Introduction
After a couple of weeks of studying, which I covered in the last few posts, I passed CompTIA Security+ last June (I schedule my posts, so dates don’t line up).
Going by exam day alone, I’m not sure how.
Checking in
About a decade ago, I studied for quite a few CompTIA exams, and needed to go to a certified test center to take the exam. In this day and age you can take it from the ‘comfort’ of your own home. Comfort in quotes, since it was 40 degrees Celsius and everything went wrong…
When taking the Security+ from home, you need to use OnVue, Pearsons remote proctoring software. It checks your ID, photographs you and your desk, and hands your screen to a proctor for the next ninety or so minutes. Check-in supposed to take five minutes.
Mine took about half an hour. The photos kept failing, for whatever reason they were not accepted; I retook them three or four times before they stuck. Right on cue, I also needed the bathroom. So the run-up to my exam went like this: reload the check-in screen, ask the proctor whether I’m even allowed to stand up, wait, reload again. By the time the first question loaded, whatever calm I’d started with was long gone.
Technical difficulties
Once the test loaded, the whole window sat shifted toward the top-right of my screen, far enough that the OnVue monitoring panel landed on top of a strip of it. That strip happened to cover part of the question area. For a stretch of questions I was working from maybe two-thirds of what was on screen, piecing answer options together from the half-sentences I could read and guessing at whatever the panel was sitting on. I was pretty sure this could only be solved by quitting and restarting the OnVue app. I didn’t dare bringing it up with the proctor, after our rocky start.

What a mess. It was still 40 degrees, and I was melting away even faster.
What is this?!
I’d gone through every module beforehand: core principles, encryption, security architecture, attack vectors, governance and compliance. The Coursera course. Folders of notes. I felt ready.
The exam came at it from angles I hadn’t drilled. Fewer “define this term” questions, more “you’re the analyst, something’s on fire, what do you touch first“. The scope is wide, but the phrasing is what gets you. Security+ writes questions where two answers are both technically correct, and you’re left picking the most correct one. Feels like gambling most of the time. Sometimes the trick is a single word in the scenario; a “first” or a “best” or a small detail about the environment that rules out the answer you were about to click. Read every word, twice. The wrong answers are designed by someone who knew exactly which shortcut you’d take.
Then the performance-based questions; the interactive ones where you configure something, match items, or work a scenario instead of clicking A through D. They were brutal and buggy as fuck. They sit near the front, they eat your time and your nerves, and knowing the OSI model by heart won’t help you one single bit. Budget time for them on purpose, and if one starts melting your brain, flag it and move on. My recommendation would be to skip them entirely at first, and only return to them when you finished all other questions.
What got me through
I passed with a screen I could barely read, a check-in that fought me, and a question bank that kept surprising me. None of that was in my study plan, and the result came out the same as if the day had gone perfectly. Preparation gets you most of the way; the last stretch is just refusing to panic when the conditions go bad. Messy still counts I guess.

Next
Security+ is in the bag, so the plan (as it is now, might change though) from here:
- Getting my TryHackMe (THM) SEC0 and SEC1 notes properly filed in my ‘Second Brain’
- Sitting the THM SEC1 exam (training already done)
- Working through the Udemy course for CompTIA SecAI+
- Earning the CompTIA SecAI+ certification
- Running the full THM Security Engineer path
And underneath all of it, labs, labs, labs on THM. Expect write-ups as I go.
Somewhere in there I also have to face the backlog. Months of head-down studying (Google Cybersecurity Professional, Google AI Professional, THM stuff and now Security+) means a pile of everything-else has stacked up from here to Tokyo, and at some point I’ll have to start clearing it.
One thing at a time.
