In the incident response process, which step comes immediately after containment?
How to study for Security+
Find your weak domains first, study in order of exam weight, practice the hands-on tasks, then sit full timed exams.
| Questions | Up to 90, multiple choice and performance-based |
|---|---|
| Time | 90 minutes |
| Passing score | 750 on a scale of 100 to 900 |
A plan in four steps
- Take a short diagnostic to see which domains cost you marks.
- Work through the lessons, heaviest domain first: Security Operations, then Threats.
- Practice performance-based tasks: rulesets, logs, incident order and email records.
- Sit full timed practice exams and repair the domain you miss most each time.
Little and often
Short daily sessions of 20 to 30 minutes keep terms fresh. Spend more of each session answering questions than reading.
Try 3 questions
Question 1Objective 4.7
Question 2Objective 4.8
A responder must collect evidence from a running compromised server. Which should be captured first?
Question 3Objective 3.4
A trading firm needs to resume operations within minutes of losing its main data center. Which recovery site fits?
Next step
Questions people ask
Do I need experience before Security+?
CompTIA recommends two years of hands-on security administration experience for the target role, but there is no formal prerequisite to sit the exam.
How long should I study?
It depends on your background. A diagnostic and your practice exam results by domain tell you more than a fixed number of weeks.