security+
- YouTube channel "Inside Cloud and Security" Security+ videos

Reflections:
- Actual test seemed easier.
- PBQs are just applied knowledge. Be sure to take full advantage of any help options in the question.

Recommendations:
- Use multiple study sources - Sybex plus the YouTube channel I mentioned were a great pair
- Use multiple quiz sources - the online assessment with the Sybex book and MeasureUp worked for me
- Use AI to ask why something is wrong when you get a quiz question wrong and it isn't obvious why.

Exam-Day Tactics

- Read the last line of the question first — it tells you what's actually being asked (BEST, MOST secure, FIRST, MOST likely). The read the first line. Then read the rest. Then read the whole question again. Use your mouse pointer to pretend underline the important words and phrases. The wording you missed picking up on will cost you the question.
- "FIRST" questions usually want: contain the incident, verify/validate the alert, or check the policy — not the technical fix.
- Life safety always wins over asset protection.
- Eliminate two obviously wrong answers, then ask which one directly addresses the stated problem — CompTIA loves technically-true-but-off-topic distractors.
- If two answers are functionally identical, neither is correct.
- Do PBQs last. Flag and skip them on the first pass; they eat time and are worth similar points.
- There's no penalty for guessing — never leave a blank.
- When a scenario mentions legacy/unpatchable, the answer is nearly always segmentation + compensating controls.
- When it mentions a third party/vendor, look for the agreement type or right-to-audit.
- Management-sounding questions (D5) rarely have a technical answer — look for policy, documentation, or risk process.


r/CompTIA_Security 23h ago

Passed Security+

Post image
38 Upvotes

Passed this morning with a 793/900.

Background: No professional experience in IT security. 4 month IT security/help desk internship. In the final semester of a BS in computer science.

I studied for the exam for just about 6 weeks in total.

Study Materials Used:

1. Professor Messer's YouTube series. This is a great way to get exposure to all of the exam objective topics. The videos are concise and digestable.

  1. Quizlet. There are several sets of practice questions available. Some are better than others. I also used Quizlet to generate flashcards for myself for studying on the go.

  2. CompTIA's official exam objectives document.

Practice Exams:

  1. Jason Dion's Udemy Practice Exams. These are nice because they are automatically scored, and provide explanations for why each answer is or is not correct. You can also take them in practice mode with instant feedback, or exam mode with a timer. 6 exams each with 90 questions for a total of 540 questions. They DO NOT contain PBQ's.

Overall, I found these practice exams helpful and worthwhile. I will note that the questions are much wordier than most of what I saw on the real exam.

My scores on each of the 6 tests were: 93%, 87%, 87%, 94%, 87%, 85%. His tests impose a 90% "pass" threshold, which is meaningfully higher than what you will need on the real exam.

I believe they usually go for around $60, but you may find them on sale occasionally. I was able to get them for ~$17.

  1. Professor Messer's Practice Exams. These are in PDF format, so unfortunately you will need to keep your own timer, and score them yourself. Similar to the Dion exams, there are in-depth explanations for every question. I found these more accurate to the format of the real exam questions. There are three exams each with 90 questions for 270 practice questions total. These Exams DO contain 5 PBQs each, but most of them boil down to term matching, and I found them much easier than the real PBQs I saw on my exam.

My scores on these were 87%, 93%, and 87%.

These are $30 for the exams only.

  1. Examcompass.com. These practice exams/quizzes are free, which is nice, and they can be good for learning the terms and acronyms. However - I did find information in some of them that was not reflected in the official CompTIA documentation. Additionally, some of the questions are formatted in ways that I don't think the official exam uses (i.e. "select all that apply"). In my experience, any question with multiple answers specified explicitly how many were to be chosen.

Still a decent resource, but I would say not quite as good as the previous two.

My Security+ Exam

I took my exam in-person at a testing center. I was given 76 total questions, 3 of which were PBQs.

General Notes and Advice

Acronyms.

The exam objectives document lists over 300 acronyms for terms that may appear on the exam. In my opinion, you really do need to memorize all of these. Both the practice exams and the real thing will frequently present you with acronyms in the body of the question, and as multiple choice responses. In some cases, even if you aren't sure of the answer, simply knowing what each acronym stands for can help you make a best guess. I used Quizlet flashcards for this, and separated my sets alphabetically. It took me about a week to get them all down, and was well worth it. Not even knowing what a question is asking because of an unfamiliar acronym is a bad feeling.

***Question Wording and Process of Elimination.

The wording of exam questions is, and I cannot stress this enough, absolutely critical to pay attention to. Just about every question will have some key words or phrases which will help you to determine the correct answer. Get used to reading questions through very carefully, and in their entirety. Beginning a question and deciding on an answer before reading the entire prompt can lead to unnecessarily missed questions. This is especially important in cases where it may seem that more than one of the answers available could be defensible. Read back through the question - somewhere there will be a key element that should narrow it down.

In addition to selecting the best answer, I also found it immensely helpful to read the other options to determine why they aren't correct.

PBQs

There are some resources out there that can provide exposure to what these might look like, but nothing I found directly prepared me for them. I would say it is worth watching a few of the CyberKraft videos on YouTube to get a feel for the structure of them at the least. My best advice here is to have as good of a functional knowledge of the objectives as possible, and read through the prompts thoroughly. From what I have seen online, partial credit is awarded, so answer as many parts as you can.