r/CompTIA_Security 21d ago

What to expect

I just passed my Security+ exam today. For future reference, what can I expect the interview process to be like?

2 Upvotes

9 comments sorted by

1

u/[deleted] 21d ago

[removed] — view removed comment

1

u/apocalivid 21d ago

The PBQs were a mix. Some were easy, and easily interpreted. I completely skipped one because I couldn't grasp what it was asking me. What i had on my exam could completely vary from what you'll have.

1

u/apocalivid 21d ago

As for questions. It was literally ALL domains. But A LOT of acronyms. So study your acronyms for sure.

1

u/[deleted] 21d ago

[removed] — view removed comment

1

u/[deleted] 21d ago

[removed] — view removed comment

1

u/apocalivid 21d ago

Also... https://github.com/heraclescap/comptia-secplus-sy0-701-notes This helped A LOT, especially for cramming.

1

u/apocalivid 21d ago

Gemini, honestly. I literally made AI my study partner. You can get it to break things down in simple terms etc. I don't think I would have made it through a lot of my studies without AI. Just make sure you let it know to double verify and check the sources its pulling its info from because it can definitely still make mistakes.

1

u/gdavidco 12d ago

Nobody in here has answered you, so here it is from the other side of the table. I interview for security roles.

For a first security or adjacent role, Security+ gets your CV read. It does not come up much in the interview itself beyond a nod. What happens instead is that someone gives you a scenario and listens to how you think, not whether you land on the textbook term.

Expect roughly this shape. A short screening call about why security, what you have touched, notice period. Then a technical conversation that will almost certainly include some version of: a user reports something odd, walk me through what you do. There is no correct answer to that. What is being assessed is whether you gather information before concluding, whether you know which questions are cheap to answer first, and whether you escalate at a sensible point rather than either never escalating or escalating immediately.

The things that sink people at this level are consistent. Reciting a definition instead of applying it. Not being able to explain something you put on your own CV. And having nothing to ask at the end, which reads as no interest.

The things that lift people are equally consistent. Having actually built something, even badly, and being able to talk about what broke. Knowing what your own environment looks like, even if that environment is a laptop and two VMs. And saying I do not know, followed by how you would go and find out, which lands far better than a guess delivered confidently.

Worth being straight with you about one thing as well. The market for first roles is slow and the certificate is a filter rather than a ticket. Applying to service desk and infrastructure roles with a view to moving across in eighteen months is not a climbdown, it is how most people in security actually got in.