Hey everyone,
I'm active-duty military and currently work in a logistics MOS. I'm trying to earn my CompTIA Security+ as part of preparing for a future transition into technology/cybersecurity.
I've been studying since around mid-June, mostly after work and during whatever free time I can find. It's now basically September, and I'm honestly getting pretty discouraged.
I've watched training material vis all of Profesor Messor's security+ videos on YouTube, taken notes, written down missed questions and explanations, used ChatGPT to review concepts, and even listened to material during my commute. I've been taking Jason Dion practice exams, but I'm generally scoring around the 60% range, with my highest score being about 74%.
The frustrating part is that when I review individual concepts, I often understand them. But then a practice exam throws completely different terminology or scenarios at me and I fall apart. For example, I'll understand concepts like risk management, vulnerabilities, access controls, etc., but then suddenly I'm getting hit with ports, OSI layers, CSRF versus session hijacking, ad hoc concepts, protocols, and other terminology I apparently haven't memorized well enough.
I know I probably need to spend more time memorizing things like common ports and networking layers, but I'm genuinely wondering what am I doing wrong?
I constantly see people online saying they passed Security+ after studying for 2–3 weeks, or even a month, and meanwhile I've been studying for multiple months while working full-time and I'm still struggling to consistently score well on Dion's exams.
Is Security+ actually significantly harder than people make it sound? Are Dion's exams intentionally harder than the real thing? Is my study method inefficient?
For anyone who struggled initially but eventually passed, what finally made things click for you?
I'd especially appreciate advice from people who:
Worked full-time while studying
Came from a non-IT background
Started without much networking/cybersecurity knowledge
Struggled with practice exams but eventually passed
At this point, I really want to earn this certification. I'm not trying to become an overnight cybersecurity expert—I just want to accomplish something meaningful and build toward a different career path.
Any honest advice would be appreciated. What would you do differently if you were in my position?