I'm a contractor working on a DoD project and my employer just told me I need to be certified under DoD 8570 within 6 months or they'll have to reassign me. I'm in an IAT Level II role, which means I need either CompTIA Security+, CCNA Security, or a handful of other options. I've been in IT for 4 years but never sat for any formal security certifications.
Security+ seems like the obvious starting point since it's the most widely accepted and the study materials are everywhere. I've been doing about 2 hours of prep a night and I'm hitting around 78-80% on practice exams. The passing score is 750 out of 900, which translates to roughly 83% depending on the question difficulty weighting.
My main weak spots are cryptography and PKI concepts - I understand the broad strokes but the specific algorithm details and certificate chain questions get me. I've got about 9 weeks until my self-imposed deadline. Anyone gone through the DoD compliance path and have advice on prioritizing study time?
For PKI specifically, focus on how certificate chains work and what happens when one breaks. The test loves scenarios where a cert is expired or the wrong CA signed it. Draw it out, don't just read about it.
Get the Jason Dion practice exams - they're harder than the real test, which is exactly what you want. I scored 72% on his exams consistently and got an 810 on the actual exam.
Make sure your employer actually submits your certification to DISA after you pass. I passed Security+ and almost missed my deadline because the paperwork sat on someone's desk for 3 weeks. Follow up aggressively.
Security+ is the right call for IAT Level II. I passed it in 6 weeks studying about 90 minutes a day from a similar baseline. The cryptography section clicks once you draw out the key exchange process on paper - stop trying to memorize and start trying to understand the flow.
I'll be honest, I almost bailed on this whole thing. I'm in the same boat as you, IAT Level II, and I went with Security+ because it's the most common path and doesn't expire into some vendor ecosystem you'll never use. My first two practice test scores were rough. Like, really rough. I'd been in IT for 6 years and figured I could wing it, and the exam humbled me fast. The performance-based questions especially. I genuinely told my wife I was going to ask my employer for the reassignment instead.
What changed it for me was drilling weak areas one topic at a time instead of rereading the whole book. OPSEC and security operations stuff was my worst domain, so I hammered practice questions like the ones at dod/questions/operations security opsec until it clicked. Took me about 10 weeks total. Passed with room to spare, and honestly the material made me better at my actual job, which I didn't expect. You've got 6 months and 4 years of experience. You're fine. Just don't skip the practice tests like I almost did.
Honestly I almost rage-quit about two weeks in. I was in the exact same IAT Level II situation and went with Security+ because it seemed like the most straightforward path, but the material felt overwhelming at first and I genuinely didn't think I'd pass in time. What clicked for me was stopping the passive video watching and just hammering practice tests until I understood why wrong answers were wrong, not just why the right ones were right.
You've got 4 years of IT experience so don't undersell yourself, the concepts aren't new, it's really just the DoD framing and terminology you have to get comfortable with. Six months is actually plenty of time if you're consistent. I passed with about 10 weeks of focused prep and it wasn't nearly as bad as I'd built it up to be in my head.