TL;DR, Passed CompTIA Security+ on my first attempt with a 782/900, after 3 weeks of focused prep during my attachment. No formal labs, just CTFs, practice exams, and Professor Messer.
Why I decided to do Security+
A few reasons:
- Market value, it’s one of the most requested entry-level certs.
- I had a 30% discount voucher I didn’t want to waste.
- My research kept pointing to it as one of the best entry-level certs for cybersecurity.
As a college student, I realised most entry-level cybersecurity jobs ask for at least Security+, so I made it my goal to get it before I finish college.
How I prepared
Study schedule
I studied across 3 weeks during my attachment (still on it). I didn’t go straight to the notes, instead I attempted practice exams raw and wrote down notes on every term I didn’t understand at the end of each exam. That turned out to be the best way for me to actually learn.
Labs & practical experience
I didn’t really do labs. I’d been playing CTFs since the start of 2025 and messing with VMs, so I already had the hands-on experience the exam expects.
Takeaway: if you already do CTFs or run a homelab, lean on it, the PBQs are far less scary once you’ve actually touched the tools.
What was challenging
Knowing what the acronyms stood for wasn’t the hard part. The tricky bit was the meanings and how they differ in context. By the 2nd week I had about 90% of them down, which felt like enough to pass. Security+ is famous for its pile of acronyms, so it was something I expected.
What helped me most
Professor Messer, 8/10
- Bought his bundle around mid-2024 (notes + practice exams).
- His free YouTube videos are genuinely helpful too.
Jason Dion Practice Exams, 7.8/10
- Grabbed them on a Udemy sale during my 3-week prep.
- Harder than the real exam, which is exactly what you want.
Exam day
I was very nervous, honestly, especially taking the check-in photo, it felt unreal. But once I settled into the exam room I relaxed a bit. I couldn’t let nerves make me fail; I’d saved a lot for this.
From advice I picked up on Reddit, I skipped all the PBQs and went straight for the multiple-choice, cruising, with the exception of 3–4 questions.
The PBQs weren’t as tough as people make them sound. They just need you to have some real, practical security experience. I spent barely 10 minutes on all four and finished with 1 hour 20 minutes to spare, revising again would’ve just made me second-guess my answers, lmao.
Then comes the wait. CompTIA makes you fill in a survey before showing your score, and I kept thinking each next page would be the result. I was shi**ing myself.
And then, 782. Passed on my first attempt. Biiiig sigh of relief, yoh.
Advice for anyone starting
- Understand concepts, don’t just memorise terms. Once you apply them to specific contexts they stop being hard to grasp.
- Take your time, but commit to a date. Booking the exam early kept me motivated as it got closer, and I deliberately avoided rescheduling.
What’s next
Next on my list is CompTIA CySA+, I already have the study material, I just need to save up for the voucher (rip). Aiming to sit it before June 2026.