Uploaded by Marius Kulikauskas

Security+ Exam Cram: Study Session & Prep Strategy

advertisement
SECURITY+ EXAM CRAM
LIVE EXAM STUDY SESSION
Coverage of all 5 Domains
Challenging Exam Topics
FAQs & Exam Prep Strategy
with Pete Zerger vCISO, CISSP, MVP
FAQs
Which materials should I use to prepare?
How long should I study before I take the
exam?
Will this session be recorded? Can I have a
copy of the slides?
How can I contact you after this study
session is complete?
Differences between 601 and 701 exams?
FAQs
Differences between 601 and 701 exams?
Command line tools and specific commands largely
removed from the syllabus.
Domain 4 (Operations) is larger (in terms of content)
You are now expected to know how to use the
quantitative risk analysis formulas.
CompTIA Security+
Exam Cram
EXAM NUMBER: SY0-701
SECURITY+
EXAM STUDY GUIDE
& PRACTICE TESTS BUNDLE
500 practice questions
100 flashcards
2 practice exams
SECURITY+
EXAM STUDY GUIDE
& PRACTICE TESTS BUNDLE
1000 practice questions
2 practice exams
Links in video description
A pdf copy of the presentation is
available in the video description!
SUBSCRIBE
Subscribed
Exam Flashcards
from Inside Cloud and Security
Features include:
✓ Flag for review
✓ Bite-size sessions
(choose your card count)
✓ OSG study reference
✓ Video link
✓ Additional reading
✓ Exam Tips
(when necessary)
Features include:
✓ Access from any
mobile browser
✓ Login with your
preferred social ID
Features include:
✓ Access from any
mobile browser
✓ Login with your
preferred social ID
✓ $5 USD per month
(billed quarterly)
Free tier offers 5 cards in each
category so you can explore
Features include:
✓ Access from any
mobile browser
✓ Login with your
preferred social ID
✓ $5 USD per month
(billed quarterly)
Link in the session chat
There is no
AWARD
for the longest
STUDY TIME!
test details
Required exam SY0-701
Number of question Maximum of 90
Types of questions Multiple-choice and performance-based
Length of test 90 minutes
Recommended ▪ At least 2 years of work experience in IT
experience
systems
administration
a focus
on
Performance-based
questions
require with
exam
candidates
security
to perform a task ▪or
solve a problem within a simulated IT
Hands-on technical information security
experience specific knowledge or skills.
environment to demonstrate
▪ Broad knowledge of security concepts
Passing score 750 (on a scale of 100–900)
test details
Required exam SY0-701
Number of question Maximum of 90
Types of questions Multiple-choice and performance-based
Length of test 90 minutes
Recommended ▪ At least 2 years of work experience in IT
experience
systems administration with a focus on
security
▪ Hands-on technical information security
experience
▪ Broad knowledge of security concepts
Passing score 750 (on a scale of 100–900)
EXAM OBJECTIVES (DOMAINS)
DOMAIN
WEIGHT
1.0 General Security Concepts
12%
2.0 Threats, Vulnerabilities, and Mitigations
22%
3.0 Security Architecture
18%
4.0 Security Operations
28%
5.0 Security Program Mgmt and Oversight
20%
chunking
cryptography
Asymmetric
Symmetric
Hashes
Block ciphers
break into “chunks” based on a unique property
24 hours
1 week
20 min
THE POWER OF
REPETITION
spaced repetition
100
Spaced Repetition
1st session
2nd session
3rd session
Forgetting curve
0
Forgetting curve longer and
shallower with repetition
spaced repetition
TO MEMORIZE
QUICKLY
1st repetition
Right after learning
2nd repetition
After 15-20 min
3rd repetition
After 6-8 hours
4th repetition
After 24 hours
5th repetition
After 48 hours
6th repetition | After 1 week
1st repetition
Right after learning
2nd repetition
After 20-30 min
3rd repetition
After 1 day
4th repetition
After 2-3 weeks
5th repetition
After 2-3 months
TO MEMORIZE FOR
A LONG TIME
Exam prep strategy
Research shows everyone benefits from a variety of sources!
TARGETED
READING
LIVE QUIZ
VIDEO
CONTENT
(or flashcards)
PRACTICE
EXAMS
POWERPOINT
REVIEW
Mix, match, and repeat based on your preferences
Exam prep strategy
Research shows everyone benefits from a variety of sources!
TARGETED
READING?
LIVE QUIZ
VIDEO
CONTENT
(or flashcards)
PRACTICE
EXAMS
POWERPOINT
REVIEW
Use OSG for topics you are struggling with…
Exam prep strategy
Research shows everyone benefits from a variety of sources!
TARGETED
READING?
LIVE QUIZ
VIDEO
CONTENT
(or flashcards)
PRACTICE
EXAMS
POWERPOINT
REVIEW
…but not to read cover-to-cover!
Exam prep strategy
Research shows everyone benefits from a variety of sources!
TARGETED
READING
LIVE QUIZ
VIDEO
CONTENT
(or flashcards)
PRACTICE
EXAMS
POWERPOINT
REVIEW
My preferred order
Exam prep strategy
Research shows everyone benefits from a variety of sources!
TARGETED
READING
LIVE QUIZ
VIDEO
CONTENT
(or flashcards)
PRACTICE
EXAMS
POWERPOINT
REVIEW
My preferred order
Exam prep strategy
Research shows everyone benefits from a variety of sources!
TARGETED
READING
LIVE QUIZ
VIDEO
CONTENT
(or flashcards)
PRACTICE
EXAMS
POWERPOINT
REVIEW
My preferred order
Exam prep strategy
Research shows everyone benefits from a variety of sources!
TARGETED
READING
LIVE QUIZ
VIDEO
CONTENT
(or flashcards)
PRACTICE
EXAMS
POWERPOINT
REVIEW
My preferred order
Exam prep strategy
Research shows everyone benefits from a variety of sources!
TARGETED
READING
LIVE QUIZ
VIDEO
CONTENT
(or flashcards)
PRACTICE
EXAMS
POWERPOINT
REVIEW
My preferred order
Exam prep strategy
Research shows everyone benefits from a variety of sources!
TARGETED
READING
LIVE QUIZ
VIDEO
CONTENT
(or flashcards)
PRACTICE
EXAMS
POWERPOINT
REVIEW
My preferred order
Exam prep strategy
Research shows everyone benefits from a variety of sources!
TARGETED
READING
LIVE QUIZ
VIDEO
CONTENT
(or flashcards)
PRACTICE
EXAMS
POWERPOINT
REVIEW
My preferred order
Exam prep strategy
Research shows everyone benefits from a variety of sources!
TARGETED
READING
LIVE QUIZ
VIDEO
CONTENT
(or flashcards)
PRACTICE
EXAMS
POWERPOINT
REVIEW
My preferred order
FAQ: which practice exams are best?
Which practice exams will best
prepare me for the SEC+ exam?
Which practice exams you use are much less
important than how you use them!
Tracking your progress on a per-domain
basis is key.
Narrowing your focus to a subset of domains Remember the
narrows the topics you need to focus on.
80/20 rule!
No practice exam engine replicates the live exam all that
well, so use practice exams to master exam topics.
M E M O R I Z I N G V S UNDERSTANDING
UNDERSTANDING
CONCEPTS
Studies show understanding BEFORE you
memorize greatly improves retention
The 80/20 process
(pareto principle)
All exam content
and study materials
EXAM
PREP
What you need
to focus on
Filter down to weak areas
with practice exams, live
review, flashcards, etc.
Spend the bulk of your
exam prep time here!
other question types
You can apply the READ strategy to complex question types!
Other question types:
Hot spot
"Hot Spot" questions require you to click on the correct part of
a diagram to answer a question.
Drag-and-drop
Click, drag and drop each correct answer from the "Possible
Answers" section to the "Correct Answers" box.
STRATEGY: You can CONVERT the question to a
traditional multiple choice and then process.
other question types: drag-and-drop
01
Which the following are hashing algorithms? Select all
that apply by dragging them to the Correct Answers box.
AES256
Blowfish
MD5
ECC
SHA-224
ECDSA
Possible Answers
Correct Answers
other question types: drag-and-drop
01
Which the following are hashing algorithms?
Select all that apply.
1. AES256
2. MD5
3. SHA-224
4. Blowfish
5. ECC
6. ECDSA
Security operations
05
0. Nothing
You need to secure apps from inbound connections and
secure users' outbound connections. You should deploy
the least number of devices to meet the need.
1. Next Gen
Firewall (NGFW)
What do you do? (click each letter and select a number)
2. Network IPS
Web
Server
B
A
3. Network IDS
Corp
Router
C
Client
4. Web App
Firewall (WAF)
Security operations
05
You need to secure apps from inbound connections and
secure users' outbound connections. You should deploy
the least number of devices to meet the need.
Which combination best meets the objectives?
1. Deploy A) NGFW, B) WAF, and C) Network IPS
2. Deploy A) Nothing , B) WAF, and C) Network IPS
3. Deploy A) NGFW, B) Nothing, and C) Nothing
4. Deploy A) WAF, B) Nothing, and C) Nothing
THE “READ” Strategy
REVIEW
ELIMINATE
ANALYZE
DECIDE
Quick reference
What is being asked? True end goal we’re solving for?
Any process frameworks or regulatory requirements?
Unimportant details intended to distract?
Answers that are definitely wrong?
What are the solution requirements?
If multiple, prioritize based on role priorities.
Evaluate each answer individually. What do we like
about each? Does one encompass the other?
Know your role! Remember your priorities!
THE “READ” Strategy
REVIEW
ELIMINATE
ANALYZE
DECIDE
Quick reference
What is being asked? True end goal we’re solving for?
Any process frameworks or regulatory requirements?
Unimportant details intended to distract?
Answers that are definitely wrong?
What are the solution requirements?
If multiple, prioritize based on role priorities.
Evaluate each answer individually. What do we like
about each? Does one encompass the other?
Know your role! Remember your priorities!
THE “READ” Strategy
REVIEW
ELIMINATE
ANALYZE
DECIDE
Quick reference
What is being asked? True end goal we’re solving for?
Any process frameworks or regulatory requirements?
Unimportant details intended to distract?
Answers that are definitely wrong?
What are the solution requirements?
If multiple, prioritize based on role priorities.
Evaluate each answer individually. What do we like
about each? Does one encompass the other?
Know your role! Remember your priorities!
THE “READ” Strategy
REVIEW
ELIMINATE
ANALYZE
DECIDE
Quick reference
What is being asked? True end goal we’re solving for?
Any process frameworks or regulatory requirements?
Unimportant details intended to distract?
Answers that are definitely wrong?
What are the solution requirements?
If multiple, prioritize based on role priorities.
Evaluate each answer individually. What do we like
about each? Does one encompass the other?
Know your role! Remember your priorities!
Download