Hi all,
I just got back from the test center where I took the Security+ exam. OMG, what a weird exam it was. It was my first CompTIA exam, so I was more nervous then usually. After the first 7 or 8 questions I felt I could relax cause the answers seemed so obvious. I think I spent as much time on question 9 as on the first 8 questions, just trying to figure out what the question said. I even picked up some new English words.

It seems they customized the exam for me though, I got very few questions on policies and other less-technical topics. Overall it was pretty straightforward, and did not get many questions about unexpected topics.
Some things in general:
- Know those well-known ports... Use our Security+ ports quiz to memorize them, you won't regret it.
- Know the difference between non-repudation, confidentiality, encryption, integrity, authentication, etc., etc.
- PKI infrastructure
- crypto algorithms, asymmetric, symmetric, hashing.
- basic networking
- VPNs, make sure you understand L2TP and PPTP, and IPsec.
- IDS, make sure you watch the free video at
www.cbtnuggets.com/techexams
- Since there were a hundred questions (somehow I expected 90) pretty much every exam objective listed at
www.comptia.com was covered by the exam.
I used the following to prepare for/pass this exam:
- Experience. Although 'Security' was never part of my job titles, basic security is always part of a sys/network admin/designer's job. I.e. I've set up 509v3 certificates and S/MIME in a huge Exchange 5.5 environment, hence I didn't need to prepare for that. Preparing for this exam did change my point of view on security and gave me a healthy doses of paranoia.
- Other certs. Apart from MCSE in general and my cisco certs, the MS Exchange and MS Proxy exam covered a lot of these security 'basics' in detail.
- The
Sybex Security+ Study Guide. I received a copy from Sybex over a year ago. One of these reasons I kept delaying the exam is that I had a real hard time finishing that book. Apart from several inaccuracies and repeated information, it never felt I knew enough about a topic from just reading that book. However, after taking the exam, it doesn't seem to be such a bad book at all. I wouldn't suggest it as the only source though...
-
PrepLogic was so kind to provide me with a free copy of their Security+ practice exams. When I first started to use them, I thought some questions and explanations seemed weird and off-topic. But after I took those 300 questions twice, I realized I learned more than from reading the studyguide. And after passing the exam today I think they are actually pretty good and definitely worth the money.
- online practice exams from various sites
- reviewed my own TechNotes.

Nr. of question is 100, I had 120 minutes + 30 extra for being a non-native english, needed about an hour, passing score is 764, and in case someone cares, I passed with 852.
I hope this is somewhat useful to others. I've been working on more Sec+ TechNotes and practice exams for some time and will put some online soon.
Johan