No Shortcuts to Knowledge
Now I know you are reading this and thinking, there's no way that's all. You would be 100% correct. There are no shortcuts to knowledge—you have to put in the time and effort. What worked for me probably won't work for most people. That's true with anything in life. You can only do your best to set yourself up for success.
I want to tell a little story about where I am right now. I'm a recent college graduate who I would say is pretty well-rounded compared to the typical student. I had an internship, earned multiple certifications, performed well in my classes, and won cybersecurity competitions at the national level.
Yet, I'm stuck in the same situation many recent graduates are facing: this industry is competitive and tough. I can't seem to get interviews or job offers. I've probably applied to around 200 jobs and have only received two interviews. One of those came from an internal recommendation, where I made it through four rounds before ultimately being beat out by someone with years of real-world experience and cloud detection engineering projects.
That experience made me realize that we aren't just competing against other recent graduates. We're competing against seasoned professionals looking for a larger company, higher salary, or career change.
How do we combat that?
Honestly... I have no earthly idea.
The only thing we can do is continue building our backgrounds, creating projects, improving our soft skills, and making sure we don't fall behind.
Now Back to the Meat and Potatoes
Leading up to the CySA+, I had just passed another, much more intense certification: GIAC's AI Security Automation Engineer (GASAE), about two weeks earlier.
At that point my brain was honestly tired of studying and a little burnt out. Fortunately, I had won a CompTIA voucher through SummitCTF, a great competition put on by Virginia Tech's Cyber Club. The voucher was about to expire, so I needed to use it.
Because of that, I wasn't looking to put as much effort into studying as I normally would. I want to make something very clear though: I do not recommend this approach.
If you have the opportunity to fully prepare for an exam, do it.
Life just happened to get in the way for me. I had several things come up leading into the exam that took priority, and ultimately I could have prepared much better.
My original plan was simple: find a YouTube course and then complete some practice exams.
What I Actually Studied
I partially followed that plan, but I quickly realized there was no way I was going to have enough time to watch an entire video series covering every exam objective.
So what did I do?
I reached out to several people I knew who had already passed the CySA+ and asked what they thought I should focus on.
Every one of them mentioned CVSS scoring.
At first I thought they just meant memorizing severity scores, but I quickly realized I didn't fully understand everything that goes into the CVSS vectors or how to properly read each version.
That ended up being excellent advice and definitely benefited me during the exam.
Practice Questions
For practice questions I mainly used two sources.
The first was a random YouTube creator that I came across. His practice questions included detailed explanations and were surprisingly similar to the style of questions I saw on the actual exam.
I also used SecuSpark's free practice questions.
There are paid versions available, but I thought the free questions were worthwhile. If I had been more concerned going into the exam, I probably would have considered purchasing the paid version.
What Actually Helped Me Pass
Ultimately, what helped me pass wasn't the practice questions or the studying.
It was the real-world experience I've gained.
That experience is far more valuable than any study guide.
I was prepared for the unexpected because I've spent years trying to become a well-rounded security professional. I'm comfortable thinking from both an offensive and defensive perspective.
I remember several questions where I wasn't completely sure what the best remediation strategy was, but I knew exactly how I would attack the system. Once I understood the attacker's thought process, I could work backwards and determine an effective defensive measure.
The same idea applied to the incident response questions. If you understand how an attacker operates, you can often look at the Indicators of Compromise (IOCs) and mentally reconstruct the attack chain.
That mindset helped me answer several questions that I otherwise might have struggled with.
My Recommendation
I recommend going a step further than simply studying for the exam.
Build applicable experience in both offensive and defensive security.
Hack The Box is one of my favorite platforms for this. While it's primarily focused on offensive security, it also offers Blue Team Sherlock investigations that are great practice for incident response.
I would also recommend becoming very familiar with incident handling procedures and the incident response lifecycle.
Finally, you should have a solid understanding of widely used security frameworks, including the MITRE ATT&CK Framework and the OWASP Top 10.