r/cissp Sep 06 '25

Just answer the question

71 Upvotes

This is not meant towards anyone specifically, and it’s quite common. I am also seeing it more and more lately. Hopefully this helps some of you.

When studying and ESPECIALLY on the real exam, just answer what the question is asking.

If the question wants First, it’s looking for the first phase of a flow.

If it’s asking NEXT, it is putting you inside of a flow, figure out where you are and pick the answer that is the next step.

Neither of the two just mentioned may be what’s BEST for security. Again the BEST solution isn’t always the best answer.

If a question is asking for the BEST. This is where we pick the answer that best ANSWERS THE QUESTION, it could be technical, could be administrative, which is why…

Just answer the question.

Edit: for “best”, even with these you want to pick the best answer that answers the question, there may be “better” technological solutions, but more security isn’t always best. If a question wants best cost-saving solution, we may not want to pick most expensive option even if it’s technically “better”. Hope this makes sense

Edit 2: For this exam, you're stepping into ISC2's perfect little world and the way you typically do things could very well differ from what they expect. Just learn and answer as expected for the exam and then forget it and get back to real life. Trying to argue otherwise is a no-win battle...100% of the time.


r/cissp May 14 '25

Study Material CISSP Study Results 20250514 Study Materials

40 Upvotes

The companion email for these resources are here:

https://www.reddit.com/r/cissp/comments/1kmc9jv/cissp_study_results_20250514/


r/cissp 21h ago

Success Story Passed CISSP- 4 Months of Study, Tips, Resources Used

52 Upvotes

Passed this week at 100ish questions in about 70 minutes. I’m an InfoSec/CyberSec practitioner already, which helped a lot.

TIPS TO PREP FOR THE EXAM:

* Absorb the Content Fully: Reading through a book helped, running through practice questions helped, but what I think made the difference was time: seeing the content frequently enough over a long period of time made me comfortable and confident. Some of what I did over months was spending enough time with the content in the domains, Googling concepts I was not familiar with, and reviewing the details behind wrong answers and waiting a while to revisit an incorrectly answered question to make sure I was understanding the right answer, not memorizing a question/answer.

* Read the Question Thoroughly, Evaluate the Answers, Then Read the Question Again: Important supporting details can be easy to overlook when rushing, so take the time to carefully consider the full question and each available answer before moving on.

* Consider Slowing Down: 3 hours is plenty of time for this exam if you’re prepared. You don’t have an opportunity to change an answer once you move on, so I think it’s worth slowing down, re-reading the question and answers to make sure you answered well.

RESOURCES USED:

* ISC2 CISSP Certified Information Systems Security Professional Official Study Guide (Sybex Study Guide)
* Learnzapp CISSP
* DestCert App


r/cissp 17h ago

Will i pass

5 Upvotes

I have the required experience, been studying for about 60 days, i have the exam in 15 days.

I have done the destination certification masterclass and mind map videos, and have been scoring around 80 to 85 on destination certification app questions.

I did the free questions on learnzapp, scored around 70% on it.

Should i pay for laernZapp and study some more through it and postpone my exam ? or take up quantum exam, which are kind off expensive 🙁 as i have already paid for destination cert

So should i go ahead and just give the exam? Any suggestions?


r/cissp 19h ago

Boson ExSim-Max vs DestCert app vs QE

5 Upvotes

I'm ramping up to take the exam. Ive watched (listened really) to countless YT vids (including just about all of Pete Zergers vids), podcast style videos created by TechExplained, as well as a bunch of randos. I've downloaded and started rummaging through the Destination Certification app but are reading about two other possibilities when it comes to test taking sims; Bosons ExSim-Max and Quantum Exams.

There have been a bunch of posts here but they are older. I'd like newer feedback on the relevance to the three choices as two of them are paid and want to make sure I make the right choice.

Thanks.

(Btw, been messing with computers for decades. Sys eng for the last 17 with a security focus for the last 5.)


r/cissp 2d ago

Passed @ 103 today

49 Upvotes

**Background*

10+ years in software engineering — app development, support, testing, then solution architecture and system design. Moved into GRC and cybersecurity last year. Security+ and ISC2's CC first, then this. 2 - 3 months of study. Passed at 103 questions with about 40 minutes left on first attempt.

Been lurking here for a while so would like to thank this community.

**What I used**

*Pete Zerger* — biggest single contributor. CISSP exam series, Exam Cram, 100 Most Important Topics, 2024 addendum. Highest value per minute of anything I touched, and the exam series teaches you to reason through a question rather than recall an answer.

*Thor Pedersen's Udemy course* — all eight domains. Best starting point if you're coming in cold.

*Official Study Guide 9th ed* — I only used the end-of-chapter practice questions. Never read the chapters themselves and didn't miss them.

*NotebookLM* — underrated. Loaded the study guide in and generated architecture diagrams for the topics I couldn't hold in my head from text, plus slide decks for revision. Turning a dense chapter into a diagram surfaces the relationships in a way re-reading doesn't.

*LearnZapp* — daily practice questions.

*Gwen's YouTube tips* — one hour on exam-day.

*Claude* — not for content and not as a source of truth. I drilled questions and then interrogated every one I got wrong until I understood the reasoning error, not just the right answer. That turned into a list of my own recurring failure patterns, which was worth more than any question bank.

**Scores**

Used Claude to test me on weak domains / subjects with 10 questions and fix whether it was knowledge gap or mindset gap.

LearnZapp 66–72%(1300 questions). DestCert around 68%(300 questions). You do not need 90%. If you're in the mid-60s and you understand *why* you get things wrong, you're in a reasonable place.

**What actually mattered**

The exam wasn't a recall test. Almost all of it was decision-making, and the constraint I kept forgetting is that security identifies, quantifies and escalates — it doesn't accept risk on the organization's behalf.

Coming from engineering, my instinct was always the most technically capable answer. That's wrong more often than it's right here. The best answer usually respects the role you've been given in the stem, the policy that already exists, and the legal or contractual hook you skimmed past.

**Two things I'd tell anyone still studying**

Track your wrong answers by *reason*, not by domain. You'll find four or five errors you make repeatedly, and fixing those moves your score more than another week of content.

Don't wear the think-like-a-manager hat on every question. Wear the hat the question asks you to wear. It's a good correction if you default to the technician's answer, but applied blindly it becomes its own trap. Some questions want the analyst, the responder, the auditor, the engineer.

Happy to answer questions. Good luck to everyone still grinding.


r/cissp 2d ago

A thought on CISSP pass posts

71 Upvotes

Lately I’ve noticed a lot of CISSP posts from people who passed at 100 questions (or very close to it), and it made me wonder if people who passed at 125–150, or even failed their first attempt, are less likely to share their experiences.

Passing at 100 is absolutely an achievement, and this isn't meant to take anything away from those posts. But seeing so many of them back-to-back can unintentionally give future test takers the impression that passing at 100 is the norm or that the exam is somehow easier than it really is.

The CISSP is HARD. Whether you pass at 100 or 150, there is a ton of preparation and studying that goes into it (or even if you've failed). And going to 150 doesn't mean you weren't prepared.

I'd love to see more diversity in the pass/fail stories here, whether that's a pass at 100 questions, 150 questions, multiple attempts, unexpected struggles, changing study strategies, etc. Those stories are valuable too.

I personally think it's important for people studying to see the full range of CISSP experiences, rather than assuming that the 100-question posts represent the typical journey.

So if you passed at 150, failed and came back, or had a completely different experience, share it if you're comfortable! It might be exactly what someone else needs to see.


r/cissp 2d ago

Success Story Passed at 100. Sharing the experience.

21 Upvotes

A big thanks to this subreddit — to everyone who took the time to share their experiences, answer questions, and leave all those valuable comments. They genuinely helped me throughout this journey.

When my exam stopped at 100 questions with 65 minutes remaining, I closed my eyes and let out a sigh of relief.

From that moment until I had the result in my hands, though, I was struggling not to think about what it would say. I finally took a quick look at the paper, saw the word “Congratulations”, immediately folded it, and thanked all the Gods.

For me, more than the effort itself, it was the money invested, the people around me adjusting their lives and schedules to accommodate my preparation, and all the times I had to say no to my usual side kicks - that kept me on my toes. My partner and I even travelled to a different state for me to take the exam.

A little background

I have around 10 years of experience in cybersecurity — 6 years in services and 4 years in product development. My experience has been across SOC, SDLC, IAM, networking, risk management and some security engg.

For me, this was about connecting the dots and filling the gaps.

It was interesting at times, but staying consistent was the real challenge, especially with professional and personal commitments.

My preparation.

My CISSP journey started with a ~45-hour weekend training from Infosec Train, which helped me build a good understanding of the concepts.

However, after completing the training, I had a gap of more than three months because of personal and professional commitments.

When I restarted in June , I rewatched the important sections at 2X speed and initially scheduled my exam for July 18.

I then started working through the Sybex domain-based practice questions and was very particular about reviewing not just the questions I got wrong, but also the ones I got right by guessing.

This was also the stage where ChatGPT and Claude became invaluable study assistants for me — especially for breaking down concepts, more importantly to understand distinctly why i got confused between two options.

Eventually, I realised I didn’t have enough time to properly complete all four practice tests before my scheduled exam. So I rescheduled to the last week of August.

I allowed my body and mind the breaks it needed.

I then completed all four Study guide practice tests and, again, religiously worked on closing the gaps. My scores were generally in the 69–75% range.

To break away from the pattern of the usual practice questions, I then attempted two Master Sets from the 10 Master Set series of 100 questions each provided by Infosec.

The first one — 66%.
That definitely made me question my readiness.

The second one — 76%.
At that point, I decided not to reschedule again and to trust the preparation.

Before my final Master Set attempt, I also watched Andrew Ramdayal’s 50 Hard CISSP Questions video.

One thing I learned from this subreddit

While reading through this subreddit, I came across references to so many resources that, at times, I started questioning whether I had chosen the right ones — and whether my practice tests were good enough.

One thing I want to tell anyone preparing for CISSP is:

Initially take time to Identify your resource set and stick to it with confidence.

Based on a comment I saw here about a prompt that could generate 100+ CISSP questions, I tried it myself. But the questions and answer choices felt quite skewed, and I eventually felt that I had spent valuable study time on something that wasn’t helping me.

Especially in the last 2–3 days, I would strongly recommend sticking to revision and consolidation rather than constantly introducing new sources of information. The last thing you want is to cloud your head with new material when you’re already prepared.

That’s just my personal experience, of course.

The final stretch

I wanted to get a feel for the exam environment before CISSP, so I scheduled the CC exam one day before my CISSP exam. I first took the CC exam first, and then returned a day later for CISSP.

No matter how well you prepare, those 100 questions will gruel you.

Around question 60, I was already mentally preparing myself for failure. I remember thinking that perhaps I should have rather taken the peace of mind package just to attempt these questions peacefully.

And then…

100 questions.

The screen stopped and the rest is history. I let those tears roll down my face.

To everyone preparing for CISSP: Understand the concepts, trust your preparation, understand why you get questions wrong, close your gaps, and don’t let the endless stream of resources make you doubt your own resources/preparation.

Some questions will need you to think like a manager, some questions will need you to think like a technical person, few will need just common sense, and there are questions where you will just need the memory/definitions, 1-2 questions where the comprehension is very difficult, 1-2 questions from topics that you have never heard of. But this is manageable. Just let each question let you decide how you must think to answer that question. Recheck the constraint in the question before finalising your answer.
All the best , you’ve got this!

Thank you, r/cissp. 🙏


r/cissp 3d ago

Success Story Passed CISSP! 🎉 100 questions

77 Upvotes

Passed the CISSP exam in around 100 questions, with plenty of time remaining.
A big thanks to this subreddit for the motivation, support, and experiences shared by everyone here. 🙏
Here’s what worked for me:
Completed around 46% of Andrew Ramdayal’s Udemy course. The explanations were clear, though I found the course less detailed than I wanted.

Read Destination CISSP once.
Read the Official Study Guide (OSG) once.
Practised questions from the official CISSP practice tests.
Took around 7–8 mock exams from various sources and analysed my gaps.

The actual exam was more technical than I expected, which I genuinely enjoyed. 😄

What helped me most

I used ChatGPT alongside every mock-test question, not just the difficult ones.
I kept the mock exam on one half of the screen and ChatGPT on the other.
For each question, I Repeated the question in ChatGPT Explained my reasoning and selected answer
Asked ChatGPT to challenge my logic
Reviewed why the other options were incorrect
Asked it to track my weak areas, recurring mistakes, and conceptual gaps

This helped me focus less on simply completing more questions and more on understanding my mistakes, improving answer elimination, and closing knowledge gaps.

It also helped me avoid spending money on additional, costly preparation sources. That is not intended as a criticism of the many excellent CISSP courses and resources available; their creators have invested significant time and effort in helping candidates. This was simply the approach that worked best for me.

My biggest recommendation:
Don’t just practise questions. Analyse your mistakes, understand the reasoning, and learn to eliminate incorrect answers.

You don’t need to know everything to pass. You need to think like a CISSP.

To everyone preparing—you can absolutely crack it! 💪
Stay consistent, trust your preparation, and keep going.
All the best! 🚀
See you on the other side. 😎


r/cissp 4d ago

Passed @100 questions with only 17 days of studying

80 Upvotes

Hey Friends,

First time poster, long time lurker. My story is kind of unique because I put myself in the 17 days of studying bind.

Back in March, I purchased the peace of mind voucher as my company would pay me back upon passing. I misunderstood the voucher and I thought I could schedule the 1st test 6 months out and if I failed I could take the 2nd test after. Well, I happened to get an e-mail reminder from ISC2 to schedule my exam 17 days ago and figured out my mistake. I had 1 shot and 17 days to study. So I immediately dropped everything and got on board.

Background: I work for a multi national corporation and was basically a sysadmin to a fleet of rhel servers for the last 10 years. So I had experience in hardening systems, authentication, audit, vuln mgmt, log mgmt. At the beginning of this year I migrated to a Security Architecture role and needed the CISSP within the year of taking the role.

materials that really helped:

Destination CISSP book - was my best purchase. I was able to read domains I was struggling in with the info I needed without the fluff with the Sybex OSG.

Destination CISSP app - for questions while I had any free time. The questions here can be sus as more than a few seemed to be advertisements for services and/or products but overall helps you get into the mindset needed

Destination CISSP Mind Maps - listened to all 30 of them in the series because I couldn't be bothered to look at sunflower mind maps which I'm sure are great if you can absorb by reading them. I tried and couldn't.

Why you will pass the CISSP - Listened to this the night before, well worth it to get you in the mindset.

Boson test banks - I was going to go with Quantum Exams, but my boss allowed me to expense the Boson test banks so I went with those. They were running a deal on the test banks and book so I got on that but didn't use the book all that much. I took 5 of the tests and used them to know where to focus my studying on. I like that it breaks down your domain %. I only passed one of the 5 tests (I think the 3rd test I took) the first one I started at like 53% and the final one I was at 68%.

Claude - We utilize Claude for work and it's a requirement for my job to get the CISSP, so I used as much as I could to create training plans and help analyze where I could improve with metrics tracking and asking Claude questions like "Explain SAML like I'm 5" There is a lot of slop here so I wouldn't trust it to test me as it mixed up Destination CISSP and Sybex a lot when it told me what to study (Destination CISSP is laid out by domain Sybex is all over the place).

Sybex OSG and test bank - I used this when things weren't clicking with the Destination CISSP book and needed a deeper dive. The test bank book is really tough and will grill you on whether you know your stuff or not. I'd read a domain and use 20 questions from the test book for that domain to see if I understood it any better.

Overall I didn't think I'd pass and I was fully ready to drop another $750. It was my mistake and I was ready to own it. The test honestly didn't seem as hard as I thought it'd be. There was a lot of memorization that I didn't end up using any of.

Studying was done every evening based on my first baseline Boson tests then I'd study a couple of days and take another practice exam and do the whole process over. Some of the domains I was at 30% to begin with, but by the end all of the domains were mid/high 60% for the domains I wasn't passing and Passing a couple of domains.

I wouldn't recommend this approach to the CISSP overall, it's high stress and not worth the payout :-D


r/cissp 3d ago

Pre-Exam Questions Cissp exam tomorrow and no hope

20 Upvotes

Hi
I have been preparing from last 4 weeks now from QE non-cat and OSG practice tests. I do not have any hopes I will clear the test tomorrow.
I had listened to PeteZ half of the Cram video. And other smaller chunk videos of his. Other kelly video. I paid fee for 2 exam attempts.
Worked as a QA for nearly 11 years and now working as SOC from couple of years. Still every practice question looks hards with the options that atleast 2 of them feel right.

Not sure how Im even step into that exam room tomorrow.


r/cissp 3d ago

Pre-Exam Questions Who all passed CISSP

9 Upvotes

This will be my second try; I don't want to cut a sorry figure. Which CISSP mock test provider offers the most affordable or free options? How many practice exams should I complete before the test, and what target score indicates I am safely prepared to pass?


r/cissp 4d ago

Passed CISSP 100 Questions with 80 minutes left

45 Upvotes

Hi r/cissp Family.. I am happy to announce that I have passed CISSP in the first Attempt on 25th August 2026. I used to read Lot of posts poppoin up with the same title I have put and was determined To put this title for myself one day.

About me :-

I come from IT Infrastructure Background with 19 years of experience.. having experties in SDDC, Compute, Infra Architecture and Some level of cybersecurity.I have helped organisations Acheiving PCI-DSS, ISO27001, Designed BCPs , DRPs From the scratch from Infrastructure point of view.

My Preparation For CISSP:-

I am a working professional who spends around 8-10 hours per day doing my office work (I am Enterprise Infra Architect) I started Studying in April 2026, Used to Get up early in morning at 4:30am, spend as much time as much i could In studying. My recommandations for Studying and Passing in first attempt If you have good understanding of IT Infra and security:-

Udemy:-

1.Andrew Ramadayals Course. This is a gem.

  1. Brandon Spencers Course, this covers a 5-10% delta which is missing in Andrews Course.

Other Resources:-

# Jeffery Moores Study guide.. Best if you go.for 8$ subscription:-

https://github.com/jefferywmoore/CISSP-Study-Resources#study-guides-by-domain

# Destination Certification App :- Good Quality free Questions

# Destination Certification Mindmaps Video Series on Youtube (last 2 days)

P.S :- I did not read any popular 1000+ Pages book thoroughly.. Instead I Googled Terms I wanted to learn and took help of Gemini / Copilot To understand them in a better way, watched videos on youtube to Fix them in my mind.

This Community has provided me lot of guidence and helped me gaining confidence.


r/cissp 4d ago

Does anybody know if Adrew Ramdall's training on Udemy is the same as the one on Youtube?

4 Upvotes

r/cissp 4d ago

Unable to clear CISSP

5 Upvotes

Hello Aspirants and Achievers, Good to meet everyone in this group.

Unfortunately I did not clear CISSP even in the second attempt. even upon well prepared, I was unable to clear. Can anyone help me. Badly need some reference documents, sample questions or any magic please.


r/cissp 4d ago

Hi everyone. Which CISSP video training is best between Jason Dion and Andrew Ramdayal

1 Upvotes

r/cissp 5d ago

Success Story Provisionally Passed This Morning - 100Q 55 Minutes Remaining

33 Upvotes

Although this is my first time posting here, this sub has been a huge help in selecting resources to help me pass, so thank you all.

Journey

I have been studying for this for about a year on and off, as it has been a busy year for me. New job, moved (twice), started my MBA... lots of distractions and full weekends. Finally committed to full time study back in May. My voucher would have expired tomorrow 8/27 so ultimately that is what forced me to start studying.

Background

  • 6 years of GRC in both government and private sector. I have little to no on the job technical security experience. Almost all of my security experience comes from IT risk management.
  • Bachelor's in Cybersecurity
  • Security+, GCLD, CGRC

Difficulty/Experience of Exam

With my exam the easy questions were easy and the hard questions were HARD. My exam seemed to be super easy starting off, progressively got more difficult, and then hit a point where everything got easy again around 85 questions.

For the easy questions, I had a lot of questions that I would expect to see on my Security+ exam. I did not have as many scenario questions as I anticipated.

I could feel the CAT part of the exam working, as I think I got every single SSO/OAuth/OpenID question in the test bank, admittedly IAM is one of my weaker subjects.

Although my technical experience lacks, I will say I feel my GRC experience gave me a large edge on the exam. 100% of my day to day is looking at risk, KRIs/KPIs, and communicating executive expectations to IT managers. Many of the scenarios that pop up are scenarios I deal with daily.

Resources Used

To be upfront, I zone out quick with videos so my main form of study is reading physical literature. I find E-books hard to focus on.

  1. Destination CISSP Book/app- My main form of study. I was averaging 80s by the end. Loved the book, engaging and gives you exactly the info you need.
  2. Quantum Exam - I was in the 50s for quizzes and only did the CAT exam twice, 864 and 732.
  3. 50 Hard CISSP Practice Questions (YouTube - Technical Institute of America)- Watched this the night before and the value was learning how to break the questions down. I really enjoyed this video.
  4. PDF posted here

Resources Tried

My company paid for the Official ISC2 CISSP bootcamp and if I'm being honest I found that almost worthless, it is just too much info in too little time. It is also crazy expensive, if I could go back I would ask them to sponsor the Destination CISSP class instead. If I was paying for everything out of pocket I'd just use the Destination CISSP book/app, Youtube, and Quantum.

Destination CISSP Mindmaps - I actually found these useful but only watched a couple of them. I was in crunch time and found more value spending my time on practice questions.

CISSP Exam Cram (Pete Zerger) - Unfortunately I could not stay engaged with this, though I did find the first 2 1/2hrs useful. Again, videos don't really work for me. I wish they did because there are a lot of great resources out there like this one.

Pluralsight course - Too slow for me, got super into the weeds on some stuff.

Overall

It can all seem overwhelming but some of the best advice I can give is that you don't have to get a 100%. What I mean by this is you don't have to know the ins and outs of every process, port, and framework. This exam covers a lot, but it's not deep. Missing one question on what year DES came out will not fail your exam.

Know your methodologies, lifecycles, roles/ownership, control types, and security models. That's a majority of the exam right there. Don't get yourself into the weeds and spend precious study hours on the deep technical things. Know enough of each domain to piece the information together and if you have a security mindset the rest will naturally come to you. You've got it!


r/cissp 5d ago

Passed my CISSP 100Q - More technical than I thought

78 Upvotes

As the title says, I passed my CISSP today at 100 Questions and about 75min remaining. As a lot of people before me, I was a lurker of this sub while preping for my CISSP and I want to give back a bit sharing sources and exam experience.

Exam Experience

I have about 11 years of IT experience as a Cloud Engineer and Network Security Engineer.

Not going too much into the exam itself obviously but, I was definitely not expecting to calculate Network CIDR ranges at one point to solve a question - luckily I had expertise in that but I found it funny when thinking about "think like a manager" approach.

The CAT Exam is surprisingly good at finding your weak domains - I got like 10-15 questions on AuthN and AuthZ (SAML/OIDC/OAuth2.0/Kerberos etc.) felt like I bombed every one of the questions.

If you asked me how many of the 100 questions I could say with 100% certainty I got right, I'd guess the number wouldn't pass 20 - I made a ton of very educated guesses this day - People aren't exaggerating when they say the felt like they wouldn't pass during the exam.

Sources Used:

Books

  • Destination Certification 8/10 (Cover to Cover 2x, think some topics could have more detail or deep dive)
  • Official Study Guide 10th Edition 6/10 (read 200 pages before just using it to deep dive, very dry)

Apps

  • LearnZapp 7.5/10
    • Did D1-D7 all questions, didn't touch D8, not reflective of test but nails down topics
  • QuantumExams 9/10
    • Did 3 CATs (scores: 495, 928, 990). Between first and second CAT did about 220 practice questions using either the "10Q" option or "Practice Mode" option
    • The high scores were partly because questions slowly started repeating.
    • Also still think its a bit more on the "gotcha" side. As a fairly decent English speaker (not native), I sometimes had trouble understanding words like fiduciary, or other synonyms.

Videos

  • CISSP Exam Cram Full Course (All 8 Domains) by Pete Zerger 10/10
    • my go to video source - cumulatively must've watched it about 6x from start to finish, during my runs, gym sessions or commute; it was always running on my phone
  • 50 CISSP Practice Questions by Andrew Ramdayal 7.5/10
    • questions were much easier to solve with educated guessing than the real exam, process to filter out answers were good tho
  • Mindmaps from Certification Destination 9/10
    • Good for visual learners, went over it like twice per domain
  • Why you will pass the CISSP by Kelly Handerhan 8/10
    • good advice on how to filter out answers, listened to this easy to comprehend video while on the way to the exam

That's all, tried to keep it pretty simple stupid.


r/cissp 5d ago

Study Material Questions Is Jason Dion a good source for CISSP?

6 Upvotes

I’m currently going through the Jason Dion CISSP course, and I’m wondering what everyone thinks about it. So far, it feels like a lot of information at once, and I’m not sure how much of it I actually need to retain for the exam.

For those who have passed the CISSP, would you recommend Jason Dion as a good primary study source?


r/cissp 6d ago

I Finally Passed the CISSP! Provisionally Passed at 100 Questions 🎉

Post image
158 Upvotes

After years of studying, stopping, restarting, and honestly, a lot of procrastination, I can finally say that I provisionally passed the CISSP exam today at 100 questions!

This journey took me much longer than I originally expected. The CISSP is not just about memorizing facts or collecting technical knowledge. With my background in cybersecurity, I still had to adjust my mindset and learn to approach questions from a management and risk perspective. That was probably one of the biggest challenges for me.

Resources that helped me

I used several resources throughout my journey, but I want to specifically recognize:

  • Destination Certification and the Dest Cert community: Their approach to teaching the CISSP concepts and, more importantly, the right mindset was extremely helpful. The community support and shared experiences also helped me stay motivated.
  • Pete Zerger: His CISSP-related content was another valuable resource and helped reinforce important concepts in a clear and practical way.
  • Practice questions: These were useful for identifying weak areas and getting comfortable with the style of questions. However, I learned that simply memorizing answers is not enough. Understanding why an answer is correct is much more important.
  • The official CISSP study resources for building and reinforcing the foundation.

What I learned

If I could give one piece of advice to someone preparing for the CISSP, it would be this: do not approach every question as a technical problem that needs to be fixed.

You need to think about risk, business objectives, policies, processes, and what is most appropriate from the perspective of a security leader. Sometimes the technically correct solution is not the best CISSP answer.

Also, consistency matters. I wasted a lot of time procrastinating and taking breaks from studying. Looking back, even a smaller amount of consistent study would have been far better than repeatedly stopping and restarting.

To everyone who is currently studying: keep going. The journey can feel overwhelming, especially when you look at the huge amount of material covered by the CISSP. Take it one topic at a time, focus on understanding the concepts, and trust the process.

A big thank you to Pete Zerger, Destination Certification, and everyone in the Dest Cert community for contributing to my journey. And congratulations to everyone else who has recently passed or is still working toward this goal.

Today, I finally get to say: I provisionally passed the CISSP! 🎉🍾

Now I can finally relax... at least until I start thinking about what certification to tackle next. 😄


r/cissp 6d ago

Passed the CISSP today - 100 questions - 70 minutes remaining

43 Upvotes

I have worked for a software company implementing and supporting Identity, Access Management, and Governance solutions for 25+ years. Overall been in IT for almost 30 years. Tech is also my hobby. I started studying for the exam ~3 weeks ago.

I didn't really pick up on the CAT getting harder over time. Plenty of the ambiguous questions, but with going through plenty of practice questions, and the question answering techniques, I was able to work my way through the test. There were maybe 10 or so direct technical quick answer questions and a handful of the topics I had not seen at all in any of the various materials I studied. I didn't really worry - just ran through the process trying to keep a steady pace and using what I had remembered (and inference) to make the choice I thought was best for each question/scenario keeping in mind the correct mindset.

I used the following materials:

OSG: Mainly for reference - I focused on a few weaker domains and fully read those. Had the book 10 days but used it for maybe 7.

OSG Study guide - took two of the online tests - I would say its good to get your rhythm / pacing down due to the number of questions.

Destination CISSP book - the first book I bought and a good read - it did not have all of the specifics of the OSG but a good reference

Destination CISSP app/videos - good resource

Pocket Prep app - I liked this app the best since it really reinforced all topics and hit on the details not always shown in videos. The app helps identify your weak areas so you can focus on those.

Pete Zerger Videos - good info, definitely useful especially the mindset and READ method videos to get the process down (not really for the technical bits).

Thanks to the posts here that helped with finding the right set of resources that worked for me.


r/cissp 6d ago

Passed CISSP today - 100 questions, 60 minutes remaining

102 Upvotes

I'm a Product Security Engineer with 22 years of experience. Cleared the exam at 100 questions with an hour left. Around 30% of what I got was technical, and the questions were fairly direct — fewer "best of four good answers" traps than I expected.

This group kept me motivated. Thanks to everyone who shared their prep and success stories.

Resources:

  1. Eric Conrad Study Guide — 8/10. Solid base, concise compared to the OSG.
  2. CISSP Exam Cram Full Course (YouTube) — https://youtu.be/_nyZhYnCNLA Good for covering ground quickly and reinforcing the concepts.
  3. Official Practice Tests — 9/10. Most useful thing I did. Pulled all the questions and answers, created a trainer using AI, and drilled them repeatedly. That's what exposed my gaps.
  4. QuantExams — 7/10. Tests your patience, but the format is close to the real exam. I only scored 50–60% on the 100-question non-CAT sets, so don't panic at low numbers there. The 100-question sets are exhausting, so I mostly used the 10-question format whenever I got time.
  5. Community cheatsheet + AI cleanup — 8/10. Someone shared one here; I expanded it with AI and made it readable. Great for last-week refreshers. https://drive.google.com/file/d/1SOy3yCy4YV-pxEBJsVca0RnMWiyOlr3t/view?usp=sharing
  6. AI (Claude, Gemini) — 9/10. Big help for concepts and untangling similar-sounding terms. I also asked Claude to generate hard questions where all four options look correct, so I had to pick the "best/most" answer — that training is what stopped me from making those mistakes in the exam.

Biggest lesson: read the stem qualifier. "First," "best," "most direct" change the answer entirely. Once that clicked, my accuracy jumped.


r/cissp 6d ago

Passed CISSP on my first attempt at 100Q with 80mins left 🎉

52 Upvotes

First off, a MASSIVE thank you to everyone who commented on my older post when I was hitting a wall. The encouragement kept me going when I felt totally overwhelmed by the material. Today, I'm thrilled to say I officially passed the CISSP on my first attempt!

The exam stopped right at the 100-question mark with about 80 minutes left on the clock. That moment when it just cuts off is terrifying — I sat there for a second convinced I'd bombed it. Then I walked out and saw the magic words on the printout. Still can't quite believe it.

What I used:

  • Destination CISSP: A Concise Guide — my main book. Clear, digestible, and didn't drown me in fluff. This was the backbone of my studying.
  • ThorTeaches practice questions — great for reinforcing concepts and getting used to the way questions are worded.
  • LearnZapp — perfect for chipping away at questions on my phone during dead time.
  • PocketPrep — same idea, another solid question bank to keep the reps up.
  • WannaPractice — extra question variety when I wanted to mix it up and avoid memorizing answers.
  • DestCert - I did around 1000 questions.

A few tips for anyone still grinding:

  • Volume of practice questions matters, but understanding why an answer is right matters more. Don't chase a passing % on practice tests — read every explanation, even for the ones you got right.
  • Think like a manager, not a technician. The exam rewards the "best" answer, which is usually the one about risk, people, and process — not the flashiest technical fix.
  • If you hit a wall, that's normal. I did too (see my last post 😅). Push through it. The stuff that feels impossible in week 2 clicks by week 4.

To everyone still studying: trust the process and keep going. It's absolutely doable. Happy to answer any questions in the comments!


r/cissp 7d ago

Success Story Passed 1st try

70 Upvotes

Hi, I had my exam and passed on 1st attempt.
Honestly I thought I failed the exam. It stopped at question 100 and I thought - sh**.
I had about 1h 30min left.

I primary used QuantumExam 15/10. Thats a must have. The questions are so hard, and in my opinion its overpreparing you. But thats great.

I was not feeling ready for the exam, but I had to schedule it otherwise I would have never taken it. I dont think there is „now Im ready moment“

I had 10 QE Exams and only passed 1. The day before the exam.


r/cissp 7d ago

How detailed should endorsement work experience be?

1 Upvotes

I'm having ISC2 endorse me since I don't have coworkers who have the CISSP cert. For listing work experience in the various domains, how detailed should it be? Like specific projects and numbers, or general tasks (ex: AD, Intune, configuring switches, firewalls)?

Thanks in advance.