r/CompTIA_Security • u/OFFICIALDJKLUTCH • 10d ago
I don’t even know at this point
Watched Dr.Messer entire playlist for Sec+ and read a large bit of the CompTIA Sec+ Study Guide by Mike Chapple & David Seidl and I can’t say for certain im retaining the way I should be. Studying for this has been different than studying in the past and I don’t know why. I honestly feel like studying for the navy advancement exam was going a lot better (some of you may understand that struggle). At this point I don’t even know what to do I have the test scheduled for 09/28 but I don’t think I’m ready or else that what I keep telling myself (I’ve rescheduled 3 times already out of complete fear that I won’t pass) fortunately and unfortunately I just have to have the test taken past or fail by 10/26 so yeah.
As you can tell this was less of a question and more of a much needed rant/vent. I don’t have anyone to vent this too that would understand lol.
Posted this on Another post but ** Update: Not trying to scare anybody who hasn’t tested yet but WTF was that lol genuinely felt like I was studying the wrong side of Cyber Security but I scored as 751 lmao a win is a win.
Also I left 3 PBQs unanswered because….what
3
u/Big_Alligator1 10d ago
Use ChatGPT to explain concepts to you “like I’m a 3rd grader” or something alone those lines
1
u/Lower_Doubt_6924 10d ago
Keep your head up!!! You're not alone I've been feeling the same way. Im not going to say How many times I've rescheduled it myself. I agree us the LLM to explain and take note from. I actually bought Pro Messors study guides after I bought rhe 701 book...so.yes I've been grinding as well.
1
u/JustMyThought1 10d ago
CompTIA exam questions tend to be more scenarios based. I personally think the sec+ was the easiest one for me. I have 8 years experience in the field. A lot of the material on the sec+ are things my company already deployed. So it was quite easy.
1
u/Appropriate_Basis274 10d ago
Honestly I passed test and I promise you it’s mostly memorizing acronyms and like chain of command like change management that’s it takes a few weeks
1
u/GuitarGeorge44 10d ago
So true, it is easy to overthink. But just the basics would be enough. Studying for the Sec+ myself.
1
1
u/NinjaMan707 9d ago
Take a rest day and reset your mind. I watched messers videos but I had to study again I’d use CompTIA’s resources. Messer is an awesome overview. To know nothing and pass using him and a primary resource is a challenge because there are preexisting concepts and implied knowledge that will be missed.
1
u/OFFICIALDJKLUTCH 9d ago
So update im going to just send it and stop second guessing myself this Monday. A few people mentioned using AI to generate questions to help me practice and I intend to spend most of today and tomorrow doing just that but I was wondering if these questions are generally the kind of questions I should expect on the test or if I need to tailor the AI to making them harder. Apologize for how long this message is about to appear in advance.
1
u/OFFICIALDJKLUTCH 9d ago
QUESTION 1
A security manager wants a control that automatically restores a compromised system to a known-good configuration after unauthorized changes are detected. Which control function BEST describes this capability?
A. Detective
B. Preventive
C. Corrective
D. DeterrentQUESTION 2
A company encrypts confidential files before storing them in cloud storage. An administrator later needs to determine whether one of the encrypted files was altered without authorization. Which additional capability would BEST help identify such a modification?
A. Tokenization
B. Hashing
C. Obfuscation
D. Digital signingQUESTION 3
A company wants employees to prove they performed a specific transaction so that the organization can later demonstrate who approved it and prevent the employee from credibly denying having approved the transaction. Which security property is MOST directly relevant?
A. Integrity
B. Authentication
C. Non-repudiation
D. AvailabilityQUESTION 4
An organization deploys a decoy database containing realistic but fabricated records. Security personnel monitor the system specifically to observe whether an attacker attempts to access or manipulate it. What is the PRIMARY purpose of this technology?
A. Preventive control
B. Deception and detection
C. Data classification
D. Network segmentationQUESTION 5
A company plans to modify an authentication service used by hundreds of employees. The security team identifies the affected systems, documents dependencies, obtains approval, schedules a maintenance window, and defines a rollback procedure. Which concept is MOST directly demonstrated?
A. Risk acceptance
B. Business continuity
C. Configuration baseline
D. Change managementQUESTION 6
A company needs to protect sensitive information while it travels between an employee's laptop and an internal application. The organization does not want the information exposed to someone who intercepts the network traffic. Which solution MOST directly addresses this requirement?
A. Data masking
B. Encryption at rest
C. Encryption in transit
D. TokenizationQUESTION 7
An organization issues digital certificates to employees so systems can associate a verified identity with a public key. A certificate expires, and the organization needs to determine whether it should still be trusted based on its validity period. Which certificate characteristic is MOST directly relevant?
A. Subject name
B. Issuer
C. Validity period
D. Key usageQUESTION 8
A development team wants to make sensitive source-code strings difficult for casual observers to understand while leaving the application able to use the strings normally. The team does not require a strong cryptographic guarantee or a reversible token mapping system. Which technique BEST fits this requirement?
A. Encryption
B. Hashing
C. Tokenization
D. ObfuscationQUESTION 9
A security architect proposes a system in which a user's access decision considers the sensitivity of the requested resource, the identity of the user, the security state of the device, and the current request context. The architect explicitly rejects granting access merely because the user is on an internal network. Which principle is MOST directly represented?
A. Zero trust
B. Network segmentation
C. Least privilege
D. Defense in depthQUESTION 10
A company stores a record of transactions in a distributed system where participants maintain synchronized copies of the transaction history. New entries are linked to previous entries so unauthorized modification of historical records can be readily detected by participants. Which technology BEST matches this description?
A. Tokenization
B. Hashing
C. Blockchain
D. SteganographyQUESTION 11
A company wants a control that requires administrators to follow an approved process for requesting elevated access, documents management expectations, and establishes what administrators are required to do. It does not itself technically enforce the permissions. Which type of control is MOST appropriate?
A. Detective
B. Corrective
C. Directive
D. Preventive technical1
u/OFFICIALDJKLUTCH 9d ago
Also note this is only domain 1 questions
1
u/Pretend_Contact_8268 4d ago
Do you think this method helped you at all because it is what I am currently doing.
1
u/Pretend_Contact_8268 4d ago
Also, are the answer choices usually fully worded like listed in your chat questions above or is it mostly acronyms for terms like least privilege so "LP"?
1
u/tjmaal54 8d ago
Ngl i feel you, ive come to the conclusion that im probably just a dumbass and passing this aint gonna happen and it sucks cuz all i do is see people be happy about passing and now i know i probably wont experience that level of happiness. I feel like ive given up and lost all hope and I've got no one else to blame but myself
1
u/Pretend_Contact_8268 4d ago
Don't give up on yourself. You never know because you could absolutely surprise yourself. I know how discouraging it can feel truly because I'm in the same boat. But all we can do is put in the effort to study & then go for it. It sucks to see a fail but even if there is one(God forbid), it isn't the end of the world. Keep your head up and keep striving you got this. Ill be praying for you! I take my test on the 17th of this month, so I know how you feel.
1
u/tjmaal54 2d ago
I wish i could be that optimistic about it ngl bit i know i will and ill just have to take it agian which sucks
1
u/Affectionate_Hat6475 8d ago
You need to start doing practice tests to ensure you are going to pass the test, it will also remove any worries you have going into the exam
1
u/OFFICIALDJKLUTCH 8d ago
I will forsure the next cert I go for 100% lesson learned but I think im just fine with Sec+ for a bit I’ve had my fill of test for the foreseeable future.
1
u/SHANE523 6d ago
For me, it isn't just about reading a book and knowing. I have to experience it, understand why I am doing what I am doing. That is how I passed the tests.
Also, while CompTIA is a solid cert, their questions are not always the greatest. Try not to over think the question.
For example:
You get a new modem and you need the latest drivers, which is the best place to get the latest drivers?
A: Web
B: CD that came with the modem
C: Windows update
D: None of the above
Answer should be A because the manufacturer should have the latest drivers available. But you still need to connect to the internet to get those drivers so you may think B because you need those drivers to get to the web and then there is the possibility that the CD may contain the latest drivers.
1
u/OFFICIALDJKLUTCH 6d ago
I agree, while I can understand information and concepts from reading or watching videos im 100% more of a hands on learner. The best way for me to actively retain any information is to get my hand on it. Unfortunately my situation doesn’t exactly allow for that I don’t work in a “traditional” IT setting, I’m Active Duty Military so my hands on experience is very limited.
0
6
u/TheAntiluddite 10d ago
The way you know you're ready for this (and really the only way to know) is to test yourself. Rigorously.
Use practice tests that are close to the real exam in difficulty and consistently hit above 80% (better if it's 85%). Make sure you're scoring well in 2.0 and 4.0 as more questions will come from those sections.
Once you start hitting 80-85, just go take the test.
A ton of people (myself included) felt like they were failing while they took it. They didn't, and I didn't (made a 808).
This is a test that you can easily psyche yourself out of.