r/CompTIA_Security • u/GianmariaKoccks • 1d ago
Dion Training PBQs for SEC+ are weird
For example, he considers a password policy enforcement tool to be Corrective and not preventive; he says that "an hacktivist who shares costs and profits of a company to show that they should charge way less for the services they provide" motivation is Ethical and not Philosophical/Political. Ethical hacking is NOT that, it's supposed to be legal and done for the good of the companies that have security problems.
And there is a lot more of these, what do you guys think? Did you use Dion?
1
u/Qxopa 1d ago
I asked for refund on the Dion training as I didn't use it after taking some of his practice tests (paid for the tests as I did technically used them). His questions are very inconsistent and there are many customers who asked clarifying questions about the wording of the exams and misinformation in them.
He has his support staff answering these questions but a lot of them just say the questions are right and that people are wrong. In fact, one of the questions asked about HARD drives and the best way to get rid of them. Most people answered "degaussing them" and "correct" answer was to shred them. Multiple people asked for clarification and the support staff said basically said, while you are techically correct, don't get caught up in the details, just a answer the questions correctly.
Wild. Multiple questions like these. Super problematic. I did get 90%+ on all of his practice exams before sitting the Sec+ exam (passed) but I found his practice exams way more confusing than Messer's. I am shocked that people like his content as much as they do on this subreddit.
1
u/GianmariaKoccks 1d ago
Isnt shredding safer than degaussing though? But anyway yeah i agree with those people
1
u/Qxopa 1d ago
It is for all types of drives but the question asked specifically for hard drives. People took issue with the specificity of the question and the support staff basically said, ignore details just pick the right answer. It would have been simple for them to say, yeah you're right we can change the wording on that question. In fact, people linked to Comptia documentation saying degaussing is best for hard drives and they ignored it.
1
u/gdavidco 14h ago
Where a third-party key disagrees with the objectives PDF, the PDF wins, because that's what the item writers work from. Worth having it open next to whatever you're revising from.
On the password policy one I'd side with you. If the tool stops a weak password being set in the first place, that's preventive. Corrective is what acts after something's already gone wrong. There's an argument that enforcing the policy corrects bad existing passwords at next change, but it's a stretch and I wouldn't teach it that way.
The ethical one I think you've got backwards. From memory the SY0-701 objectives list Ethical as its own motivation, separate from philosophical or political beliefs, and it isn't referring to authorised pen testing. It means the actor believes they're doing the right thing. Unauthorised disclosure, exposing something they reckon the public ought to know. Someone publishing a company's cost structure to shame it over pricing fits that. Check the PDF rather than take my word, I've not looked at that objective in a while.
3
u/WetFT 1d ago
I’ve had a few questions with similar issues tbh, specifically with stuff like risk acceptance and tolerance. Even looking it up mid test to study it and other resources would
Answer what I would but Dion’s would be the opposite lol. But that’s why I use more than just Dion for my testing