DEV Community

TiltedLunar123
TiltedLunar123

Posted on Originally published at secplusmastery.com

A Practice Exam Score Is Not a Security+ Prediction

Every study group has a simple rule: get 85 percent on your practice exams and you'll pass. Some say 90. Others suggest you'll be fine if you score in the 70s or 80s on one vendor's tests. Where does that number come from?

In August, I took SY0-701 and relied on practice exams, so this isn't against them. The problem is, that rule can't do the job people think it can. The gap between what people think it measures and what it really does measure is where many first-time failures come from.

Two kinds of numbers

A practice test gives you a percentage: 68 out of 80 correct, so 85 percent.

Your Security+ score arrives in a different currency altogether. It's a scaled score, 750 on a scale from 100 to 900, and the lowest score on that scale is well above zero. You can't convert between the two in either direction, because nobody outside CompTIA holds the conversion and there is no fixed one to hold.

When someone tells you 85 percent means you're ready, they're not giving you a measurement, they're giving you a personal correlation with a sample size of one person.

Whose questions were they?

Under that, there's a harder problem. A practice test scores you against a particular set of questions, so what it really shows is how you did on that set.

Two vendors covering the same objectives can be very different in difficulty, and neither of them is calibrated against the thing you are actually going to sit. One might write items with a clear right answer and three distractors, while another might make you choose between two defensible answers based on a scenario. Score 85 on the first and 65 on the second, and you've found something about the vendors, not yourself.

The exam has its own difficulty level, set by a process none of those authors are part of.

The number that improves for the wrong reason

Here's the one that trips people up. You take a test and score 70. You study. You take it again and score 88, so 18 points better.

Some of that improvement is real. Some is because you've seen the questions before. That part is not progress.

Recognizing a question you've seen before is a different skill from working out an answer you have never encountered anywhere, and the exam only ever tests the second of those. A rising score on something you keep retaking is partly about remembering the questions. Each pass shifts more of the score into recall and less into actual competence.

For the score to matter, the material has to be new every time.

The thing most tests leave out

Nearly all practice tests are multiple choice. SY0-701 mixes multiple choice with performance-based questions, and those are tasks. You're given an interface and asked to do something in it. Drilling with four-option questions doesn't train for that, which is why so many say the multiple choice was fine but the simulations weren't. Ask yourself which half you drilled. Where your preparation is a stack of practice tests, the skill you have drilled least is the one most likely to cost you time on the day.

What the score is good for

Practice tests aren't a waste. They're still one of the better things to spend money on. They're a diagnostic tool rather than a crystal ball. Three jobs, all of them useful.

The per-objective breakdown is the real prize, because a result telling you cryptography is sitting at 50 percent stays useful no matter what the overall score said, and unlike the headline number it points at something you can go and repair.

Timing is the one people often ignore. If you can't finish a set within the time you gave yourself, you've surfaced a problem that will still be there on exam day, long after the score is forgotten.

Question shape is the quiet one. Getting comfortable with scenarios where two answers both seem right is real preparation, and it's the main argument for doing practice questions.

A better readiness test

Want to replace 85 percent and I'm ready? Try this.

Download CompTIA's exam objectives from the Security+ page behind an email form, not a payment. Work through them line by line, saying out loud what each one means and where you would actually use it, before you let yourself look anything up or check a single answer.

The lines where you stall are your study list. That test has no scaling, no vendor difficulty, and no seen-question problem because you're not being scored against someone else's writing. You're checking if you can explain the concepts.

When the stalls end, book it.

Top comments (0)