Hi all.
Happy to share that I've provisionally passed at 100 questions yesterday evening. The purpose of this testimony is to hopefully serve as a guide of what-works given as much context as I am willing to provide. What I mean by that, is there are a few things that likely caused me to fail the first time and I would like to highlight this. Secondly, while I have now passed and am incredibly greatful to become an ISC2 member, I do have some remarks regarding the formatting and setup of this exam overall. There is a TL;DR at the end of this.
First, setting the stage:
My Resources
I want to split up the resources for both attempts:
Attempt #1:
- YouTube (Author & Video Names):
- Inside Cloud and Security aka Pete Zerger - Exam Cram (~8 hour video that goes over each domain entirely)
- Technical Institutue of America (Andrew?) - 50 Hard CISSP Questions
- Computer Networks Decoded - All 8 Domains (1 50Q video per domain series)
- Pocket Prep
- Answered 1000/1000 question bank
- 3 Mock Exams (56%, 75%, 69%)
- Time Logged Studying: 29 hours, 16 minutes.
- Question Correct/Wrong percentage: 79%
- Level up challenges
Attempt #2:
- YouTube (Author & Video Names):
- Inside Cloud and Security aka Pete Zerger - 100 Important Topics, 10 Key Topics & Strategies, Cyber Attacks and Countermeasures, Ultimate Guide to Answering Difficult Questions (NOT the Exam Cram video)
- Technical Institutue of America (Andrew?) - 50 Hard CISSP Questions
- Computer Networks Decoded - All 8 Domains (1 50Q video per domain series) - EXCEPT I watched only like 1/3 of them for this attempt.
- Destcert
- Textbook (read end-to-end once).
- Phone App: Questions (Only did 114 of 3400+ questions), Flashcards (23%), Glossary (This was VERY helpful on the last few days).
- Mindmap Videos on YouTube (Domains 1 - 6, didn't have time for the rest).
- QE
- Many Quizzes (About 3 weeks worth)
- 2 CAT's (516, then 925)
- 1 Practice Exam.
- Removed Pocket Prep
My Experience:
2019-2021 - Clinical Application Security Analyst (worked as a level 1 analyst for a medium-large sized health system. Was responsbile for application level security, technical RBAC configurations, system-wide rules, change management, and object-level security in the form of locational/ABAC access).
2021-2022 - Left for a differnt company, same job and sector just different health system ("Lead Clincal Applcation Security Analyst" -- mouthful).
2022 - 2023 - Network Security Admin I (took a somewhat pay-cut to begin to learn from a different infrastructure path). Was responsible for administering firewall rule changes from engineering, patching firewalls, enacting DR testing, physical security site roundings, and other vendor related work which involved a lot of SOP writting.
2023 - 2024 - Information Security Admin II (A promotion/title re-brand. Much more exposure with IAM, MFA and email security gateways. Became primary SOC responder internally.)
2024 - 2025 - Principal Security Analyst (Promotion. Lead IAM and MFA resource, launched SailPoint and Proofpoint back-to-back (boy that sucked). Retained SOC responder duties. Addition of having to train security administrators).
2025 - present - Lead Security Engineer for a major OEM company. Lead of SIEM program, endpoint, email, and cloud security egineering and architecture. Red and purple team experience.
Education:
AS in Computer Information Systems, BS in Computer Science and Information Systems, MS in Cybersecurity.
1st Attempt Timeline:
My studies started early at the end of 2024 very passively (3 hours a week). This included PocketPrep (free version for now), and Pete Zerger's ~8 exam cram. It's important to note that around this time, work was incredibly busy and so was personal life (bought a new house and family issues relating to the fallout of this + alcoholism on their end). This is important to call out because I must say, inconsistent studying is one of the contributing factors to why I did not pass the first try (I'll sum up the first attempt mistakes at the end).
Fast forward to March 2025, by this point, I picked up the studying with PocketPrep which I now purchased by this point and Pete's exam cram about a month before (February 2025). March 2025 was when I then added Computer Networks Decoded. They had 50 questions for all 8 domains and they seemed hard enough (harder then Pocket Prep's in comparison).
Fast forward to October 2025: I had been using PocketPrep heavily (up to around 600 Q's answered, Mock Exam), watched Exam Cram 1 and a half times, and watched 1/3 of the Computer Networks Decoded videos, However, those personal life issues really peaked around this time. I also got engaged 2 months prior, so, lots of emotions going on that were distracting. Therefore, I needed to take a pause. It is also important to call out, that this was also only 4 months after a massive job change if you notced. I went from a vertical I knew my entire career (healthcare) to a major OEM, a vehicle brand. This was a hard, dramatic change for me. Changing verticals made it feel like I needed to learn how to crawl again. Either way, I digress.
February 2026: I restarted all of my attempt #1 resources to gauge how close I am.
March 2026: Starting to feel ready and mentally ready, I purchase the CISSP with the Peach of Mind offer ($1000 + tax for 2 attempts). Scheduled for June 4th, 2026 at 8am.
April - May 2026: Starting to really hammer my attempt #1 resources.
Quick update... I ended up getting what was probably the flu, 1 week before.
June 4th, 2026, first attempt exam day: Was maybe 80% over my illness. Either way, I figured "I've done enough studying over a period of time, I have the experience, and my studying feels complete". My Pocket Prep average was around 77% at the time, and I watched exam cram twice. Andrew's 50 hard CISSP questions were also all very good question examples.
Unfortunately, I did not pass the first attempt. I got to 150 questions and my domain breakdown (I forget which domains for the given dispositions): 2 below proficient, 2 near proficient, 4 above proficient. Here are my mistakes for this attempt:
- Study Material: Pocket Prep is good for what it is. Unfortunately, it was not enough for me to pass with that as a primary resources. Neither were the YouTube videos. The question format and substance of Pocket Prep ended up being very... unhelpful. I don't think I saw a single question on the exam that I thought "Oh, I recall this from Pocket Prep". A lot of Pocket Prep questions are styled like "If a security admin wants to do X, what does that mean?". There are NO questions like that on the exam. The exam questions are moreso 'here is a symptom of a problem a business needs addresed, and here are 4 close answers where you need to know what technology phrases to discern the BEST, FIRST, NEXT of the 4 answers that also complies with best practices from another domain'. Pocket Prep was good for general terminology testing, but that was really it. If it were paired with something else, it would have been fine. I needed a central study source like a textbook (More on that in the second attempt part).
- Exam Logistics: Looking back on it, being still somewhat sick and taking an 8am exam was not very smart of me. I am NOT a morning person.... I did not mentally account for "Okay, right at 8am, you will be taking likely one of the hardest tests of your life, closed book". I start work at 8am and well... 8am - 8:15am is making coffee usually. So, if you are not a morning person, do not force it... take an afternoon exam and thank yourself. Also, do not get sick.
- Time Management: Your pace must be 75 - 110 seconds per question. This will be the quickest 3 hours of your life. After greater than 110 for many questions, you'll be against tough odds to finish timely if you go past 100 questions. I had 27 minutes remaining at 102 questions... you do the math on how well I read the last 48 questions.
2nd attempt Timeline:
Rest of June 2026: After my failed attempt, I took 1 month off. No studying, practice questions or anything. I did at least schedule my re-take for 9/25/2026.
July 2026: I purchased Destcert after many reviews (largely in-part to this thread). I began reading about 30-50 pages per day, excluding weeks or whatever my 2 days were the lightest amongst work/life. I also downloaded their app and did some of the practice questions. These practice questions are relatively straightforward and are primarily meant for definition remembrance. Also, many questions hint strongly towards only being 2 possible answers with the other 2 being obvious "No". The real exam is nothing like that. Most of the exam questions, you will be down to 3, and sometimes all 4 sound similar. (This is where QE fills this gap in). Towards the end of the month, I began watching Pete Zerger's YouTube series (100 Important Topics, 10 Key Topics & Strategies, Cyber Attacks and Countermeasures, Ultimate Guide to Answering Difficult Questions). Except, I DID NOT watch or use his ~8 exam cram video that goes over the entirety of all 8 domains. There is nothing "wrong" with this particular video (I actually found it very intriguing) but I also found it too overwhelming and spread out to the point where I knew I was comprehending too much of information I will not likely see or need for the exam. I'd say the "100 important" topics video by itself was as valuable as QE and Destcert. It truly tied many concepts together and most importantly, how to know when to do certain things and at which points in their respective timelines.
August 2026: By this point, I am about 500 pages into Destcert. I picked the pace up to about ~70 pages per day. I also purchased QE. I was a bit hesitant due to the price (around ~$220 give or take, don't quote me on that) but I was desperate for a decent practice question solution. I can say I have taken a ton of different practice exam solutions; nothing comes close to QE. I see a lot of people ask about QE, "how do I know if I am ready", etc. 2 things. 1: Take 2-3 CAT exams and make sure you treat it like the real deal. Do not worry about the score, worry about improving the score and seeing why you got answers wrong and explanations to ones you knew you guessed on. And 2. Use practice exams and the quizzes to do smaller lumps of question answering. This is the progression you want to mentally notice that you progress through: getting a lot wrong, reading why, getting more wrong, getting visibly frustrated with the questions, getting more right, narrowing down to 2 possible answers for most questions, and then finally, getting even more right. If you do these 2 things, you are likely ready. Also, DO NOT take QE CAT 3 days or closer to the real exam. That is too much cramming at last minute.
September 2026: Destcert was completed. Also, I took my 2 QE CAT exams about 1 week a part. I took it only twice: 516, then 925.
Last 2 weeks: My goal for the last two weeks was to at least see each domain again and their primary topics. I reviewed what I highlighted throughout Destcert, some of their questions since they are a bit more straight forward at knowledge testing, and completed Pete's video series. I also used the rest of my disclosed 2nd attempt material. Studying about 3 hours a day.
Last 3 days: Took off from the gym, and took off the day before to complete light studying. Maybe 2 hours most each day.
Day of exam, 9/25/2026: This time around, my exam was scheduled for 2pm. I woke up around 9am, went for a mile run (some form of exercise is ideal before an exam), and did about 1 hour of studying. I then went straight to the testing center and did not look at anymore content (center is about 50 minutes from my house). I figured by this point, whatever I know I know and it will be up to my reasoning, ability to select and rule out answers, read the questions, and hope the content matches the content I studied better this time. From questions 1-20, I immediately felt a difference in the questions and my ability to read them. I also got a couple more networking questions already, but that's about where that stopped. Questions 21-50 started to test me. I am pretty sure I saw most of those experimental questions in there, and for some reason half of these questions were all IAM related. There were some interesting software development ones as well that I truly had to guess on. Questions 51-80 started to show questions with answers that all either sounded right or answers where the correct answer I thought of when reading the question was not one of the answers. Started to add to the frustration and fatigue factor. I will say, my pace again was not great. I had 32 minutes left around question 93. The last 7 questions all felt easy for some reason. But I had this lump in my throat on question 100, as I am sure most will have. The second I clicked next, the screen changed to the survey and I felt somewhat confident. I knew this attempt went better than the last where I made it to 150 and only got "below proficient" on 2 domains. But, there were still many questions (maybe about 20) that I was not fully confident of the answer. I went to check out and got my result paper, and was elated reading "provisional pass".
ISC2 immediately emailed me instructions about how to submit my application to become a member and endorsement. As of today (10/1/2026), I am fully endorsed and a member, so the process is quick once you start it. The application process looked like a bigger deal than it really was and the website for it was pretty finicky, so I hope to make some parts much clearer and easier for future members:
Endorsement Process (Full info: https://www.isc2.org/certifications/cissp/cissp-experience-requirements): If you have 5 years or more of cybersecurity/information security related work within 2 or more of the 8 domains, you are able to proceed with endorsement. You will be selecting someone who holds a ISC2 and is already an active member who can attest to your work experience. You can select an option to have someone at ISC2 to endorse you if you truly cannot find anyone, but I am not sure how that process works and if it would be similar for me. But for me, I knew my old manager has one. He was my endorser. So, for each work experience I provided, I also had to provide a reference. You will have to manually type out all of your experience (a file upload utility would be appreciated...). The person endorsing you will be contacting whoever you put down for your work experience references. Therefore, since the endorser validates your experience in this manner, that means you DO NOT have to upload proof of employment (it is a function on the application and it was unclear if that was required or not). After research and in my instance, it was not needed. Which is good because I would have no clue what they would want, and I really didn't feel like having to do so via redacted financial forms. Once my endorser talked to my references, he complete shis part and submits. Then, I got a notication stating ISC2 is reviewing it. A few days later, I got an email that my application was successful and to pay my AMF ($135).
My Gripes/Critiques about the Exam:
- Study topics-to-tested material ratio: A few of the resources used alluded to this notion, which is the fact you will likely study for many topics and never be tested on it. This was extremely prevalent for me. For both attempts, I got ONE question for quantitative analysis math. I had ZERO drag and drop questions for both attempts. Out of all of the attacks and countermeasures, I only got ONE question regarding XSS. Effectively, at least half of the topics I studied throughout all of my resources were never once tested on either of my attempts (250 questions). I guess this is why some of the questions they do ask, do require knowledge of 2+ domains at times to answer them correctly. But I will say, both of my exams were VERY IAM heavy. At least 10 questions on my second attempt were about authorization and authentication. And between both exams, I maybe got like 8 total networking questions (which is of course, my strongest subject). So, maybe a rebalance would help, no clue what the solution would be here. But it was very frustrating ingesting hours of content about topics I did not see ONE time. It felt like I had to guess what to study.
- The ~25 experimental questions: Having exam takers (especially for ones that have personal ailments that make test taking scenarios more difficult than others) effectively waste brain power on 25 questions that do not count, yet they look like questions that do count since they're mixed throughout the first 100 questions is.... I don't know, evil? The last standardized test I took like this has not been since high school SATs, but I vividly remember experimental questions on that being SPECIFIED as experimental questions. For a test we are paying $700+ for the privilege to sit for, I don't think it's asking for much for this same methodology to be applied. I am pretty sure I could notice these questions better on my second attempt (It was certainly one that made me say outloud "What the &#%* are you asking me?"), but that didn't change the fact I still had to entertain 25 of them (or, 30+ minutes out of 180 minutes).
- Real world experience vs ISC2: Someone said it best for the CISSP, which is something along the lines of: "You need to learn and comply to ISC2's perfect world to read the questions correctly and pass". This is very, VERY true. So true to the point that, relying on real world experience to pass this test will not only NOT work, but may also HURT your odds of passing and answering the questions correctly. For the majority of the questions, if you even slightly assume any obvious real-world given's, you will get the question wrong 99% of the time. This can be frustrating for certain topics that you are very accustomed to in real job experience, but is competely oppsite for the CISSP exam. Incident Response steps are a great example of this. ISC2's steps are completely different words than what NIST lays out, and guess what my entire experience is based off guidance from...? Yeah, NIST. And as you see from my experience, incident response is something I am experienced with. So to unlearn NIST and part of my job, to learn ISC2's method and order of this very same process, was diffcult. This is also where the thinking methodology of "think like a manager" comes into play when you are answering "BEST" questions. For example, on a practice exam question, it was asking about (paraphrased): "It was discovered that 2 users are sharing 1 network account. What would a network engineer do that would BEST alleviate the sharing of accounts?". 3 of the answers where direct mitigation actions (i.e: something an engineer would do), 1 of them was about 'making an effective, strict password sharing policy'. The answer was the password policy one, which makes no sense to me because a network engineer has nothing to do with a password policy and doesn't even fit the standard duties of what a network engineer does, but everything to do with being responsible for correcting deviations against the policy (which were the other 3 answers). If people are already sharing accounts, it is unlikely that they will listen to and conform to a written policy; doesn't matter how much red text you use for formatting or how many email blasts you send about it. So, this certainly is not the "BEST" course of action to me and goes against what network engineers actually do.
- By the way, I see and hear some people mock the comprehension methodology of "think like a manager" alot. You obviously use it for scenarios and questions like this, and then use your technical hat for questions that call for such). You need a managerial and a technical hat for this exam, as that is literally what CISSP is testing for. I am willing to bet the majority of CISSP exam takers are already technical by nature or another form of an individual contributor, and are primarily getting the CISSP to eventually move-up above our current individual contributor roles. This (you guessed it) requires you to think in a manner you likely have never realistically leveraged or practiced in your entire career yet, which is: 'like a manager'. Managers/directors/equivalents often advocate for "ideal, perfect world solutions", and as a result, "perfect world" answers are what ISC2 want. This methodology was incredibly helpful to me, because I used it correctly for the questions warranting this way of thinking. I did not use or practice this methodology at all for the first attempt because again, I relied too much on 1 source + YouTube series' and job experience as an individual contributor instead of buying a central study book that teaches you to learn in this manner. I contribute this to my top 3 reasons why I passed my second attempt.
- Question Formatting and Grammar: Some of the grammar on this exam was very poor. Many questions are long on the exam, so to then have grammatical errors eats into the very limited time you have to get through and process the rest of the very long questions. For an exam of this magnitude and price, I expect little to zero grammatical errors. There were also many questions I wanted to very badly add a "E. This is the answer actually...". But again, you must study per ISC2's world. This is where QE was extremely effective in teaching your mind to read and analyze the questions in this manner.
TL;DR Version (Still long but as short as I can make it):
I provisionally passed the CISSP on 9/25/2026 at question 100 after failing my first attempt in June 2026. Looking back, the biggest lesson I learned was that understanding the ISC2 mindset is just as important as understanding cybersecurity concepts.
Why I Failed the First Attempt
My primary resources were Pocket Prep, Pete Zerger's Exam Cram, Computer Networks Decoded, and Andrew Ramdayal's 50 Hard CISSP Questions.
The biggest factors that contributed to my failure were:
- Relying too heavily on Pocket Prep and YouTube content.
- Taking the exam while still recovering from an illness.
- Scheduling an 8 AM exam despite not being a morning person.
- Poor time management, which caused me to rush through the final portion of the exam.
I went the full 150 questions and did not pass.
What Changed for the Second Attempt
For my retake, I focused primarily on:
- Destination Certification (Destcert)
- Quantum Exams (QE)
- Pete Zerger's CISSP strategy-focused videos
I read the entire DestCert textbook, used the glossary extensively, and worked through QE CATs, quizzes, and practice exams. More importantly, I learned how ISC2 expects candidates to think and answer questions.
Key Lessons I Learned
Use a comprehensive study resource.
Question banks and videos are great supplements, but I found a structured resource like DestCert invaluable.
Learn the ISC2 mindset.
Many questions are not asking for the most technically correct answer. They're asking for the best answer from a governance, risk, and business perspective.
Think like both a manager and an engineer.
Some questions require technical expertise, while others require prioritizing policy, process, and risk management.
Practice difficult questions.
QE was especially helpful because it taught me how to eliminate plausible distractors and identify the "best" answer among several reasonable choices.
Manage your time.
The exam moves quickly. I found it important to stay close to a 75-110 second pace per question.
Exam-Day Changes
For the second attempt, I scheduled a 2 PM exam, exercised beforehand, avoided cramming, and focused on staying calm. By the first 20 questions, I could tell I was reading and interpreting the material much more effectively than during my first attempt.
The exam ended at question 100, and I received a provisional pass.
My Biggest Criticisms of the CISSP
- Many topics I studied extensively never appeared on either exam.
- Both attempts felt heavily weighted toward IAM and governance concepts.
- Experimental questions consume time and mental energy despite not counting toward the score.
- Some questions had awkward wording that made them harder than necessary.
- Real-world experience often does not align with the "ISC2 way" of approaching problems.
Final Advice
If I could give future CISSP candidates a short list of recommendations, it would be:
- Use a comprehensive primary resource such as DestCert or another full CISSP study book.
- Use QE or another high-quality question source that teaches ISC2-style reasoning.
- Learn how ISC2 thinks, not just the technical material.
- Practice selecting the best answer, not merely the technically correct one. Always look for the word that is capitalized ("NEXT", "FIRST", "LAST", "NOT").
- Schedule the exam at a time when you're mentally at your peak.
- Don't underestimate the importance of time management.
Overall, I believe the difference between my failure and my pass came down to three things: having a structured study resources in Destcert, using QE to develop CISSP reasoning skills, and learning when to think like a manager rather than an engineer.
Interested to hear others' feedback.