Build one small Security+ lab and keep two projects you can show an employer
A Security+ home lab needs two virtual machines, a free firewall and a log viewer. Use it to harden a system, read logs and spot a simulated attack, and write up two projects in four lines each: goal, what you did, result and lesson.
A credential says you studied. A project shows what you did with the study.
One lab, two uses
The lab has a first job: it trains the skill that performance-based tasks test. It has a second job that people forget. After you pass, it gives you things to say in an interview.
You need very little:
- Two virtual machines.
- A free firewall.
- A log viewer.
You do not need to pay for every lab platform. CredenTrek suggests building on free virtual machines and using one practice-test source thoroughly, which is a saving that does not risk the pass.
Three sessions for the lab
The skill is short to describe: harden a system, read logs and spot a simulated attack. Turn each into a session.
- Harden a system. Take one machine, list what is running, remove what you do not need and tighten access to what stays.
- Read logs. Generate ordinary activity on the second machine, then find it in the log viewer. Do it again after a deliberate mistake, such as a wrong password.
- Spot a simulated attack. Start something noisy on one machine and find the evidence on the other.
Point the sessions at your weakest objectives. A low self-rating on monitoring or investigations deserves more lab time than a topic you already enjoy.
Keep a lab note as you go
After each session, write three lines: what you tried, what happened, what you would do differently. These notes become the material for the next section, and they stop the lab turning into an evening of clicking.
Turn two sessions into two projects
Choose the two sessions where you learned the most. Write each in four lines.
| Line | What it holds | Example |
|---|---|---|
| Goal | What you set out to do | Detect failed sign-ins on a test server |
| What you did | The steps, briefly | Forwarded logs to the viewer, set a filter for repeated failures |
| Result | What you found | The filter flagged the deliberate wrong passwords within the session |
| Lesson | What changed in your thinking | Raw logs were noisy until I filtered by event type |
The example is illustrative. Use your own lab and your own words.
Where the projects go
Before you pass, your CV can say "CompTIA Security+ candidate, exam booked for" followed by the month and year. After you pass, list the credential with its exam code and year, for example "CompTIA Security+ (SY0-701)", and place the two projects directly under it.
In CredenTrek's view, a four-line project gives an interviewer far more to ask about than a bare credential line.
Tag each session with an objective
Write the objective number at the top of every lab note. If you study V8, use the V8 number, and remember that V7 numbers differ in Domains 1, 2 and 4. After a few weeks you can see at a glance which objectives have lab evidence and which have none, and that gap is where the next sessions go.
Do not overclaim
A lab project is not work experience, and it should not be written as if it were. Label it as a home lab project. A small honest claim is safer than a large vague one.
Questions readers ask
What do I need for a Security+ home lab?
Do I have to pay for lab platforms?
How should I list a lab project on my CV?
This article is independent and is not endorsed by CompTIA. Facts change: confirm them on the official page before you act.