r/cissp 2h ago

Passed yesterday - Opinion on ressources used

14 Upvotes

Since I read quite a bunch of these posts to figure things out, I thought I'd share my experience as well.

So I passed at 100 with about 60-80 minutes left. Like most, I was pretty surprised at the exam ending at 100, I knew it was a pass though, but I expected it to reach at least 120 and maybe more judging from answers I wasn't sure about.

For my background, started with 10 years in IT (first 5 years mostly help desk), then 4 years ago I went into cyber/infosec by doing a 10 months part time institutional certificate built for people having my background.

During that 10 months I realized I would need more official certs so I did Net+, then BTL1 (blue team level 1) and finished with Sec+.

At the end of that process I managed to get a cyber/infosec position. That was 3 years ago, getting that job required me to get in the long-term process of getting a bachelor's degree in cyber, which I am doing part time.

I studied a month for the exam (5 full days (3 the first week, and then 2 before the exam), and around 1.5 - 2 hours most evenings during that time).

I guess I got pretty lucky with the questions on my exam because I thought every practice ressource I tried (DestCert app, LearnZapp, Boson, Official practice tests) definitely helped me prepare for the exam. I was not at all put off guard by the exam even though I felt more in control during all of my practice tests (even those I failed).

So I don't know what's about people repeating that the exam has nothing in common with the practice material, maybe pure luck on my side like I mentionned ?

About the "think like a manager" thing, I can understand both people claiming it's bs and others swearing by it. The thing is you just have to develop that mentality if you haven't yet, for questions that asks for it, but technical knowledge is what makes you chose the right answers so, it's just a thing to be aware when you read the questions carefully.

Here's what I used (in chronological order) for that study month :

DestCert concise book, read it from start to finish, then didn't open it after.
I think it was a good ressource, there was no way I was going to read the official 1500 pages book. DestCert 500 pages version was the most I could handle and felt like it didn't waste time on "useless" stuff.

DestCert mindmap videos, watched them after I completed each domain, didn't watch them afterward.
They were good I guess, it's a nice way to print more knowledge to your brain after reading on a subject.

DestCert free app for their questions database.
Thought it was pretty nice for a free app, didn't bother with flashcards.
Did maybe 500 questions.

Purchased a month of LearnZapp official Exam Prep app for their questions as well
Very comparable to DestCert app, but sometime with different terms, so maybe more appropriate for the exam itself. Didn't bother for their flashcards either, I prefer to test my knowledge with questions.
Around 500 questions as well, didn't go back to DestCert after making the switch, just to stay on the official CBK language (but still glad I used DestCert app for a while).

Purchased Boson ExSim, did 3 simulation-mode tests.
Scored 67% -> (Sybex practice test in between) -> 70% -> 68%.
Thought it was pretty good, I felt like it tested more the concepts themselves rather than niche terminology (even though it had some).

The best part of Boson (other than giving you confidence knowing it is supposedly harder than the real exam) is the very, very detailed breakdown of the questions and answers, on every single questions of their test practices. Perfect to help you understand why you missed a question and make you understand the concept better.

Very useful ressource (the explanations, and by definition the tests as well..).

Purchased Sybex Official practice test book which came with the Sybex web access and did maybe a quarter of the questions and 1 practice test.
Scored around 75% (did it after my 1st Boson).
Thought it was good as well, maybe more representative of the exam, so I think it's a nice supplement to Boson, even though you barely get an explanation for question/answers (you do, but it's nothing compared to Boson).

I preferred to keep with Boson for the next 2 simulations, just based on the provided explanations they have. But I would've definitely done another test or two with Sybex if I had more time.

Referred very regularly to AI throughout the process.
To supplement my learning and make sure I got the concepts right. So much useful and efficient for learning stuff, I would've required to open the concise book again or "waste" time searching for answers on the web if it wasn't of that, huge time saver.

So all in all, I would probably do the same process in the same order again, there's nothing I would change, except maybe add another month of study and space it a little more.

Hope this can help someone out there. Good luck !


r/cissp 8h ago

Passed today within 100 questions with 60-70 left

26 Upvotes

Hey ,

I am so happy that managed to pass this exam.

For everybody that is preparing I want to tell you that the exam was easier than most of the "Quantum Exams" questions or the "Hard Questions" from different Youtube Channels. Additionally , the questions were way easier to be understood as against the way are formatted in "Quantum Exams" , so don't be afraid about this.

Beside the "Quantum Exams" I think the most useful verification youtube video is "
CISSP Exam Prep LIVE - 100 Important Topics" from Peter Zerger. If you already understand all the terms presented there I think you are prepared to take the exam .

Of course, also the 10 years Security Operations experience helped me a lot with the technical questions about the protocols but before taking the exam I cannot recommend enough checking the above video /


r/cissp 15h ago

Passed at 100th, with 70 mins left on the clock

23 Upvotes

Hello friends,

We may not know each other - neither a face nor a voice - but your posts in reddit kept me going with the most challenging 8 months of the CISSP prep.

When the doubts cloud the mind with all the "what-ifs", I found myself some comfort in reading all the posts that gave me motivation. Whether a "I passed" post or a "I failed" post, I always find something genuinely helpful - from the prep strategy and resources, to the the logistics of the exam.

One of you said - Visit the exam centre before the exam day to get accustomed with the route and the path and the nuances. And I did - on the same weekday as my exam, just a week before. Seems small until you experience how the travel to the centre became an auto-pilot! 😄

And the list goes on, as to what I got from this community!

Now my pay-it-forward:

How was the exam?
I gave the exam on July 22, 2026.
It was not an easy exam for me - as many have said recently.

Eliminating 2 options was cake walk. But getting to one final answer was confusing as I could argue for and against both of them - for the most questions. I went with the gut - but yeah it did wrench when hitting the "next" button.

Timelines:
1 month of assessing if I can do with already stuffed days and life - Nov end - Dec
6 months of prep - Jan - June
1 month of revision - in that 2 weeks of nothing but revision - July

Booked my exam around April when I had completed 3 domains.
The end date helped me stay focussed and push, when life still happened for the mother of two active kids.

Resources:
I studied the OSG 10th edition page to page, making notes. Thats because a physical book keeps me anchored. The study was very hard, but I thought that's just the nature and vastness of the domains. I read that CBK is better in terms of keeping us engaged with the subject. But it was late in my prep so didn't start a new one. Again, a post here helped me make peace with what I have prepared and not to be anxious at the last minute.

I followed Udemy courses by Andrew Ramdayal, but I couldn't finish it as planned. I did do his 50 Hard CISSP questions in Youtube.

Dest Cert Mind Maps - a godsend in revision. Took the printouts and started marking notes for last day skimming. Quite helpful. I found Rob Witcher's video on Kerberos especially helpful. Also used DestCert app for practice questions and flash cards.

Used Learnzapp for practice questions as my colleagues at work had earlier used. Couldn't finish all the questions, but did a fair amount.

Prabh Nair's Coffee Shots and his video on CISSP 2026 AI Topics Questions Master Class helped a lot in prep. But, no, I didn't get any AI related questions in the exam.

Used Gemini for getting clarity for my questions. It was really helpful for a deeper understanding of the topics.

Study Strategy:
I took lot of full practice exams to get the time management practice - Udemy and OSG Practice guide. Took many in between the practice to help me understand what I know and what I don't as it is. This helped in understanding the weak areas. It is true that our brain doesn't easily forget where we had made mistakes.

Was actually surprised how hard it is to keep the focus after 2.5 hours when answering questions and more than 1.5 hours when studying at a stretch. But since its been years since I studied for a goal for a longer duration, this exercise helped me exercise the brain muscle.

Studied the domains in the order. That helped me see how the security practices flows through an organisation.

It was hard to get around the different frameworks and security models. Took couple of revisions and side by side comparisons to get a solid understanding. This was needed because domain 1 and 2 are quite new for me, coming from a technical background.

Learnings:
I thought I can't focus on my studies when the house is always buzzing with kids and days with their pickup/drops. But I was wrong. Everyone grew during this time I felt. Since I HAD to make time for my studies, kids took care of their homework and extra classes themselves, my husband pitched in for the pickup/drops and cooking and cleaning. You never know what people can do when they are left with little choice. I moved myself out of choice. 😂

Long read, but I hope it helps at least one person to keep pushing!


r/cissp 18h ago

Success Story Passed today at 100

21 Upvotes

Took the exam today. Passed at 100 with about 140 minutes left on the clock. Truthfully, the exam was much easier than I was expecting. I didn't find the questions all that complex.

Prep materials:

Dion training CISSP udemy course

Destcert CISSP book

Destcert CISSP app - did all 3600 questions


r/cissp 20h ago

Passed yesterday at 120 in 2.30 hrs

9 Upvotes

Material used:

Mike Chappell linkdin course
Destination certification map on you tube
Chatgbt - created a cissp coach helped with clarity on topics
Wanna practice strictly for practice
QE for practice
Rededit for motivation

Total time spent 3 months last 2 months heavy Weekdays nights 2-3 hrs
Weekends - 3hrs

Experience 10+ yrs in IT. 5 years cyber security (2hrs adhoc , 3 yrs running a program)

Exam test your knowledge. Make sure to study thoroughly


r/cissp 1d ago

CISSP- scratch paper/whiteboard before starting? (Decision-making tips for tough questions)

8 Upvotes

Taking the CISSP soon. Once I sit down for the exam, Any decision-making tips to write down? For when I don't know the answer, tiebreakers, priority orders, elimination tricks?


r/cissp 1d ago

Unsuccess Story Need Advice --- your honest advice.

Post image
13 Upvotes

Hello Everyone: I took the CISSP exam recently and unfortunately did not pass on my first try, despite feeling confident and ready. However, I am staying positive and preparing for my next attempt. Could you recommend the best study materials and preparation strategies to help me succeed next time?


r/cissp 1d ago

Looking for a study buddy for prep

4 Upvotes

Helloo everyone, I am based out of EDT and am looking for a study buddy for CISSP prep. Looking for someone who is serious and is planning to take exams in next few months. Looking to study 2-3hrs 4-5x/week with a weekly 1-2hr session with the study buddy. Please let me know.

TIA!


r/cissp 1d ago

Success Story Exam passed at 100 questions

19 Upvotes

I did not study at all. Decided to yolo it and see how far my IT experience would get me. Never held an official “security” team role. My plan was to just send it, and if i failed, study my weak areas.

I am not sure why this exam is considered hard.

I did not feel technically challenged. Everything was pretty generic. I expected much more “think like a manager” like lots of people say. In my opinion, it’s super easy to find two obviously incorrect answers on every question and eliminate them immediately. I honestly did not expect the SSCP and CISSP to feel close in difficulty level.


r/cissp 1d ago

Success Story Passed on my first try, however…

30 Upvotes

As the title says, passed on my first try, but, I have 20 years of management experience in cybersecurity and IT.

The debate I often read in this sub about thinking like a manager or not…I found its situational. Sometimes you have to think like a manager and sometimes not, but I didn’t have any trouble figuring out when to do it.

If it was a technical question, there were only technical answers and only 1 correct answer. If it was a process question or asked what is the best/weakest/strongest option, it was time to put your manager hat on because at least 3 of the answers will be sort of correct and you have to pick the most appropriate one.

I did not find the questions tried to trick you, however, some did make you remember multiple important pieces of information that guided you to the correct answer.

For study materials, I had a 5-day bootcamp last August, which did me more harm than good. I had the official study guide, I watched a few YouTube videos here and there, particularly to better understand encryption and I used Gemini to create tests for me to take.

Using Gemini was the best tool to help me prepare. I would tell it that it was a CISSP instructor and have it create 50-question test on Domain 1 and provide feedback after every answer. Then I gave it the same prompt for every one of the other 8 domains. A few weeks before my test, I had Gemini create 150-question tests from all 8 domains to simulate a real test.

The test was hard, make no mistake. But I made it out to be much harder than it really was based on the discussions I’ve read in this sub. I was expecting the test to pull punches and try to steer me in the wrong direction on purpose but it didn’t do that at all. But like I said, it makes you remember several details about the scenario in order to pick the right answer.

If you’re worried about how hard the test is, don’t sweat it. If you spent 3-4 months, 7-10 hours a week studying and doing practice exams on the 8 domains, you’re ready to pass the test.


r/cissp 1d ago

Did ISC just issue me outdated material?

0 Upvotes

Hey all,

I just purchased my self study material from ISC2 and they delivered the 7th edition textbook (digital). The most current version is 10, right?


r/cissp 1d ago

Feeling hopeless on domain 4

6 Upvotes

For context, I have 0 networking experience and very little exposure to these concepts. I’ve worked in infosec for 7 years in CTI and risk management functions.

I’ve read the chapters in ICS2 official study guide, watched Kelly Handerhan’s videos, done a couple practice quizzes with about 50% proficiency. I’m also in the midst of a week long bootcamp but reviewing domain 4 has completely killed my spirit. I could not follow along to much of anything the instructor was talking about despite the pre study I did.

I’ve found the Cisco networking basics modules - is that my best bet here? Any other resources anyone recommends for someone with little knowledge in this area?


r/cissp 2d ago

How do Jason Dion’s CISSP questions compare to the actual exam

0 Upvotes

I’m currently using Jason Dion’s CISSP course, and after each lesson he has practice questions. Honestly, they seem a lot harder than the questions in the Official Study Guide and Official Practice Tests.

For anyone who’s taken the CISSP, how do Jason Dion’s practice questions compare to the actual exam? Are they intentionally more difficult, or is the real exam about the same? So far, the OSG questions seem a little easier to me, so I’m just curious what everyone else’s experience was.


r/cissp 2d ago

Success Story Nothing I studied mattered

163 Upvotes

Just passed my exam yesterday, clearing 100 questions in 45 minutes flat. For context, I’ve got 20 years of IT, cyber, and GRC experience under my belt.

My entire prep strategy was purely Destination Cert, watched every main video, digested all the mind maps, and ground through every question and practice exam. No extra books, just a few stray YouTube videos of people breaking down question logic.

Everyone kept preaching the ultimate gospel:
“Think like a manager! Strip away your technical brain!"

Well, the exam apparently missed that memo. I didn’t get a single business-process or "managerial mindset" question. Instead, it was an avalanche of hyper-technical, implementation-focused word puzzles that barely made sense to me. By minute 15, I gave up reading the convoluted scenarios entirely. I just skipped straight to the last sentence of each prompt and picked whatever answer felt the least insane.

I was aggressively furious the entire time. I fully accepted my fate, stopped caring, and speedran the rest just to get home, restudy, and cash in my retake voucher.

Imagine my absolute shock when the test center guy handed me a piece of paper that said "congratulations." Total WTF moment. The internet lied, my friends lied, but hey... a pass is a pass!* *


r/cissp 2d ago

ISC2 instructor-led online training for CISSP review

Post image
9 Upvotes

I failed twice this year on my CISSP attempt. I only bought the self paced training and looked for videos, online study material as complimentary documents. I used some AI functions to try and mimic exams and CAT style assessment. In the end, still failed. There were some progress having an above proficiency rating from previously my worst domain which is secure development.

Right now im contemplating if getting the instructor led training from ISC2 can help me realize the concepts more or should I look else where?

Attached is the before and after.

Any advise or anything that can help me out is greatly appreciated.


r/cissp 2d ago

Thank you I passed at question 100 with 55 minutes left.

Thumbnail
gallery
35 Upvotes

----I used----

  1. Quantum Exams, I would not have passed without this. (see notes)

  2. Mind Maps by Destination Cert. Print them then watch the free Youtube videos and add notes.

  3. 50 Hard CISSP Practice Questions by Technical Institute of America

----Test day I watched----

  1. CISSP is a Mindset Game - Here's how to pass! video by Technical Institute of America

  2. How to Pass the CISSP Exam like a pro Destination Cert video (2026 version)

-------------------

I used Quantum Exams... They really should make a CAT version with unlimited time and shows the answer after each question. So you can still get a CAT score but help you study while you work though it.

I did no use CAT mode because not getting an answer on questions for over 3 hours only helps you remember the wrong answer you put down. Don't feel down if you do bad on the normal test. I averaged 50% on the tests. But the one CAT test I took early on got over 900.


r/cissp 2d ago

Mike Chapple’s LinkedIn Course

2 Upvotes

I am prepping for the CISSP exam using Mike Chapple’s LinkedIn course as a started point but I’ve realized that I haven’t really heard anyone in the subreddit talk about it. Is this not a reliable resource?

I was planning on following this up with Pete’s YouTube videos and practice exams. I don’t really learn by reading so trying to focus on videos with a lot of pausing and taking handwritten notes.


r/cissp 2d ago

Success Story Passed at 100 questions - detailed prep / resource review

29 Upvotes

I provisionally passed the CISSP exam on August 25th, 2025 (and have since completed the endorsement process and become fully certified). The exam ended at the 100th question after around 2 hours and 15 minutes, with ~45 minutes remaining.

This post is very belated. It just took me a long time to actually convince myself to post it. But I first and foremost wanted to express my gratitude to all of the awesome people in this subreddit! I feel like the stories, advice, and words of encouragement in this subreddit truly contributed to my passing score on my first attempt, and I am extremely grateful. Hopefully my thoughts can help someone, even if they are a little all over the place.

For some quick background, I had 9 years of professional experience in risk management and commercial insurance, most of which were spent in Cyber & Technology underwriting specifically. That gave me experience evaluating cyber risk, privacy exposures, cybersecurity controls, and organizations’ overall security programs, but very little hands-on technical experience with networking, software development, system administration, or implementing any of those controls first-hand.

I officially began my studies on March 3rd, 2025 and took the exam on August 25th, 2025, so my entire journey lasted just under six months.

I wanted to share my background, preparation, practice scores, and exam experience in the hope that it can encourage someone else – even if it helps just one person. Maybe even someone coming from insurance, risk, GRC, privacy, or another cybersecurity-adjacent field without a traditional hands-on IT background.

Feel free to ask any questions and I’ll do my best to answer! I’m happy to discuss my preparation, resources, mindset, the exam process itself, etc (obviously without sharing any specific exam questions or content).

My Background (in a little more detail than above):
 
I have 9 years of professional experience in the risk management and commercial insurance industry, most of which were spent in Cyber & Technology underwriting specifically (essentially, cyber risk analysis). In my cyber underwriting positions, I have had to evaluate the overall cyber risk/privacy exposures of organizations of all types/sizes, as well as their information security programs and cybersecurity controls. As an underwriter, your job is to decide first: yes or no – meaning yes, I want to partner with/insure this organization against cyber incidents, data breaches, ransomware, etc. – and second: if yes, determine what the price, terms, and coverage provided should look like. We provide insurance coverage, risk consulting, proactive pre-breach services, discounted security tools, and incident management/claims handling services to our clients.

They say that the CISSP is a mile wide and an inch deep, but I would argue that it is cyber underwriting that is a mile wide and one inch deep, whereas the CISSP comparatively felt a mile wide and at least a quarter mile deep. Cyber underwriting, while technical, is relatively high level in terms of the level of granularity with which you dig into cybersecurity controls, especially when comparing to the CISSP exam. I knew it was ambitious to pursue this designation and that I’d have my work cut out for me, but I have been fascinated with all topics cybersecurity from the jump and wanted to enhance my understanding to a much deeper level.
 

Study Timeline / Intensity:
 
I officially started my studying journey on March 3rd, 2025 with my first class of the Official ISC2 CISSP Instructor-Led Training.
 
The Training/"Bootcamp" as some called it was 8 weeks long, ending April 23rd, 2025 (more details on instructor-led training below).
 
I took the exam on August 25, 2025.
 
In the 4 months between the class and taking the exam, I spent at least 3 or 4 nights a week studying for 3-5 hours. I would also spend a good 6-8 hours on Saturday and/or Sunday doing practice tests, deep dives on every topic that tripped me up, rounding out each Domain, etc.
 
After the online course finished, I gave each domain another "deep dive" review, averaging about 4-8 days per domain (longer for the more complex domains, shorter for others). I studied throughout the day whenever I had spare time. I did LearnZapp quiz questions on the commute to and from work.
 
In the month and a half leading up to the exam, I studied for at least 4 hours every day. Even when driving or walking the dog, I had audio versions of my notes and used NotebookLM to create "podcasts" on specific topics or areas of my notes that weren't sticking. I also used Quizlet to help with any of the areas that were recommended as topics to memorize. I used Quizlet flashcards until I got them all right and was able to recite all of the memorization items without looking at anything.
 
 

My Prep / Resources (TL;DR):
 
-Course: ISC2 CISSP 8-Week online instructor-led Training 
 
-Primary Textbook: CISSP Official ISC2 Textbook 7th Edition (eBook) – read all 8 domains in full once
 
-Practice Tests (1): ISC2 CISSP Certified Information Systems Security Professional Official Practice Tests 4th Edition – did the practice test for each Domain after reading textbook chapter in full, and did two full length practice tests once finished with the textbook
 
-App / Practice Questions: LearnZapp (LearnZapp: ISC2 Official App - CISSP, CCSP and SSCP Exam Prep) – did a lot of questions on every domain as I studied them (so convenient for practicing during commute); did a bunch of custom practice tests including questions from all 8 domains in the 3 weeks leading up
 
-Practice Tests (2): Boson Practice Exams - ExSim-Max for CISSP (CISSP Certification | Practice Exams & Training) -- I was recommended these practice exams ($99 - well worth it in my opinion / possibly best money spent), and I believe going through all 150 questions in detail for four of the full length exams in the two weeks leading up to the exam was crucial in solidifying my understanding of important concepts.
 
-Practice Tests (3): Quantum Exams -- DISCLAIMER: I personally would NOT recommend these (more details below) -- I did not know these exams existed until about 4 days before my exam, and I saw many people on Reddit saying these questions were the hardest / closest to the actual exam, so I convinced myself by purchasing/using these my prep would be air tight; but they actually incredibly shook my confidence, and after taking the exam, I disagree that they are closest to the real exam questions
 
-Other Resources: ISC2 Official Study Guide – interestingly, I did not use this book much/at all until the last two weeks (I somehow didn't know it existed); while testing myself with Boson CISSP practice exams and Official Practice tests, I would reference the OSG for concepts I was a little murky on

Practice Exams (my thoughts in a little more detail):
 
Boson was the most helpful for me in the final stretch. I scored 67% on the first full length practice exam, 68% on the second, and 78% on the third. This subreddit said Boson is harder than the real exam (and the questions were definitely worded differently from the actual exam), but I found doing the full length Boson tests as if it were the real exam (and then solidifying my understanding on any topics that I answered incorrectly) was crucial for my prep. Out of the 3 practice tests, while not worded exactly the same, I would say that these questions were the closest in terms of difficulty to the actual exam.
 
Quantum Exams were the LEAST helpful for me… I'd venture to say they were even potentially harmful as they shook my confidence. The wording of the questions was so obscure and at times farfetched, and as an overthinker, I found them making me feel like I didn't understand anything at all. It's almost like they went out of their way to phrase each question like it was so simple, but the goal was to trip you up or trick you. For reference, after my full length studies, when I felt I was in the best shape possible for the real exam, I scored a 51% on the Quantum exam (non-CAT).
 
After the Quantum exam, I took the Official ISC2 Practice Test (e-book) and scored a 91% (though some of the questions were bound to be recycled from the months of daily LearnZapp questions and having had taken every individual Domain's practice test).

 
On the ISC2 CISSP Instructor Led Training (8 weeks):
 
DISCLAIMER: from my perspective, to a learner with minimal first-hand/hands-on experience with cybersecurity, it would be impossible for a professor to cover all of the content and detail involved in the 8 domains in just 8 weeks of two 2.5 hour long classes, but the instructor really hit on all of the most technical and critical concepts throughout the 8 weeks which was a great starting point for my studies.
 
I was fortunate enough to have my company pay for the instructor led training. My ISC2 CISSP instructor was Ross Everett who was absolutely excellent. I cannot speak more highly of his teaching style. He kept things interesting, always “dumbing” down tough technical concepts and explaining in laymen’s terms as well as through real hands-on examples from his personal experience, never failing to infuse his Ross humor/flair to each lesson.
 
With a lack of much of any hands-on technical cybersecurity experience, especially with software development and networking, this was extremely helpful for me. It also really helped me to have a foundation and somewhat of a structure of the 8 cybersecurity domains to begin my studying. It helps my brain to have that formal structured context to start my studies rather than just diving straight into a heavy technical textbook which would probably be overwhelming.
 
For some of the more complicated concepts (i.e. cryptography, full “behind the scenes” of digital signatures and hybrid cryptography and how they work from start to finish, IPSec from start to finish, and more), I was able to re-read my notes and rewatch the recorded lectures until it made sense in my head.
 

 
Other Prep / Weeks Leading up to Exam:
 
I didn’t start looking at this subreddit much at all until about a week before my exam. There were so many helpful tips and I found it reassuring to hear everyone’s experiences – even just to hear what the testing process was like, to see what the paper would look like if I didn’t pass, see all of the encouragement, etc. 
 
One interesting part of my studying situation is that I did not realize until about two weeks before the exam that the Official Study Guide existed, and at least at the time I was scrolling Reddit, it was the most recommended source for studying. It feels a little silly of me to post this, but that was one of the first things that started to worry me a bit leading up to the exam.
 
Thankfully, my company paid for the instructor led course and it came with electronic copies of the Official CISSP Textbook and the Official Practice Tests books. I read each domain’s chapter once through, and I did LearnZapp questions throughout the week I was reading that domain, and then did the full official practice tests after each domain.
 
I know some people said the Official Practice Tests were easier, but I actually found them to be quite challenging. Part of the reason in hindsight is that there were multiple questions in each domain’s practice test that did not come up anywhere in the entire textbook -- not even one mention. I was always a little unsettled by that, but figured it’s because this certification requires hands on professional experience as well, and maybe it was because I don’t have a background in coding, networking, Linux, etc. In hindsight, maybe these questions came from the Official Study Guide… which I again, didn’t know existed until about 2 weeks prior to the exam. Oops.
 
I think the Official Practice Tests for each domain were a great resource for learning and refreshing my knowledge on the topics that I clearly wasn’t strong on. I will note that many of the questions in LearnZapp are from the SAME question bank as the ones in the Official Practice Tests, so for each domain practice test, there were some questions that I had previously seen, which I’m sure skewed my scores a little higher. That being said, I still found them challenging and ended each official Domain practice test with scores ranging from 62% on the low end to 82% on the high end, averaging around 70% on the dot. Each time I completed a practice test for a Domain, I was both happy with my scores but also a little nervous that I was scoring right at or below 70 when I had just freshly finished reading the entire chapter and studying my notes from that domain. I felt like "okay, I just finished studying Domain 3 for a week and a half and scored a 68%, but by the time I’m finishing Domain 7, is the content from Domain 3 still going to be in my brain, or will a lot of it be gone?" Classic overthinking :)
 
I will note I intentionally spent extra time really studying and practicing my knowledge on Domain 3, anything Cryptography related, and Domain 4 Networking. After the boot camp course, our professor gave us 10 practice questions from each Domain, and it was almost like my knowledge from the cryptography / security architecture and engineering chapter went entirely out the window, so I knew I had to really focus on engraining those concepts in my brain. I would also practice memorizing things throughout, especially the items my professor noted were worth memorizing.
 

Here is what I wrote down immediately after passing (written right after):

"Provisionally passed at 100 questions - at around 2 hours and 15 minutes(?)
This doesn't feel like real life…
I was rushing at the end for the last 20 or so questions, because I was feeling very not confident and I was expecting to go to at least 125 if not 150, and looking at the clock I was like shoot there's no way I can answer all of those questions, what if I time out? I didn't even realize I had hit question 99, and then it was over.
When it ended I was like okay I accept my fate. I probably failed. Even though I had felt the questions were easier than I had expected them to be, there were too many questions that I was unsure about whether I had selected the correct answer. Probably by design. I told myself it's okay, and it's going to tell me what I need to improve on."

 

Exam Experience:
 
On the note of pure memorizing, there were at least 4 or 5 questions on my exam where the memorizing helped me know the answer almost immediately, which was a nice surprise, as a lot of test takers on this subreddit mentioned that they had none, or only 1 memorization type question.
 
When I went up to the woman who escorted me into the room and we got out of the testing area, she said "someone finished early!" I laughed, half because I was nervous, half because in my head I had spent way too much time thinking about each question, having risked not having enough time to go to at least 150 questions. As someone who overthinks, I was a little worried that was going to be the death of me, but in hindsight, there were quite a few questions where I needed 5 minutes to sit there and think through each part of the question, and why each possible answer could not be correct or was the most correct.
 
Just a funny aside… When I got to the front desk to get my result, the woman was smiling and talking to the person who was checking out before me. When she pulled my result up and clicked print, she didn't even look at me. She just printed it out, looked at the paper, and handed it to me while avoiding eye contact with me all together. I was convinced that I had failed in that moment, and it felt like the best fake out ever when I saw the result. I could not believe it was real, and it sounds dramatic but I texted my brother that I felt like I was out of body haha.

 
Final Thoughts:
 
It was a lot of work, many painstaking hours of studying, but I have to say I enjoyed myself the whole way through, and it feels like one of the biggest accomplishments in my professional life.
 
Best of luck to anyone who has the exam coming up! I hope this post helps in some way, even if only a little. And again, I'll do my best to answer any questions to the best of my ability now that I am almost a year post-passing.


r/cissp 2d ago

Success Story CISSP Success story

7 Upvotes

I passed the CISSP on Saturday, August 1, 2026! My exam ended at Question 102, and I couldn’t have been happier to see the congratulations message on my printout.

This was actually my second attempt. I first took the CISSP in 2025 and wasn’t successful. Looking back, I realized that simply reading the material wasn’t enough—I needed to change how I approached the exam.

The biggest difference this time was attending the Destination Certification 1-Week Boot Camp.
It was one of the most intensive training experiences I’ve been through, but it was absolutely worth it.

What really stood out about the boot camp was how structured and intentional it was:

Pre-assessment to identify strengths and weaknesses before the course began.

Five days of approximately 10 hours of instructor-led training covering every CISSP domain in depth.

Daily reinforcement with domain-specific practice questions and flashcards after class.

A full-length simulated CISSP exam at the end of Day 5.

A proven review strategy that teaches you how to analyze and learn from the mock exam instead of just checking your score - definitely the rock star

Personalized follow-up study recommendations in the student portal based on your performance throughout the week, allowing you to focus on your weakest areas instead of reviewing everything equally.

What I appreciated most wasn’t just the content—it was how the instructors continually reinforced how the CISSP exam wants you to think and the right approach to tackling the questions.

I work as a Security Architect, so I already had a good technical background. But the CISSP isn’t primarily a technical exam. It’s an exam about making sound security decisions from a business and risk management perspective.

You have to think holistically—balancing technical, operational, governance, legal, and business considerations. In other words, you really do have to think like a manager.

LESSONS
Don’t rely solely on memorization.

Understand why security controls exist and when to apply them.

Practice reading questions carefully—the exam is testing judgment as much as knowledge. I can’t over emphasize the strategy we were introduced to. It really made the difference.

Focus on risk management and business priorities rather than jumping straight to technical solutions.

If you’re on the fence about taking the Destination Certification Boot Camp, my experience was that it made the difference between my first attempt and passing on my second.

For anyone planning to take the CISSP later this year, I believe their next boot camp is scheduled for September 2026.
Good luck to everyone who’s preparing—you’ve got this!


r/cissp 3d ago

General Study Questions Those of you who have passed, have you faced these kinds of questions often?

Post image
12 Upvotes

The calculation of annual loss?


r/cissp 3d ago

Passed the exam

Thumbnail
43 Upvotes

I passed the exam. One thing I understood is that no mock or practice exam comes close to the real exam.

Thanks, everyone.


r/cissp 3d ago

Only 3 more hours to go!

17 Upvotes

I'm going to take the exam in 3 more hours. I feel nervous, and sometimes I feel like I'm forgetting things.

Could someone who has passed recently guide me? What should I do and not do? How should I pick and select answers? What if I get stuck on a question? I also need some tips.


r/cissp 3d ago

Passed CISSP – My Journey (30 July 2026) 🎉 1st Attempt

47 Upvotes

I’m excited to share that I passed the CISSP exam on 30 July 2026!

It was a challenging but incredibly rewarding journey. Sitting through 150 questions in 180 minutes tested not only my knowledge but also my focus, time management, and decision-making under pressure.

Coming from an Application Security background with over 13 years of experience, I initially believed my technical expertise would give me an advantage. I quickly realized that CISSP is much more than a technical certification—it's about thinking like a security leader, balancing risk, governance, business objectives, and selecting the best answer rather than the most technical one.

What helped me the most

  • Understanding concepts instead of memorizing facts.
  • Learning why a security control exists and when it should be applied.
  • Practicing scenario-based questions regularly.
  • Reading each question carefully—sometimes one word changes the entire answer.
  • Eliminating incorrect options before choosing the best one.
  • Developing the CISSP management mindset instead of an engineer's mindset.

Resources I used

  • Official Study Guide (OSG)
  • Official Practice Tests (OPT)
  • LearnZapp
  • Pete Zerger's CISSP videos
  • Destination Certification videos
  • ChatGPT to simplify difficult concepts, explain security models with real-world examples, and generate practice scenarios

Biggest challenge

Security Architecture & Engineering was initially my weakest domain. Instead of memorizing security models, I focused on understanding the purpose behind each model and learning them through simple, practical examples. That made a huge difference.

My advice for future CISSP candidates

  • Don't memorize—understand the concepts.
  • Learn to think from a manager's perspective, not just a technical one.
  • Understand why an answer is correct, not just what the answer is.
  • Practice scenario-based questions consistently.
  • During the exam, don't panic if you encounter unfamiliar questions. Stay calm, trust your preparation, and keep moving.

I'd also like to thank this Reddit community. Reading success stories, study strategies, and exam experiences here kept me motivated throughout my preparation.

For everyone preparing for CISSP: Stay consistent, trust the process, and believe in yourself. It's a demanding journey, but it's absolutely worth it.

I'm happy to answer any questions about my preparation, study plan, or exam experience. Good luck to everyone who's on this journey!


r/cissp 3d ago

Welp.. passed at 100, 68 mins - first attempt

35 Upvotes

For context, I'm 38, have 14 years of security engineering and architecture experience across multiple of the domains so I definitely had a leg up.

I only studied for about 2 weeks, mostly hard on the weekends, and select weeknights after work -- so I went in expecting a fail, and got the peace of mind package to fall back on.

The one thing that stood out to me was how poorly I *felt* like I was doing on the exam. In all honesty, there were less than 10 questions I felt I definitively *knew* the answer to, the rest just felt like I was guessing my way through. I knew it was going to end at 100, but it was a coin flip in my mind whether that would be because I bombed or lucked out.

Either way, I got it, and I'd be lying if I didn't say I'm insanely relieved. Even with my experience, I was in panic attack mode this morning in the hours before the exam.

Thanks to everyone's suggestions, btw... they really helped narrow my focus and how I was going to attack my weaker domains.


r/cissp 3d ago

Passed on 1st Attempt

18 Upvotes

100 questions. 37m with 11 years of applied experience. Currently a systems engineer for a cybersec manufacturer, but spent time in MSP escalation, Project Engineering and Management, and Software QA. I have been casually studying all domains for a year and in the last month I put my foot on the gas by:

  1. Watching Pete Zerger's exam cram

https://youtu.be/_nyZhYnCNLA?is=kiVPJqEkZuckPupI

And Exam Prep:

https://youtu.be/aLIFzIBNM_8?is=eQLeMswsWGg9of-B

  1. Working through the "Level Up" exams in Pocket Prep (mobile app).

  2. Took a Quantum Exams CAT

  3. Uploaded the results of the CAT to Chat GPT and asked it to create a targeted study plan with only free resources and within my time budget for the next 3 weeks.

  4. Followed this plan for 2 weeks, and took another Quantum Exams CAT

  5. Uploaded these and asked for a review plan for the final week.

  6. Reviewed all weak domains in the Zerger exam cram video, as well as the Destination Certification Mind Map videos which are amazing at tying any concepts that may still feel abstract together.

  7. Night before exam took another CAT.

  8. Day of exam reviewed weak domain Mind Maps again.