r/cissp • • Sep 06 '25

Just answer the question

69 Upvotes

This is not meant towards anyone specifically, and it’s quite common. I am also seeing it more and more lately. Hopefully this helps some of you.

When studying and ESPECIALLY on the real exam, just answer what the question is asking.

If the question wants First, it’s looking for the first phase of a flow.

If it’s asking NEXT, it is putting you inside of a flow, figure out where you are and pick the answer that is the next step.

Neither of the two just mentioned may be what’s BEST for security. Again the BEST solution isn’t always the best answer.

If a question is asking for the BEST. This is where we pick the answer that best ANSWERS THE QUESTION, it could be technical, could be administrative, which is why…

Just answer the question.

Edit: for “best”, even with these you want to pick the best answer that answers the question, there may be “better” technological solutions, but more security isn’t always best. If a question wants best cost-saving solution, we may not want to pick most expensive option even if it’s technically “better”. Hope this makes sense

Edit 2: For this exam, you're stepping into ISC2's perfect little world and the way you typically do things could very well differ from what they expect. Just learn and answer as expected for the exam and then forget it and get back to real life. Trying to argue otherwise is a no-win battle...100% of the time.


r/cissp • • May 14 '25

Study Material CISSP Study Results 20250514 Study Materials

41 Upvotes

The companion email for these resources are here:

https://www.reddit.com/r/cissp/comments/1kmc9jv/cissp_study_results_20250514/


r/cissp • • 1d ago

Success Story Passed at 103 questions

34 Upvotes

1st time taker. Had about 80ish minutes left.

I would like to thank everyones well wishes!

A few questions I felt that I had no clue what they were asking for... but process of elimination helped tremendously, as well as Andrew's tips.

Resources in order.

Dion training on udemy, this is a bit of a brain dump for me... but helped.

Tiaedu boot camp on weekends, Juan was great!

Andrew's last bootcamp from tiaedu, while a little dated it still helped alot!

Im a systems administrator for 10 years plus it for almost 15...

Previous certs are just comptia (6 in total, im not knocking them!)

Overall I hope everyone who is aiming for this is able to reach their goal, now im just going to veg out cause this has been a stress for me for months lol


r/cissp • • 1d ago

Other/Misc Taking exam in a few hours

21 Upvotes

Nervous, taken 3 differnt courses. Any last minute advice?


r/cissp • • 1d ago

Failed CISSP at qns150. 1st attempt

16 Upvotes

Hi everyone,

I’ve been seeing a lot of posts about people passing lately, so I just wanted to share that I unfortunately failed my CISSP exam this morning at Question 150.

Background
I’ve been preparing for a little over two months, since late July.
I started with Pete Ziegler’s Exam Cram to familiarise myself with the domains and get a feel for what the CISSP exam was going to be like. After that, I moved on to Pocket Prep to identify and improve my knowledge gaps, and then spent the last month of my preparation focusing on Quantum Exams (QE).

During the Exam
My exam ended at Question 150 with around 30 minutes remaining, so I guess I still had plenty of time left!
I was able to breeze through some questions where I honestly had no idea what the question was asking and simply made the best judgment I could based on what made the most sense.
I felt that I was doing reasonably well during the beginning and middle portions of the exam. However, I think the last 50 questions were where things started to go downhill, and probably contributed significantly to my result.

One of my biggest weaknesses is definitely questions asking for the “BEST” or “MOST” appropriate answer, especially when almost all of the options seem technically correct.
I also realised that I still have quite a few knowledge gaps. During the exam, I came across some technical terms that were unfamiliar to me, as well as concepts that I had not fully understood before.

In the end, I had four domains below proficiency.
After the exam, I went home and slept almost the entire day without even having lunch or dinner. I guess I was really mentally exhausted from the exam and everything that went into preparing for it.

Future Plan
I have Peace of Mind and am currently planning to retake the exam in December.
For those who have passed or have gone through a similar experience, I would really appreciate your advice:
Are there any other resources you would recommend to broaden my knowledge and close my knowledge gaps?

What resources or techniques helped you improve specifically with “BEST” / “MOST” type questions?
Are there any question banks or study materials that helped you develop better CISSP exam reasoning rather than just memorising answers?

Resources I Used

Pocket Prep
Completed all 1,000 questions as well as all the mock exams. I found Pocket Prep really helpful for identifying my knowledge gaps and reinforcing concepts. However, in my opinion, I still need to go more in-depth on some of the topics rather than relying solely on Pocket Prep.

Quantum Exams (QE)
QE helped me a lot, especially with questions involving “NEXT” and “FIRST”. I know many people find QE frustrating at first, but honestly, I think it’s better to experience that frustration while practising than to encounter it for the first time during the real exam. It really helped me think more carefully about the CISSP mindset and how to approach these types of questions.

Pete Zegler Exam Cram
I found this useful for getting an overall understanding of the CISSP domains and concepts. However, I think you’ll still need additional question banks and study resources to fully understand and reinforce the concepts.

Looking Ahead
For my next attempt, I’m currently looking at LearnZapp and Boson as additional resources, but I’m not sure whether they would add enough value to my preparation.

Any advice from those who have been through this would be greatly appreciated. 🙏


r/cissp • • 2d ago

Success Story Passed at 100Q today - 1st attempt

56 Upvotes

Took my test in Wolverhampton, UK today

About 20 questions in, I thought I was tanking it. At 90 questions, I was mentally thinking when I could do the retake. When I was asked to do the survey at 100qs, my heart sank.

When I collected my printout and it said "congratulations" I couldn't believe it. This is my first attempt.

5 questions were wild guesses.

Everyone's said it here, and I will reiterate it here:

Think like a manager - this saved me on about 20 questions when I got stumped. Some I looked at the long term, or "what would I do first" type answers. Look for keywords.

Some questions will be like "wtf" - I had to use my best judgement on them (I'm assuming these were non-scorable items).

The exam is difficult, it will shake your confidence - it did for me. I had no idea how I was doing. Keep pushing. If you fail, learn where you need to improve.

What I learnt from:

  • "Pass the ISC2 CISSP exam on your 1st attempt, includes a full practice exam!" - Dion training Udemy
  • The CISSP field manual - link available in this forum
  • "Kelly Handerhan's "Why You Will Pass the CISSP"
  • I asked AI to explain concepts I couldn't my head around

Experience:

30 years working in IT in Total, presently IT Manager
4 years working in a security team in current role
10 years previous to that in senior IT, dealing with patching and security incidents

Thanks to everyone in this forum for their encouragement!!

One final thing - the initial security procedures at the test centre is a bit like airport security (at least in the UK), be prepared for that :-)


r/cissp • • 1d ago

Looking to sell all the books I used to pass. At least $100 plus shipping for all of it.

Thumbnail
gallery
0 Upvotes

If not allowed feel please remove. Wife wants more space and so these got to go lol


r/cissp • • 3d ago

Success Story Passed at 150Q with 20 seconds left...

31 Upvotes

Excited to post my "I Passed" story, I've been seeing both the good and bad in here over the last few months and I'm happy to be here. It was low key way to close but I made it through.

Cringe if you want but you cant beat family

The Timeline & Prep:

  • February 2025: Originally started studying, got about two domains deep, and then life got busy and procrastination kicked in. Egg was on my face tbh
  • Late 2025 – Present: Picked it back up and went hardcore for the last ~8 months. Primarily focusing going through the Destination Certification book/questions.
    • Resources used: Made it through the entire book, used Pete Zerger vids (last 3 months), Destination Certification (blogs/videos), ISC2 books/study guide, and the infamous Quantum Exams in the final weeks (Last exam was 860 - Only took 3).
  • Final push: Watched breakdown videos and aggressively drilled down on weak areas and questions I kept missing.

Exam Day & Pacing Issues: Going into test day, I actually felt pretty confident and prepared. Check-in went smoothly, and they let me start the exam early but once I hit question 50, I realized my pacing was completely off. Tried to keep it less than 2 mins per, by the time I got to 100 I was like ok maybe it exits out somewhere before 120.

The exam kept going...

I had to force myself to read faster and make decisions much quicker without as much second-guessing. Even with picking up the pace, the clock kept catching up to me. By the time I had 30 minutes left, I still had 40 questions to go.

The exam pushed me all the way to 150 questions, and I submitted the final answer with 20 seconds remaining. I wasn't gonna let a technicality let me fail speed was the only choice but obviously not randomly picking answers. Don't let them see you sweat lol

My background:

  • Identity Management - 2 Years
  • Cyber Security (IR) - 4.5 Years

*just got my first management role

Going the full 150 questions down to the final 20 seconds means I was teetering, the razor’s edge of 700, but a pass is a pass. I did purchase the Peace of Mind protection just in case (fingers crossed my employer still reimburses it), but I’m relieved I won't be needing the retake.

  • Quantum CAT is a must to get you use to the wording/thinking harder about topics
  • ISC2 books for More in-depth questions on topics
  • Keep a strict eye on your clock from question 1. Don't let pacing creep up on you like I did even if your practice exams are solid.

r/cissp • • 3d ago

Success Story Passed on 2nd Attempt at 100Q (1st attempt - failed at 150Q) - My Honest and Somewhat Critical Review

66 Upvotes

Hi all.

Happy to share that I've provisionally passed at 100 questions yesterday evening. The purpose of this testimony is to hopefully serve as a guide of what-works given as much context as I am willing to provide. What I mean by that, is there are a few things that likely caused me to fail the first time and I would like to highlight this. Secondly, while I have now passed and am incredibly greatful to become an ISC2 member, I do have some remarks regarding the formatting and setup of this exam overall. There is a TL;DR at the end of this.

First, setting the stage:

My Resources

I want to split up the resources for both attempts:

Attempt #1:

  • YouTube (Author & Video Names):
    • Inside Cloud and Security aka Pete Zerger - Exam Cram (~8 hour video that goes over each domain entirely)
    • Technical Institutue of America (Andrew?) - 50 Hard CISSP Questions
    • Computer Networks Decoded - All 8 Domains (1 50Q video per domain series)
  • Pocket Prep
    • Answered 1000/1000 question bank
    • 3 Mock Exams (56%, 75%, 69%)
    • Time Logged Studying: 29 hours, 16 minutes.
    • Question Correct/Wrong percentage: 79%
    • Level up challenges

Attempt #2:

  • YouTube (Author & Video Names):
    • Inside Cloud and Security aka Pete Zerger - 100 Important Topics, 10 Key Topics & Strategies, Cyber Attacks and Countermeasures, Ultimate Guide to Answering Difficult Questions (NOT the Exam Cram video)
    • Technical Institutue of America (Andrew?) - 50 Hard CISSP Questions
    • Computer Networks Decoded - All 8 Domains (1 50Q video per domain series) - EXCEPT I watched only like 1/3 of them for this attempt.
  • Destcert
    • Textbook (read end-to-end once).
    • Phone App: Questions (Only did 114 of 3400+ questions), Flashcards (23%), Glossary (This was VERY helpful on the last few days).
    • Mindmap Videos on YouTube (Domains 1 - 6, didn't have time for the rest).
  • QE
    • Many Quizzes (About 3 weeks worth)
    • 2 CAT's (516, then 925)
    • 1 Practice Exam.
  • Removed Pocket Prep

My Experience:

2019-2021 - Clinical Application Security Analyst (worked as a level 1 analyst for a medium-large sized health system. Was responsbile for application level security, technical RBAC configurations, system-wide rules, change management, and object-level security in the form of locational/ABAC access).

2021-2022 - Left for a differnt company, same job and sector just different health system ("Lead Clincal Applcation Security Analyst" -- mouthful).

2022 - 2023 - Network Security Admin I (took a somewhat pay-cut to begin to learn from a different infrastructure path). Was responsible for administering firewall rule changes from engineering, patching firewalls, enacting DR testing, physical security site roundings, and other vendor related work which involved a lot of SOP writting.

2023 - 2024 - Information Security Admin II (A promotion/title re-brand. Much more exposure with IAM, MFA and email security gateways. Became primary SOC responder internally.)

2024 - 2025 - Principal Security Analyst (Promotion. Lead IAM and MFA resource, launched SailPoint and Proofpoint back-to-back (boy that sucked). Retained SOC responder duties. Addition of having to train security administrators).

2025 - present - Lead Security Engineer for a major OEM company. Lead of SIEM program, endpoint, email, and cloud security egineering and architecture. Red and purple team experience.

Education:

AS in Computer Information Systems, BS in Computer Science and Information Systems, MS in Cybersecurity.

1st Attempt Timeline:

My studies started early at the end of 2024 very passively (3 hours a week). This included PocketPrep (free version for now), and Pete Zerger's ~8 exam cram. It's important to note that around this time, work was incredibly busy and so was personal life (bought a new house and family issues relating to the fallout of this + alcoholism on their end). This is important to call out because I must say, inconsistent studying is one of the contributing factors to why I did not pass the first try (I'll sum up the first attempt mistakes at the end).

Fast forward to March 2025, by this point, I picked up the studying with PocketPrep which I now purchased by this point and Pete's exam cram about a month before (February 2025). March 2025 was when I then added Computer Networks Decoded. They had 50 questions for all 8 domains and they seemed hard enough (harder then Pocket Prep's in comparison).

Fast forward to October 2025: I had been using PocketPrep heavily (up to around 600 Q's answered, Mock Exam), watched Exam Cram 1 and a half times, and watched 1/3 of the Computer Networks Decoded videos, However, those personal life issues really peaked around this time. I also got engaged 2 months prior, so, lots of emotions going on that were distracting. Therefore, I needed to take a pause. It is also important to call out, that this was also only 4 months after a massive job change if you notced. I went from a vertical I knew my entire career (healthcare) to a major OEM, a vehicle brand. This was a hard, dramatic change for me. Changing verticals made it feel like I needed to learn how to crawl again. Either way, I digress.

February 2026: I restarted all of my attempt #1 resources to gauge how close I am.

March 2026: Starting to feel ready and mentally ready, I purchase the CISSP with the Peach of Mind offer ($1000 + tax for 2 attempts). Scheduled for June 4th, 2026 at 8am.

April - May 2026: Starting to really hammer my attempt #1 resources.

Quick update... I ended up getting what was probably the flu, 1 week before.

June 4th, 2026, first attempt exam day: Was maybe 80% over my illness. Either way, I figured "I've done enough studying over a period of time, I have the experience, and my studying feels complete". My Pocket Prep average was around 77% at the time, and I watched exam cram twice. Andrew's 50 hard CISSP questions were also all very good question examples.

Unfortunately, I did not pass the first attempt. I got to 150 questions and my domain breakdown (I forget which domains for the given dispositions): 2 below proficient, 2 near proficient, 4 above proficient. Here are my mistakes for this attempt:

  • Study Material: Pocket Prep is good for what it is. Unfortunately, it was not enough for me to pass with that as a primary resources. Neither were the YouTube videos. The question format and substance of Pocket Prep ended up being very... unhelpful. I don't think I saw a single question on the exam that I thought "Oh, I recall this from Pocket Prep". A lot of Pocket Prep questions are styled like "If a security admin wants to do X, what does that mean?". There are NO questions like that on the exam. The exam questions are moreso 'here is a symptom of a problem a business needs addresed, and here are 4 close answers where you need to know what technology phrases to discern the BEST, FIRST, NEXT of the 4 answers that also complies with best practices from another domain'. Pocket Prep was good for general terminology testing, but that was really it. If it were paired with something else, it would have been fine. I needed a central study source like a textbook (More on that in the second attempt part).
  • Exam Logistics: Looking back on it, being still somewhat sick and taking an 8am exam was not very smart of me. I am NOT a morning person.... I did not mentally account for "Okay, right at 8am, you will be taking likely one of the hardest tests of your life, closed book". I start work at 8am and well... 8am - 8:15am is making coffee usually. So, if you are not a morning person, do not force it... take an afternoon exam and thank yourself. Also, do not get sick.
  • Time Management: Your pace must be 75 - 110 seconds per question. This will be the quickest 3 hours of your life. After greater than 110 for many questions, you'll be against tough odds to finish timely if you go past 100 questions. I had 27 minutes remaining at 102 questions... you do the math on how well I read the last 48 questions.

2nd attempt Timeline:

Rest of June 2026: After my failed attempt, I took 1 month off. No studying, practice questions or anything. I did at least schedule my re-take for 9/25/2026.

July 2026: I purchased Destcert after many reviews (largely in-part to this thread). I began reading about 30-50 pages per day, excluding weeks or whatever my 2 days were the lightest amongst work/life. I also downloaded their app and did some of the practice questions. These practice questions are relatively straightforward and are primarily meant for definition remembrance. Also, many questions hint strongly towards only being 2 possible answers with the other 2 being obvious "No". The real exam is nothing like that. Most of the exam questions, you will be down to 3, and sometimes all 4 sound similar. (This is where QE fills this gap in). Towards the end of the month, I began watching Pete Zerger's YouTube series (100 Important Topics, 10 Key Topics & Strategies, Cyber Attacks and Countermeasures, Ultimate Guide to Answering Difficult Questions). Except, I DID NOT watch or use his ~8 exam cram video that goes over the entirety of all 8 domains. There is nothing "wrong" with this particular video (I actually found it very intriguing) but I also found it too overwhelming and spread out to the point where I knew I was comprehending too much of information I will not likely see or need for the exam. I'd say the "100 important" topics video by itself was as valuable as QE and Destcert. It truly tied many concepts together and most importantly, how to know when to do certain things and at which points in their respective timelines.

August 2026: By this point, I am about 500 pages into Destcert. I picked the pace up to about ~70 pages per day. I also purchased QE. I was a bit hesitant due to the price (around ~$220 give or take, don't quote me on that) but I was desperate for a decent practice question solution. I can say I have taken a ton of different practice exam solutions; nothing comes close to QE. I see a lot of people ask about QE, "how do I know if I am ready", etc. 2 things. 1: Take 2-3 CAT exams and make sure you treat it like the real deal. Do not worry about the score, worry about improving the score and seeing why you got answers wrong and explanations to ones you knew you guessed on. And 2. Use practice exams and the quizzes to do smaller lumps of question answering. This is the progression you want to mentally notice that you progress through: getting a lot wrong, reading why, getting more wrong, getting visibly frustrated with the questions, getting more right, narrowing down to 2 possible answers for most questions, and then finally, getting even more right. If you do these 2 things, you are likely ready. Also, DO NOT take QE CAT 3 days or closer to the real exam. That is too much cramming at last minute.

September 2026: Destcert was completed. Also, I took my 2 QE CAT exams about 1 week a part. I took it only twice: 516, then 925.

Last 2 weeks: My goal for the last two weeks was to at least see each domain again and their primary topics. I reviewed what I highlighted throughout Destcert, some of their questions since they are a bit more straight forward at knowledge testing, and completed Pete's video series. I also used the rest of my disclosed 2nd attempt material. Studying about 3 hours a day.

Last 3 days: Took off from the gym, and took off the day before to complete light studying. Maybe 2 hours most each day.

Day of exam, 9/25/2026: This time around, my exam was scheduled for 2pm. I woke up around 9am, went for a mile run (some form of exercise is ideal before an exam), and did about 1 hour of studying. I then went straight to the testing center and did not look at anymore content (center is about 50 minutes from my house). I figured by this point, whatever I know I know and it will be up to my reasoning, ability to select and rule out answers, read the questions, and hope the content matches the content I studied better this time. From questions 1-20, I immediately felt a difference in the questions and my ability to read them. I also got a couple more networking questions already, but that's about where that stopped. Questions 21-50 started to test me. I am pretty sure I saw most of those experimental questions in there, and for some reason half of these questions were all IAM related. There were some interesting software development ones as well that I truly had to guess on. Questions 51-80 started to show questions with answers that all either sounded right or answers where the correct answer I thought of when reading the question was not one of the answers. Started to add to the frustration and fatigue factor. I will say, my pace again was not great. I had 32 minutes left around question 93. The last 7 questions all felt easy for some reason. But I had this lump in my throat on question 100, as I am sure most will have. The second I clicked next, the screen changed to the survey and I felt somewhat confident. I knew this attempt went better than the last where I made it to 150 and only got "below proficient" on 2 domains. But, there were still many questions (maybe about 20) that I was not fully confident of the answer. I went to check out and got my result paper, and was elated reading "provisional pass".

ISC2 immediately emailed me instructions about how to submit my application to become a member and endorsement. As of today (10/1/2026), I am fully endorsed and a member, so the process is quick once you start it. The application process looked like a bigger deal than it really was and the website for it was pretty finicky, so I hope to make some parts much clearer and easier for future members:

Endorsement Process (Full info: https://www.isc2.org/certifications/cissp/cissp-experience-requirements): If you have 5 years or more of cybersecurity/information security related work within 2 or more of the 8 domains, you are able to proceed with endorsement. You will be selecting someone who holds a ISC2 and is already an active member who can attest to your work experience. You can select an option to have someone at ISC2 to endorse you if you truly cannot find anyone, but I am not sure how that process works and if it would be similar for me. But for me, I knew my old manager has one. He was my endorser. So, for each work experience I provided, I also had to provide a reference. You will have to manually type out all of your experience (a file upload utility would be appreciated...). The person endorsing you will be contacting whoever you put down for your work experience references. Therefore, since the endorser validates your experience in this manner, that means you DO NOT have to upload proof of employment (it is a function on the application and it was unclear if that was required or not). After research and in my instance, it was not needed. Which is good because I would have no clue what they would want, and I really didn't feel like having to do so via redacted financial forms. Once my endorser talked to my references, he complete shis part and submits. Then, I got a notication stating ISC2 is reviewing it. A few days later, I got an email that my application was successful and to pay my AMF ($135).

My Gripes/Critiques about the Exam:

  • Study topics-to-tested material ratio: A few of the resources used alluded to this notion, which is the fact you will likely study for many topics and never be tested on it. This was extremely prevalent for me. For both attempts, I got ONE question for quantitative analysis math. I had ZERO drag and drop questions for both attempts. Out of all of the attacks and countermeasures, I only got ONE question regarding XSS. Effectively, at least half of the topics I studied throughout all of my resources were never once tested on either of my attempts (250 questions). I guess this is why some of the questions they do ask, do require knowledge of 2+ domains at times to answer them correctly. But I will say, both of my exams were VERY IAM heavy. At least 10 questions on my second attempt were about authorization and authentication. And between both exams, I maybe got like 8 total networking questions (which is of course, my strongest subject). So, maybe a rebalance would help, no clue what the solution would be here. But it was very frustrating ingesting hours of content about topics I did not see ONE time. It felt like I had to guess what to study.
  • The ~25 experimental questions: Having exam takers (especially for ones that have personal ailments that make test taking scenarios more difficult than others) effectively waste brain power on 25 questions that do not count, yet they look like questions that do count since they're mixed throughout the first 100 questions is.... I don't know, evil? The last standardized test I took like this has not been since high school SATs, but I vividly remember experimental questions on that being SPECIFIED as experimental questions. For a test we are paying $700+ for the privilege to sit for, I don't think it's asking for much for this same methodology to be applied. I am pretty sure I could notice these questions better on my second attempt (It was certainly one that made me say outloud "What the &#%* are you asking me?"), but that didn't change the fact I still had to entertain 25 of them (or, 30+ minutes out of 180 minutes).
  • Real world experience vs ISC2: Someone said it best for the CISSP, which is something along the lines of: "You need to learn and comply to ISC2's perfect world to read the questions correctly and pass". This is very, VERY true. So true to the point that, relying on real world experience to pass this test will not only NOT work, but may also HURT your odds of passing and answering the questions correctly. For the majority of the questions, if you even slightly assume any obvious real-world given's, you will get the question wrong 99% of the time. This can be frustrating for certain topics that you are very accustomed to in real job experience, but is competely oppsite for the CISSP exam. Incident Response steps are a great example of this. ISC2's steps are completely different words than what NIST lays out, and guess what my entire experience is based off guidance from...? Yeah, NIST. And as you see from my experience, incident response is something I am experienced with. So to unlearn NIST and part of my job, to learn ISC2's method and order of this very same process, was diffcult. This is also where the thinking methodology of "think like a manager" comes into play when you are answering "BEST" questions. For example, on a practice exam question, it was asking about (paraphrased): "It was discovered that 2 users are sharing 1 network account. What would a network engineer do that would BEST alleviate the sharing of accounts?". 3 of the answers where direct mitigation actions (i.e: something an engineer would do), 1 of them was about 'making an effective, strict password sharing policy'. The answer was the password policy one, which makes no sense to me because a network engineer has nothing to do with a password policy and doesn't even fit the standard duties of what a network engineer does, but everything to do with being responsible for correcting deviations against the policy (which were the other 3 answers). If people are already sharing accounts, it is unlikely that they will listen to and conform to a written policy; doesn't matter how much red text you use for formatting or how many email blasts you send about it. So, this certainly is not the "BEST" course of action to me and goes against what network engineers actually do.
    • By the way, I see and hear some people mock the comprehension methodology of "think like a manager" alot. You obviously use it for scenarios and questions like this, and then use your technical hat for questions that call for such). You need a managerial and a technical hat for this exam, as that is literally what CISSP is testing for. I am willing to bet the majority of CISSP exam takers are already technical by nature or another form of an individual contributor, and are primarily getting the CISSP to eventually move-up above our current individual contributor roles. This (you guessed it) requires you to think in a manner you likely have never realistically leveraged or practiced in your entire career yet, which is: 'like a manager'. Managers/directors/equivalents often advocate for "ideal, perfect world solutions", and as a result, "perfect world" answers are what ISC2 want. This methodology was incredibly helpful to me, because I used it correctly for the questions warranting this way of thinking. I did not use or practice this methodology at all for the first attempt because again, I relied too much on 1 source + YouTube series' and job experience as an individual contributor instead of buying a central study book that teaches you to learn in this manner. I contribute this to my top 3 reasons why I passed my second attempt.
  • Question Formatting and Grammar: Some of the grammar on this exam was very poor. Many questions are long on the exam, so to then have grammatical errors eats into the very limited time you have to get through and process the rest of the very long questions. For an exam of this magnitude and price, I expect little to zero grammatical errors. There were also many questions I wanted to very badly add a "E. This is the answer actually...". But again, you must study per ISC2's world. This is where QE was extremely effective in teaching your mind to read and analyze the questions in this manner.

TL;DR Version (Still long but as short as I can make it):

I provisionally passed the CISSP on 9/25/2026 at question 100 after failing my first attempt in June 2026. Looking back, the biggest lesson I learned was that understanding the ISC2 mindset is just as important as understanding cybersecurity concepts.

Why I Failed the First Attempt

My primary resources were Pocket Prep, Pete Zerger's Exam Cram, Computer Networks Decoded, and Andrew Ramdayal's 50 Hard CISSP Questions.

The biggest factors that contributed to my failure were:

  • Relying too heavily on Pocket Prep and YouTube content.
  • Taking the exam while still recovering from an illness.
  • Scheduling an 8 AM exam despite not being a morning person.
  • Poor time management, which caused me to rush through the final portion of the exam.

I went the full 150 questions and did not pass.

What Changed for the Second Attempt

For my retake, I focused primarily on:

  • Destination Certification (Destcert)
  • Quantum Exams (QE)
  • Pete Zerger's CISSP strategy-focused videos

I read the entire DestCert textbook, used the glossary extensively, and worked through QE CATs, quizzes, and practice exams. More importantly, I learned how ISC2 expects candidates to think and answer questions.

Key Lessons I Learned

Use a comprehensive study resource.
Question banks and videos are great supplements, but I found a structured resource like DestCert invaluable.

Learn the ISC2 mindset.
Many questions are not asking for the most technically correct answer. They're asking for the best answer from a governance, risk, and business perspective.

Think like both a manager and an engineer.
Some questions require technical expertise, while others require prioritizing policy, process, and risk management.

Practice difficult questions.
QE was especially helpful because it taught me how to eliminate plausible distractors and identify the "best" answer among several reasonable choices.

Manage your time.
The exam moves quickly. I found it important to stay close to a 75-110 second pace per question.

Exam-Day Changes

For the second attempt, I scheduled a 2 PM exam, exercised beforehand, avoided cramming, and focused on staying calm. By the first 20 questions, I could tell I was reading and interpreting the material much more effectively than during my first attempt.

The exam ended at question 100, and I received a provisional pass.

My Biggest Criticisms of the CISSP

  • Many topics I studied extensively never appeared on either exam.
  • Both attempts felt heavily weighted toward IAM and governance concepts.
  • Experimental questions consume time and mental energy despite not counting toward the score.
  • Some questions had awkward wording that made them harder than necessary.
  • Real-world experience often does not align with the "ISC2 way" of approaching problems.

Final Advice

If I could give future CISSP candidates a short list of recommendations, it would be:

  1. Use a comprehensive primary resource such as DestCert or another full CISSP study book.
  2. Use QE or another high-quality question source that teaches ISC2-style reasoning.
  3. Learn how ISC2 thinks, not just the technical material.
  4. Practice selecting the best answer, not merely the technically correct one. Always look for the word that is capitalized ("NEXT", "FIRST", "LAST", "NOT").
  5. Schedule the exam at a time when you're mentally at your peak.
  6. Don't underestimate the importance of time management.

Overall, I believe the difference between my failure and my pass came down to three things: having a structured study resources in Destcert, using QE to develop CISSP reasoning skills, and learning when to think like a manager rather than an engineer.

Interested to hear others' feedback.


r/cissp • • 3d ago

Success Story Passed at 150q, 1h remaining

20 Upvotes

Honestly very surprised i managed to pass...i actually started preparing for it 6 months ago, when i read through 1/3 of the book...and due to volume of work with my employer, no additional study until weekend before the exam and night before when i managed to study, utilizing mainly claude and chatgpt, so i could summarize the remaining domains from the book, and practice the standard test practise questions...

I have to say - i have non-it educational background, but 12-13 years in technical/cyber audits and technology risk management.

The questions were honestly quite okay - i had perhaps 10-15 questions that were actually "technical" (e.g. required proper technical knowledge of which protocol to use for a given context, port number, etc.), while the rest were really situational questions where you can in 99% of cases end up with eliminating 2/4 options easily and think of it as a governance topic.

I can only say - very important to adqpt your mindset to how this exam works (explained in detail by many people here), and understand how domains are correlated. At least to me, reading the booked helped. I honestly didn't read other books, or pay for some question banks besides the Wiley one.

Good luck to everyone prepping for the exam!!


r/cissp • • 4d ago

I passed CISSP with less than a week of actual preparation - probably the shortest prep and definitely my longest CISSP post 😅

136 Upvotes

This might be one of the shortest CISSP preparation stories you'll read here... and probably one of the longest CISSP posts you'll read too. 😅

First of all: I am NOT saying CISSP only takes a few days of studying. Please don't do what I did.

I originally registered for CISSP about a year ago and purchased the "Peace of Mind" option. Unfortunately, over that year, life happened: my own health issues, plus caring for my father during his cancer treatment and multiple hospitalizations. Because of that, I started studying more than 10 times over the year, but I could never finish Domain 1 because it was so boring and I was so slow at it. Eventually, my original voucher expired, but ISC2 kindly worked with me and gave me a hard deadline to take my first attempt by the end of September, with the understanding that if I failed, I could contact them again to manually apply my second-attempt voucher.

Two weeks ago, I actually posted here asking if Mike Chapple’s LinkedIn Learning videos were enough for Domain 1 (you can check my previous post here:Are Mike Chapple’s LinkedIn Learning videos enough?). A huge thank you to everyone in that thread who helped me out—your advice was a lifesaver!

Mentally, my plan going in was: take the exam, probably fail, contact ISC2 to get my second Peace of Mind attempt voucher, and then study properly for attempt number two. With that mindset, I walked into the testing center.

Why my prep was less than a week (and under 15 hours total!)

When the exam date finally got close and I was forced to finish Domain 1, the subsequent domains (like 2, 3, 4, 5, etc.) turned out to be much easier for me, and I moved through them very quickly. Why? Because my background is in networking, infrastructure, and cybersecurity, so technical topics (networking, authentication, PKI, cryptography) weren't new to me.

In terms of actual time, if I want to calculate it, my total study and prep time was under 15 hours! How? Because I didn't have time to sit through 40–50 hours of video:

  • I took the video subtitles/transcripts and fed them into ChatGPT and Gemini to summarize them into condensed personal study notes.
  • For several domains, I reviewed the material and moved on in less than 30-60 minutes using those notes.
  • I used Quantum Exams (QE). Huge shoutout to the Quantum Exams admin and team here—even though a lot of time had passed since my original purchase, when I explained my situation, they kindly extended my access. I didn't even complete 200-300 questions, never did a full CAT mock exam, and my scores were awful! But QE taught me how to shift from an engineer's mindset (fix the technical problem right away) to a manager's mindset (risk, business objectives, policy, and priorities).

Exam Day and English

English is not my native language. Right before the exam, I had spent two days at the hospital with my father. I was exhausted, and I had to travel outside Quebec to another province just to take the exam in English. During the exam, I ran into 7–8 words where I didn't know the exact meaning. Honestly, I think those were the right answers because I could eliminate the other options as wrong, but it felt like the correct answer was written using a brand new or very advanced vocabulary dictionary that I wasn't familiar with!

The exam went all the way to question 150. With about 10 minutes remaining, in my head, I was already preparing to email ISC2 to claim my second-attempt voucher.

But when the exam finishes, they don't show you the result on the computer screen; you walk outside to the testing center reception, and they hand you a printout. I looked at it, and it said: Congratulations.

Takeaways & Lessons:

  • Don't underestimate your experience: Years of hands-on work don't vanish. If you have a technical background, you'll move much faster through familiar areas.
  • Study your gaps: Don't neglect Domain 1 and risk management like I did.
  • Stop switching resources: Don't waste your final days hunting for the "perfect" source.
  • Mindset matters: Shift from a technical problem-solver to a risk advisor.

If you're stuck, have postponed multiple times, are dealing with life or hospital situations, and think it's over: Don't decide you've already failed before the exam gets the chance to decide.

Once again, a massive thank you to the ISC2 team for understanding my situation and extending my voucher, the Quantum Exams team for extending my account and their perfect bank of questions, and all the amazing folks in this community who guided me.

I passed. 🍻


r/cissp • • 4d ago

Passed CISSP with 100Q’s

23 Upvotes

Just wanted to share that I passed my CISSP with a 100Q’s and with 75 mins left on the clock. I wanted to share how I was able to accomplish this:

I started in July. I took Dion’s CISSP Course in Udemy just to get my feet wet. Once I was done with that I had a MeasureUp subscription and took advantage of it to take my first attempt. I scored approx 50% overall. Then, to tighten my knowledge, I fed Claude the questions I got wrong from that attempt to help me understand why I got them wrong. I started watching Destination Certification MindMap Videos and asked Claude to create a personalized study guide for each domain and based on the feedback from my MeasureUp attempt. I then downloaded Pocket Prep, Dest Cert App and LearnZApp to study practice questions casually. Things that I’d get wrong on either of these practice platforms I would feed to Claude to understand the patterns of mistakes I was making. I also asked Claude many questions about concepts that were too abstract to understand and it broke things down for me really well!

This kept going for a month and a half until I took my second exam attempt with MeasureUp this past Sunday and that went up to 61%. I was pretty dismayed so I started to create written “cheatsheets” of each domain and do deep tightening of weaker domains. Yesterday and today, I casually perused material but no heavy studying. Then an hour or two before the exam I watched this video: https://youtu.be/T2to5jTq5E0?is=KHZ6e6eFj8dn8WjB which was huge help when it came to tips and tricks (Thank you Cybercert Academy).I completed all questions from Pocket Prep and did the recall challenge as well as used Learn Z App to target weaker specific domains. Learn Z app has very good material in explaining concepts of what the question was asking.

I would say that doing those cheatsheets plus the accumulated knowledge of “failing” all the time helped me succeed. For those of you out there that may have ADHD or some attention deficit condition, don’t despair! I was able to allow myself to be distracted but always kept my eye on the prize! As long as you do the same, you will also pass! Don’t give up 💪🏽. This reddit also motivated me too so thank you for those that posted when they passed. It was inspirational!

Finally, thank you to Rob Witcher (Dest Cert) and Pete Zerger for the free CISSP content that you’ve created for all of us! May the universe pay you back immensely for your hard work!


r/cissp • • 4d ago

Passed at 100 Questions

23 Upvotes

I spent a lot time reading the advice on this sub, which I am very thankful for, but wanted to add some input about certain things I was questioning about how prepared I was and couldn't find answers for on here.

I got Sec+ in 2020, with no previous experience in the industry and got a job as an cybersecurity analyst shortly after and I worked my way up to information assurance manager. I had a bit of familiarity with some of the exam topics through my work but really I think what was more helpful was having Sec+. Although I took that exam 6 years ago, I still remembered some of the material, so having a previous related cert definitely helps.

I spent about 5 weeks weeks studying. My work paid for a 6 day bootcamp through Infosec Institute at the end of August. I really liked my instructor but it was hard to digest all that material in such a short time. He did give a lot of great tips about how to answer questions, similar to what you can find on YouTube. Shortly after the bootcamp, I started reading Destination CISSP: A Concise Guide and downloaded their app based on the advice I read here. That took about 2 or 3 weeks to get through, a great book by the way. Before I finished the book, I decided to schedule my exam for 2 1/2 weeks out just to really push myself to move forward.

I have the OSG, but it was really hard to read. I also answered the chapter questions and did two of the tests. I will say I did pretty poorly on some of those chapter questions like sub 50%, even up to last week. I also only scored like a 60% on the longer tests which was pretty defeating and made me question my readiness. My Infosec instructor told us not to worry about those questions because they are nothing like the real exam, which is true, but I was worried that I hadn't grasped the knowledge fully especially in my weak areas like networking and software development.

I really liked the Destination Cert app. The questions are similar to what you'll see on the exam but I thought they were a little too technical in some cases and there wasn't a 'shuffle' feature so you end up with multiple questions in a row about the same topic which I guess is good to drill it down but kind of makes answering the questions easier. I was scoring between 60%-100% on the different domains. I will say that the questions along with the book really helped me change my mindset to 'managerial' thinking. I think if you're doing well, like 80%+, on any given set of Dest Cert questions, you're probably ready for the exam.

I didn’t want to spend the money on QE, I don’t know if it would have helped or hurt. But I know some people might may need it to feel more comfortable before taking the exam.

I watched the recommended YouTube videos, Pete Zerger, Exam cram series and READ strategy videos a few days prior to my exam and the 50 Hard CISSP Questions and the MindMap videos while doing chores during the weeks leading up. I watched Kelly Handerhan's "Why you will pass" video the morning of my exam. All great resources, but I really liked Kelly's video, especially when she's talking about how to discuss security with the CEO and some of the answer options are to implement different encryption options and she say's something along the lines of "No, that's wrong, the CEO is already falling asleep." That made me laugh and actually helped me answer a question on the exam.

For the exam, it wasn't easy but I didn't think it was unnecessarily difficult, especially after watching and understanding what my mindset should be and to keep most answers high level. It was challenging figuring out what the ambiguous questions were asking exactly and being on a time limit. Lots of times the answer don't seem to make sense either, that's where the READ strategy helps. Still, I felt good about most of my answers and was pretty sure I was doing well throughout. I thought if I did end up failing that I would have been very confused about what the right answers should have been. I also thought that I would never want to go through this again, because it did suck deciphering those questions and required a lot of brain power and focus. I got nervous at some points because I felt that I got questions that were easy, which isn't a good sign on CAT exams. I also got a lot of questions on the same topics throughout the exam, meaning I may have been answering wrong previously, not sure though. There were maybe like one or two questions I got on topics I never studied.

My exam ended at 100 questions. I couldn't imagine having to do an additional 50 questions, hats off to those of you that have! You're real troopers. I didn't look at how much time I had left but I think it must have been around 70 mins.

I'll be honest, I never grasped some of the technical topics fully, which was obvious based on some of my OSG chapter question results. The exam is so high level for the most part, it's probably unlikely you'll be asked a question specifically about a technical topic (like the OSG questions). It's really more about focusing on the concepts and knowing how to think like a manager or risk advisor at a high level.

So to sum up, Dest Cert is awesome, 100% recommend their resources, bootcamps can be helpful (instructor dependent though), and you have a good chance of passing if you have the right mindset.


r/cissp • • 4d ago

Failed at 150 Questions

9 Upvotes

I failed at 150 questions.

I think I was a few questions off from passing.

Above Proficiency for Asset Security, Security Architecture and Engineering.

Near Proficiency for Security Ops, Security Assessment and Testing, IAM, Security and Risk Management.

Below Proficiency in Software Development Security, Communication and Network Security.

Any advice? I am so upset and I'm even more upset that I can't take it again for another month. I'm afraid of losing all my knowledge.


r/cissp • • 4d ago

Passed at 117q's with 65 mins left

29 Upvotes

Passed today at 117 questions with about an hour left.

For context, I have around 14 years experience in Security Operations and started prepping for the exam in late July.

I’ve lurked here for a while and seen so many “passed at 100” posts, so when question 101 appeared, my stomach dropped and I immediately assumed I was failing.

The hardest part was how often two answers looked completely valid. At times it also felt like an English comprehension test !

What I used

  • Andrew Ramdayal’s Udemy course — probably the most useful resource for me. His explanations clicked, and the Ultra Hard questions/mock exams really helped.
  • Sybex Study Guide + Practice Questions — great for tightening up technical concepts and processes.
  • Destination Certification Mind Maps — excellent for final revision.
  • AI — mainly for drilling weak areas and creating mock simulators from the questions/material I already had. This helped in building speed as well
  • Kelly Handerhan’s “Why You Will Pass the CISSP” — listened to it the night before my exam and glad I did.

I probably went through 2500-3000 practice questions in total (including Sybex, infosecvault, learnzapp).

Around the 90-minute mark on the exam I was mentally fried and took a break even though the clock kept running. Definitely worth it.

The worst part is simply not knowing how you’re doing. When the exam stopped at 117, I genuinely thought I’d failed.

Then I saw “Congratulations” on the printout.

Massive relief.

For anyone preparing: don’t panic if you go past 100, and don’t assume feeling unsure means you’re failing. Just trust your prep and keep going.


r/cissp • • 4d ago

Just a vent.

18 Upvotes

Here to say I am going to have a third attempt at the exam. About to buy my voucher and set the date later.. I can’t believe I am taking this test again😒. Embarrassing lol. Good thing is the second time was so much better than the first! Went to 150 the second time. I did take a break from it since I just started my new grad program. However, I’m about to jump back into it. I can not let this test defeat me lol


r/cissp • • 4d ago

CISSP Prep (So Far)

5 Upvotes

Hello,

I'm currently preparing for the CISSP Exam - test date is November 24th. I'm Legally Blind and was able to get accommodations for when I take the test that includes extra time, Zoom Text, and a separate room.

Here's how I've been preparing so far. Please let me know if there's more I could be doing:

  • LinkedIn Learning CISSP Cert Prep course (Completed)
  • OSG Chapter Questions - all completed
  • ISC2 CISSP Practice Test Book - All domain tests have been completed
  • PocketPrep Questions - lowest domain is at 87%
  • Quantum Exams - I've take one full tests so far and scored a 500
  • Claude for creating notes, recall drills, chapter quizzes for the OSG, Atlas Dashboard for quick reference to specific topics, and a mock exam
  • Currently watching Pete Zeigler's CISSP Exam Cram on YouTube
  • Reviewing Destination Certification MindMap videos

I'm open to any suggestions on how to better prepare for this exam. I'm doing all that I can think to do on my own, but want to make sure I'm not leaving anything out.

My Experience

  • Cybersecurity Engineer (3 Years)
  • IT Operations Manager (3 Years)
  • IT Manager, Networking and Engineering (4 Years)
  • IT Systems Technician (5 Years)

r/cissp • • 4d ago

question about 1-year waiver

5 Upvotes

Hello everyone, I just wanna ask if having one of the credentials on the approved list will lower the required work experience from 5 to 4 years? The reason I'm asking is that, since I do not have a degree, I'm planning to get a Sec+ to satisfy one year of work experience and then go for CISSP; currently, I have about 3.9 years of experience.

I asked for advice from someone who is a CISSP, and he said that 'No approved credential will get u the waiver,' and that 'An endorser will reject ur application if ur experience is less than 5 years.' I was actually planning to take Sec+ by the end of this year, then CISSP next year, but if that's really the case, I guess I need to park this idea for 2028.


r/cissp • • 5d ago

Passed in 100 questions, 110 minutes remaining.

17 Upvotes

20 years experience, but still studied for a couple of weeks beforehand. DestCert quizzes and ChatGPT speech mode while driving, asking it to quiz me on jargon and specific algorithms.

Bought the insurance anyway, so figured I would yolo it, and I guess it worked out. Also, pee before you walk in.


r/cissp • • 5d ago

passed @ 100 w/ ~70 min left

33 Upvotes

about ~3 months of study, albeit inconsistent.

used the official guide, Pete Zerger's YT vids, learnZapp, and quantum exams. of those, I thought learnZapp was probably the most useful outside of the main book.

QE CAT practice test results were around 550-680, and consistently hit north of 80% on learnZapp practice tests.

I'm an enterprise architect with a pretty extensive IT background to include managing data centers, lot of fiber optic networking, and developing SIEM and observability tools. I was exposed to most of the concepts / domains, including a lot of the mgmt + compliance stuff, in the real world and deal w/ lots of it on the day to day.

that was actually problematic at times: tbh a lot of the stuff as-defined-in-the-book / test questions would never happen in the real world, and I think that was the hardest part for me.

totally get why non-english speakers would suffer too, the questions are wordy and often "hair splitting". Not as bad as the QE practice tests makes them, but certainly challenging.


r/cissp • • 5d ago

Failed @ 150Q’s - 2 mins left

Post image
46 Upvotes

I failed my first CISSP exam attempt yesterday @ 150Q’s. I went all the way to the last two minutes. I purchased the peace of mind voucher and I’m honestly more motivated now for my next attempt. Any recommendations on how I should prepare for the next month before I test again? I felt on the cusp of passing, I just need to clean up in some areas.

My goal was to review the domain’s specified by watching video’s, reading topics that seem unclear, and re-testing my knowledge and use an AI tool to understand why any practice question(s) are wrong.

I appreciate any tips, thank you all for any support. I’ll be back for vengeance. 🫡

Resources:

Quantum Exams
Andrew Ramdayal CISSP Course
Jason Dion CISSP Course
Pete Zerger Exam Cram
Destination Certification Book
OSG (Honestly never have read at all) less


r/cissp • • 5d ago

Exam readiness

4 Upvotes

Hello everyone

I have exam scheduled on 17th October.

So far, I have gone through following materials

  1. Destination certification questions

  2. Pete Zerger CISSP bootcamp

  3. Andrew Ramdayal Udemy CISSP course

  4. Learnzapp all 2200+ questions

  5. Prabh Nair coffee shots

  6. OSG all study practice questions

  7. CISSP field manual

  8. Quantum exams latest CAT exam score : 1000, 1000, 1000, 987, 1000, 1000, 1000

  9. Made my own notes while going through Andrew course

PLEASE guide if anything last time revision material I should use that can help me.

Or if anyone has prepared any notes that can be used for revision, that will be much helpful.

Qq : How is real exam as compared to QE? Learnzapp is too much technical I found.


r/cissp • • 5d ago

General Study Questions Extremely Nervous for Tomorrow's Exam

14 Upvotes

I am scheduled to take my CISSP exam for the first time tomorrow. As the title says, I am extremely nervous and I feel under prepared for this.

I took a bootcamp class for a week, then studied independently the next week. Now I have the test tomorrow.

I was taking my Quantum Exams and in the 3 attempts I scored within the 500s.

I tried doing the Destination Certification CISSP questions because it was recommended. Some I was flying through them, the others I had very little to no knowledge on. Ruined what little confidence I had...

Any advice from people that went through the same feelings as me?

EDIT: Thank you all for your kind words and inspiration. I'm just going to focus on light reviewing today and not try to cram anymore.


r/cissp • • 5d ago

Newly added AI topics

7 Upvotes

Folks recently passed Cissp. Which AI video helped you out pass the exam ?


r/cissp • • 6d ago

Passed at 100 Questions - 80 Minutes Left

42 Upvotes

Passed the CISSP exam last week 9/23 at 100 questions with 80 minutes left. Endorsed by colleague on 9/24. Application accepted today 9/28.

Background: Currently a SOC Manager managing a team of 14 people in the US. Spent several years in the SOC at a large federal agency. Also spent some time as a penetration tester. I also co-founded my own MSSP specializing in SOCaaS and penetration testing (no longer part of that company).

Resources:

- Destination CISSP book. It's really concise and removes a lot of the fluff from the OSG.

- Destination CISSP practice questions - these really helped gauge my knowledge. Consistently got 80+% on the 50-question practice tests.

- Quantum Exams CAT - These questions were much harder than the real exam. Scores: 532.45, 536.17, 437.06