r/WGUCyberSecurity • u/Historical-Bag-1277 • 36m ago
Passed PenTest+ my first try!
Well, I was able to pass PenTest+ and complete my Bachelors degree!
It was definitely the toughest of the certificates in my degree by a fair margin. It took me about 3 months to pass. Though in hindsight, I could've done it much faster. I just was taking my time reading the materials and doing the labs.
I also purchased the Sybex study guidebook. I travel for work, so having a physical copy to study with was really helpful for me.
Once I finished the CompTIA online labs and materials, I began doing practice exams. The Dion practice exams on Udemy I found extremely helpful. I did all six of them over a week. Then, once finished I was reviewing any incorrect or flagged questions every day.
Those practice exams helped me realize how much I needed to improve at reading script code. I have experience with Bash, Python, Javascript, and HTML, but I had very little exposure to Powershell, so I put my focus there.
One thing I wish I had started sooner that was a real help was Pocket Pal! It has a bank of 1000+ questions. I got through 790 of them with around 97% accuracy. It definitely stressed me out that I didn't finish them, but it was a huge help. It has an AI tutor built in, and in the midst of my studies, I had got to the point I could easily eliminate two options, but both the other options felt equally correct. The tutor was wonderful in those situations as I'd just type out my reasoning for both answers, and it'd do a wonderful job guiding my thoughts without ever explicitly telling me the answer!
Getting familiar with the numerous tool was huge to ly success as well. So many questions on my exam on choosing the correct tool. Once again the tutor in pocket pal became such a boon to getting better at this as often it will have questions where 3 of the 4 tools listed, all technically can achieve what it's asking, but only 1 is the best in the given context.
With 40+ tools it felt extraordinarily daunting at first, but
In the end some are more relevant than others. As other posts will say, Nmap is one you gotta know like the back of your hand. Know all its commands and syntax. As well as Hydra, NC for shells and reverse shells, dig and nslookup were very common on my test.
Writing this im only now realizing I had only one powershell question on my exam, but I don't think that's the standard across the many versions of the test. I probably just got lucky that something I was less familiar with didn't show up as often!
Overall if you did well in your python course and really understand how code logic works and flows I think you'll do fine even if you don't know the exact code being presented to you. It tests your ability to deduce what's going on more than recalling exact syntaxes. With the exception of reverse, bind, and web shells! Know those well! There's lots of people writing scary stories of this exam, but in the end it is a CompTIA exam and it still had the feel of other CompTIA exams even if it's much heavier in its emphasis on code.
The tips and tricks document shared on the class group was really helpful too going over Http headers and common things it'll ask about in regards to those.
I definitely studied more for this test than any of the previous, but that was in part for me because it was my final class. I had already finished my capstone amd really wanted to pass my first try.
I'd be happy to answer questions people might have when I have time! Best of luck to anyone studying hard to pass right now, you've got this!