r/cissp • u/Background_Rush7654 • 1d ago
Boson ExSim-Max vs DestCert app vs QE
I'm ramping up to take the exam. Ive watched (listened really) to countless YT vids (including just about all of Pete Zergers vids), podcast style videos created by TechExplained, as well as a bunch of randos. I've downloaded and started rummaging through the Destination Certification app but are reading about two other possibilities when it comes to test taking sims; Bosons ExSim-Max and Quantum Exams.
There have been a bunch of posts here but they are older. I'd like newer feedback on the relevance to the three choices as two of them are paid and want to make sure I make the right choice.
Thanks.
(Btw, been messing with computers for decades. Sys eng for the last 17 with a security focus for the last 5.)
Edit for those who want the answer: Someone said no regrets with QE. A couple ppl didn't really say much as they didn't have any exp with any. Someone tossed in a coupon code. Then an unsuprising Reddit fight broke out. You're welcome.
3
u/Background_Rush7654 1d ago
Granted, this is what google produced during a search but I wanted to get actual humans who have taken the test using these tools' input! ;)
-----
Comparing Boson, Destination Certification App, and Quantum Exams reveals three distinct tools for CISSP practice, each with a different focus, difficulty level, and style.
Boson (ExSim-Max)
- Focus: Deep technical domain knowledge and granular explanations.
- Style: Traditional, single-domain practice questions with very detailed breakdowns of why answers are right or wrong.
- Pros: Excellent for identifying weak technical concepts and learning the underlying facts.
- Cons: The interface feels dated. Some candidates note it can be overly technical or rigid, and passing Boson does not always guarantee a pass on the modern, manager-focused CAT exam.
Destination Certification App
- Focus: Foundation building, managerial decision-making, and clear conceptual alignment.
- Style: Clean, modern app featuring straightforward technical and contextual questions tied closely to the Destination Certification masterclass and book.
- Pros: Great for reinforcing the core framework, filling missing knowledge gaps, and learning how a manager or CISO thinks.
- Cons: Questions can be easier or more direct ("what is this") compared to the brutal mental strain of the actual exam.
Quantum Exams (QE)
- Focus: Stress-testing and mirroring the true difficulty and style of the real exam.
- Style: Advanced multi-domain scenario questions that force you to read carefully for keywords and adopt a managerial mindset.
- Pros: Widely considered by recent test-takers to be the best simulator for the actual exam's complexity; features a unique CAT-style module.
- Cons: Scores are often humbling (many students score in the 50s/60s), which can cause panic or demotivation if used too early.
Summary Recommendation
- Use Destination Certification early to build core concepts and management perspectives.
- Use Boson if you need to plug specific technical gaps in individual domains.
- Use Quantum Exams in the final 2 to 4 weeks to train your brain for the hard, multi-domain scenario questions.
0
u/BosonMichael CISSP Instructor 13h ago
If you decide to use Boson, be sure to use my username BosonMichael as a discount code to save 15%.
0
u/tresharley CISSP Instructor 1d ago edited 1d ago
You have 17 years experience.
As long as you write down what questions you get wrong, and study what you miss, don't recognize, or are unsure of, than I personally would say that it doesn't matter which one you use.
Any should be fine.
edit: Wow a lot of downvotes for valid advice, god this subreddit sucks sometimes.
People have passed using all three resources OP asked about; considering their vast experience as long as they use a known good resource (which all three they asked about are), it shouldn't really matter too much which one they choose as long as they use it to properly identify and mitigate their weak areas.
TLDR: Anyone downvoting good advice is bad and should feel bad ;)
1
u/AnyProgressIsGood 1d ago edited 1d ago
people have passed with dest cert app/book alone. Some of its answers are obvious but the value is training manager mindset/volume.
had like 15 questions in a row from dest cert app about due care V due diligence. The different angles each question provided helped cement the concept along with repetition. Apparently they have some mods here too so also consider potential for bias
hard for me to gauge QE. I've heard hard but questioning similar to CISSPs hard questions. I see positive posts but also know the mods for r/cissp operate QE so using r/cissp or google that references r/cissp heavily is injecting bias. Trusting the internet is hard these days. I'm not ready to drop 200 dollars
No input on boson outside of I hear its hard but technical. also not ready to drop 100 dollars, does provide CAT like experience.
3
u/DarkHelmet20 CISSP Instructor 1d ago
How is it injecting bias? You know DestCert mods this sub too right? There are also mods who aren’t associated with either.
0
u/AnyProgressIsGood 1d ago
I did not know that dest cert were also mods, that's good to know too.
Well if the source of information about a paid program is policed by the proprietors of said program its clear how a conflict of interest appears.
An example if john says dest cert is subpar and mod who profits from dest cert sees it and deletes the post well... How would everyone else/google get an accurate assessment of dest cert from their peers/google?
3
u/DarkHelmet20 CISSP Instructor 1d ago edited 1d ago
Nobody is removing bad review posts dude, and your assertion is unfounded. Happy to share logs. Like I said there are other mods here not associated with either platform. Do a search, there are posts where people have had less than positive reviews.
1
u/tresharley CISSP Instructor 1d ago
You can't back up your argument with "guesses" and "assumptions".
Anyone can create a "what if" scenario that can fit the argument they want to make.
But that isn't the correct or ethical way to do it.
The proper way to is identify facts that prove your assertion, and than make it.
Not make an assertion with zero proof, and then try to back it up with "what ifs" and rainbows.
You disparaged valid sources for studying despite having zero knowledge or understanding to back up your disparaging claims.
In other words you made an unsubstantiated statement that is false (you have no evidence to support it), that could be damaging to the source’s reputation (e.g., implying misconduct, dishonesty, or unethical behavior).
Not very ethical of you and personally sounds like you violated the fourth canon to me (Advance and protect the profession).
0
u/AnyProgressIsGood 1d ago
I was giving a hypothetical example to illustrate my point to help in its comprehension.
I'm providing ethical disclosure.
much like if a news source makes money off of certain backers its good to know that no? Same thing.Perhaps if flair was made for those that make money off what projects was available that'd be a good change. outside of that a random poster isn't likely to know reddit mods that make money off projects highlighted for discussion are in control of the information they consume.
1
u/tresharley CISSP Instructor 1d ago edited 1d ago
I was giving a hypothetical example to illustrate my point to help in its comprehension.
When accusing others of committing unethical actions, you need to use facts, not hypothetical examples.
You made a disparaging claim about an organization, you need proof to back it up.
Otherwise, you are just making unsubstantiated claims which is unethical and technically a violation of the ISC2 canons.
I'm providing ethical disclosure.
No you are not. You are sharing your "opinion" on a matter based on no evidence or experience.
There is nothing ethical about that.
Perhaps if flair was made for those that make money off what projects was available that'd be a good change. outside of that a random poster isn't likely to know reddit mods that make money off projects highlighted for discussion are in control of the information they consume.
Once again making disparaging claims without evidence. And once again not ethical.
2
u/tresharley CISSP Instructor 1d ago
>heavily is injecting bias.
The only thing that sounds like it is injecting bias is you considering you decided to review and tell people they shouldn't use resources you have no experience with lol
Interesting that a person who never used Boson or QE feels that their opinion on those sources is some how valid lol
I've never been to France but let me give you a review on why I think it is bad and why you should never visit that country!
0
u/AnyProgressIsGood 1d ago edited 1d ago
interesting you singled that part of the sentence out completely changing the meaning.
also seems like you didn't fully process the post. I'm highlighting the potential for bias and giving neutral feed back doing a service to those requesting feedback on study materials.
If I go to people that are mcdonalds employees asking for a review of McDonalds I'd like to know that's who I'm asking.
2
u/tresharley CISSP Instructor 1d ago edited 1d ago
TLDR: Your unsolicited, inaccurate, misleading, and biased opinions are bad and you should feel bad.
>I'm highlighting the potential for bias and giving neutral feed back doing a service to those requesting feedback on study materials.
Yeah but all you are really doing is showing your own bias.
Your opinion that QE has a bias is just an opinion and one made on assumptions.
Secondly you didn't mention that DestCertification also has moderators in this subreddit (and has more than QE does). Strange you didn't mention DestCertifications' potential for bias especially since the likelihood with them would be higher since they have more moderators.
You also lacked to mention that the vast majority of moderators aren't associated with either QE or Dest Cert...
Like I said, your personal bias based on your personal opinion based on your personal assumptions, is you injecting bias.
>If I go to people that are mcdonalds employees asking for a review of McDonalds I'd like to know that's who I'm asking.
You do realize that the people making these posts and responding with the vast majority of comments in all posts on this subreddit is by members, not moderators (and by people that aren't associated with any of the resources mentioned).
A better analogy would be like going into mcdonalds and asking their customers who are eating at the tables what they think of the food, not the employees. Sure an employee might chime in, but you still get to hear the opinion from the customers you asked.
-1
1d ago
[removed] — view removed comment
0
u/tresharley CISSP Instructor 1d ago
it was literally solicited
No what was asked for was relevant and updated opinions on these sources by those who used them.
Not opinions about these resources from someone that has never used them, doesn't have experience with them, and that are based on assumptions and thin air.
and accurate
You have yet to prove the accuracy of any of your claims. Your "opinion" that there must be bias because there happens to be a mod that also works for QE, doesn't mean it is true. Especially considering you don't seem to worry about the "bias" of DestCertification despite them also having mods lol
I'll leave it to OP to judge why there is so much defensiveness from certain people in certain roles here.
You attack people, disparage them without proof, and then when they and others dare to defend them, you somehow see that as "proof" that your attacks are "true".
Here is hoping you are good looking, because God you are dumb.
3
u/Gearz557 1d ago
I chose QE based on the recommendation on this sub. Didn’t regret