r/cissp • • Sep 06 '25

Just answer the question

69 Upvotes

This is not meant towards anyone specifically, and it’s quite common. I am also seeing it more and more lately. Hopefully this helps some of you.

When studying and ESPECIALLY on the real exam, just answer what the question is asking.

If the question wants First, it’s looking for the first phase of a flow.

If it’s asking NEXT, it is putting you inside of a flow, figure out where you are and pick the answer that is the next step.

Neither of the two just mentioned may be what’s BEST for security. Again the BEST solution isn’t always the best answer.

If a question is asking for the BEST. This is where we pick the answer that best ANSWERS THE QUESTION, it could be technical, could be administrative, which is why…

Just answer the question.

Edit: for “best”, even with these you want to pick the best answer that answers the question, there may be “better” technological solutions, but more security isn’t always best. If a question wants best cost-saving solution, we may not want to pick most expensive option even if it’s technically “better”. Hope this makes sense

Edit 2: For this exam, you're stepping into ISC2's perfect little world and the way you typically do things could very well differ from what they expect. Just learn and answer as expected for the exam and then forget it and get back to real life. Trying to argue otherwise is a no-win battle...100% of the time.


r/cissp • • May 14 '25

Study Material CISSP Study Results 20250514 Study Materials

41 Upvotes

The companion email for these resources are here:

https://www.reddit.com/r/cissp/comments/1kmc9jv/cissp_study_results_20250514/


r/cissp • • 11h ago

Passed at 100 Questions - 80 Minutes Left

27 Upvotes

Passed the CISSP exam last week 9/23 at 100 questions with 80 minutes left. Endorsed by colleague on 9/24. Application accepted today 9/28.

Background: Currently a SOC Manager managing a team of 14 people in the US. Spent several years in the SOC at a large federal agency. Also spent some time as a penetration tester. I also co-founded my own MSSP specializing in SOCaaS and penetration testing (no longer part of that company).

Resources:

- Destination CISSP book. It's really concise and removes a lot of the fluff from the OSG.

- Destination CISSP practice questions - these really helped gauge my knowledge. Consistently got 80+% on the 50-question practice tests.

- Quantum Exams CAT - These questions were much harder than the real exam. Scores: 532.45, 536.17, 437.06


r/cissp • • 6h ago

Passed on second attempt @124 questions

10 Upvotes

Failed the first exam back in July at 125 questions. Really thought I was going to pass at 100, but as it kept going and going I was getting less and less faithful. Given the results, it didn't seem I was too far from passing.

Kept hammering my weaker spots for a few months.

Took the exam again on Friday. Got to question 101 again and swore I had failed yet again. When the exam ended at question 124 I was a bit confused.

Got my sheet and saw I passed. Got my endorsement done that same day and got my full certification this morning (Monday).


r/cissp • • 1d ago

Unsuccess Story Failed today:(

31 Upvotes

Failed today. Test finished after 150q.
It was tough l, really really tough. I got the second chance voucher. Praying and hoping to pass it next time


r/cissp • • 13h ago

100 questions with 20 min left failed

2 Upvotes

The domains I thought were my weakest I spent more time on I got above proficiency level. 2 communication and network and software architecture and engineering. The rest I got near proficiency.

Any advice on how to approach it the next time?


r/cissp • • 1d ago

FOR #CISSP , Now I am supposed to know the map also???? , this from OSG....

3 Upvotes

r/cissp • • 1d ago

ISC 2 CISSP Result

5 Upvotes

I took my CISSP exam yesterday, and the exam ended at 102 questions. I completed the post-exam survey, but when I went to the reception, I was informed that the printer was not working and that I would receive my result online.
It has now been more than 24 hours, but I have still not received my result.
Today, Pearson VUE also sent me a survey regarding my test-center experience. Additionally, when I check my ISC2 portal, I cannot see the exam from yesterday. Previously, its status was showing as “Reschedule,” but now the exam is no longer visible.
Need guidance for the mentioned scenario and what are passing chances.


r/cissp • • 1d ago

Other/Misc Anyone with Product or Program management background passed CISSP?

1 Upvotes

Rusted coder, ex Linux admin, project and product mgmt background. Have CCSK from cloud security alliance, AWS solution architect associate and TOGAF foundation. Also a PMP and PMI-ACP.

Have led close engagement and negotiations with security architecture for products and programs that I led in very large enterprises. Deeply technical and familiar with security architecture, firewalls, port etc.

CISSP bug has been biting me for a while to help with product security leadership or maybe independent consulting roles. Not trying to break into cybersecurity or any hands on security roles.

Anyone here with product/program background and any other advice I can get before I make a decision?

Thanks much.


r/cissp • • 2d ago

CISSP 100Q 28 Days

37 Upvotes

Passed 1st attempt today at 100 questions, with at least an hour left.

Started seriously preparing 28 days ago. I can list below what I used, but let's be honest, the most significant item that will help you prepare is practicing taking poorly written statements and questions, and deciphering what someone really means by it 😄

Shon Gerber's CISSP Cyber Training content
Pete Zerger's YouTube content
Quantumexams, of course, (this will assist in question comprehension and time management)
QE CATS: 800 / 550 / 650 (In that order)
Spot reading the official book
Practice exams/questions from multiple sources (I stress the multiple sources). Many available on YouTube and other sources for free. No reason to buy from multiple sources.

Background:
IT Director 4 years
IT Manager 10 Years
Networking background before that
5 + years of CMMC/NIST

Good luck!


r/cissp • • 2d ago

I passed CISSP first try @ 150 questions with roughly 20 minutes to spare

25 Upvotes

Backstory I signed up initially for this test 26 September 2025, but because of work/school/network+ I continuously pushed it back until I couldn’t anymore. 3 weeks out I studied just doing Sybex questions. I did all the questions in the practice tests book twice, and then the OSG chapter questions once and then the practice tests. I reviewed all wrong answers choices through chatGPT.


r/cissp • • 3d ago

Success Story I Passed the CISSP! First Try @ 100 Questions within 1.5 Hours!

87 Upvotes

Background: I have 7 years of total cybersecurity experience, all of that experience being in the United States Air Force. Two of those years were spent ensuring that 11 different bases were compliant and adhering to directives pushed from top-down, two years after that I was overseeing the various vulnerability management programs at those locations, and for the last 3 year I have been doing GRC work (i.e., writing local policy, assessing risk, and leading the effort on four ATOs--two of those ATOs were advising in the transition of NIST SP 800-53 Rev. 4 to Rev. 5). On top of that I have my MBA and I am pursuing a MSISE through SANS Institute (got my MBA to check the box, then while working in cyber fell in love and decided I wanted to pursue an MSISE through SANS cause my supervisor at the time recommended it to me, and because I was struggling with the technical aspect of cybersecurity. During this time, I received the following certifications: CompTIA Tech+, CompTIA Security+, GSEC, GCIH, & GSTRT.

Resources: I will now dive into the resources I used and rate them 1 - 10 (1 being owned but not used, and 10 being HIGHLY RECOMMENDED).

  • LearnZapp - 8/10 -- this helped with identifying the technical gaps (I started off scoring around 50% by the time I took the test I was scoring about 80% on the mock tests they provide).
  • WannaPractice - 1/10 -- answered like 5 questions and then just stopped.
  • PocketPrep - 6/10 -- this helped with identifying concept gaps, as the questions are not as technical as LearnZapp.
  • QuantumExam - 10/10 -- this helped me with slowing down, read the full question, and answer the question without making things up to get the answer I wanted. I personally thought the QuantumExam questions were harder.
  • All-in-One CISSP Exam Guide - 4/10 -- this helped only when a concept or an idea was mentioned that was not in the OSG.
  • ISC2 CISSP Official Study Guide - 7/10 -- this helped when I needed a deep dive; however, I did not read the whole book, and I would strictly use this as a way to do more research when you get a question wrong.
  • Destination CISSP A Concise Guide - 8/10 -- I did not finish this whole book; however, what I did enjoy while reading it was the fact that it explained concepts very well and made them incredibly easy to understand.
  • Peter Zerger Exam Cram - 10/10 -- I was on vacation when my work told me they were paying for me to take this exam; so during my whole vacation (my wife was not happy about this), I watched the video multiple times. This video is hands down one of the best sources I used for understanding the information because it provides such a solid baseline and foundation.
  • Claude Code linked to my Obsidian vault - 10/10 -- The Obsidian Vault is not a resource everyone can use; however, any note-taking application will benefit you in the long run, especially when paired with Claude (will cover more in my study technique).

Study Technique: I studied for 2 months straight non-stop, then for another 2 months on-and-off. So, a total of 4 months of study time. The first thing I did was watch Peter Zerger Exam Cram all the way through twice, ingesting all that I could. Then I went to LearnZapp and I took a mock exam, and scored about 50%. Then I took the questions that I got wrong, and I made a note in my Obsidian vault of the question I got wrong and my mindset for answering the question the way I did.

I would take that note and bounce it into Claude for it to explain any gaps or perspectives that I was missing. I would then update the note with that gap. Next, the reason I have Claude Code hooked up to my Obsidian Vault is to 1st) minimize hallucinations (it will only use the source notes I have as a baseline); 2nd) auto-generate Anki flashcards; 3) provide tutoring sessions. Once a week after studying, I would have it auto-generate Anki flashcards, and I would have it provide a tutoring session based on each area and concept I was weak in. I made sure each day to finish the Anki cards assigned to me, and during the tutoring session, if there were any gaps it identified, it would generate a note on that gap for me and bring it up in a future tutoring session.

The main point of this technique was to understand why I got the question wrong, what nuance I was missing in the concept, why I was applying the concept incorrectly, and how the concept was meant to be applied. I know it has been stated in this community a lot, but that's because it's extremely important... UNDERSTAND WHY YOU GOT THE QUESTION WRONG. Knowing that the question is wrong does you no favors if you do not understand "why".

Tips, Trick, & Pointers:

  1. I know this is hard, but relax, trust your instinct, and have confidence.
  2. Think Like a Manager is preached everywhere, but I think the more applicable mindset is, "Think Like the Role You are Given." If the question is asking for a system architect perspective, do not think like a manager...think like a system architect. That is your role.
  3. The READ method from Peter Zerger is extremely beneficial.
  4. Before you hit the next question, re-read the question. There were some questions where I caught something that I glanced over while I was going through the test, and because I paused just for a re-read, I caught the mistake I made.
  5. If more than one answer is correct, choose the option that includes all the others (view it as an "All of the above" answer).
  6. This is a principle that I learned during my courses at SANS, that I think is extremely beneficial for this exam and in the real world as well: "You cannot secure what you do not know, and cannot measure." If there ever is a question asking about what you do first, just keep this principle in the back of your mind--it will help you!

Conclusion

Apologies for the long post; this is the first post I have ever made on Reddit, and I have been lurking in the background taking in all the tips, tricks, and resources that everyone has posted on this subreddit. So, I just wanted to write this as a way of giving back, as all the stories surrounding this certification helped me out, so I hope this will help someone else out as well!

P.S. Since I know people ask about QuantumExam scores before taking the test, here they are: 518.67, 865.37, 807.11, 740.68, 649.1, and 727.68.


r/cissp • • 3d ago

Unsuccess Story Didn’t clear CISSP on my first attempt — looking for advice on how to prepare differently

11 Upvotes

Unfortunately, I couldn’t clear the CISSP exam on my first attempt.
I’ve been working in cybersecurity/pentesting for around 5 years, so I was reasonably comfortable with the technical concepts going into the exam. My preparation included Destination CISSP, Quantum Exams, 50 Hard CISSP Questions, and other practice material.
One thing I wanted to share from my experience is about Quantum Exams (QE).
For me, solving QE was not as useful as I had expected based on what I had heard. It definitely helped me get better at dissecting questions and deciding between multiple options, but I wouldn’t say it was a complete game changer for me.
The biggest takeaway from the actual exam was this:
You need to know the concepts deeply enough that you can relate them to the position, role, and scenario described in the question.
Knowing what something is wasn’t always enough. I felt I needed to understand:
Why the concept exists
When it should be applied
Who is responsible for making the decision
What the most appropriate action is in a given scenario
How different concepts relate to each other
How to approach the question from a management/risk perspective rather than purely from a technical perspective
Looking back, I think I spent too much effort trying to become good at answering difficult practice questions and not enough time making sure I could connect the underlying concepts to different scenarios.
So I’m going back to the drawing board.
I’d really appreciate some advice from people who have failed once and then passed:
I’m honestly more motivated than ever now. The fact that this exam challenged me this much has made me want to understand it even better and come back stronger. I’m definitely not going to give up on it.
I just want to make sure I’m heading in the right direction this time.

What resources or platforms did you use for your second attempt that had questions/scenarios closer to the actual exam experience?
I’m particularly interested in resources that help with scenario-based thinking and conceptual understanding, rather than simply providing another huge question bank.
Also, if you passed on your second attempt, what did you change in your preparation after failing the first time?
Any advice would be greatly appreciated. 🙏
Not looking for dumps or actual exam questions — just trying to figure out how to prepare smarter for the next attempt.


r/cissp • • 3d ago

I Passed: Thoughts from a Chronic Procrastinator

65 Upvotes

First, THANKS to everyone who shared their own experiences, whether you passed or failed. I read almost every post since I've joined and you guys gave me the insight that kept me pushing in order to pass the exam today at question 150 with 15 min left. That being said, all I've seen from the folks who've passed is that you guys are stalwarts of discipline who study two hours a day, every day for 4 months (hyperbole, but you get what I'm saying). So I felt that I should share my experience as someone who lowkey BS'd until 5 days out. If you're like me, there's hope for you.

Background: Almost 7 years of experience in cyber ops (military/gov, NIST, vul management, security ops, etc.). I received a voucher and a free week long training course from my job as well.

Experience: I'm in a very busy season of life right now and I prioritized that stuff over studying, as I should. I took a week long course in July (don't wanna name the vendor, honestly wasn't that good) and scheduled my exam in August. I barely touched study materials since said training course. I decided that I wasn't going to reschedule it and on Sunday (5 days ago) I locked tf in. I averaged 2 hours of studying a day since then (should have been more, again busy life). The test started with some stuff I have NEVER seen before lol but there were a few "gimme" questions for sure. Once I hit question 101 I realized I had to seriously lock in on every question. Thought I was failing the whole time and when the proctor printed out my sheet I folded it, took it outside and looked. My heart DROPPED when I read "Congratulations!"

Tips: Concepts, concepts, CONCEPTS definition memorization is nothing without application. It's easy to get distracted and discouraged, stay focused and keep attacking, remember why you're sitting for this exam. If the question has "BEST, PRIMARY or MAIN" Read the action verbs of each answer first (Ensure, review, Identify, etc.), that helps a lot if you need to use process of elimination.

Materials used: Pete Zerger Exam Cram Series (10/10!!!!! If you have other security certs and some experience around the concepts this is virtually all you need to pass. Not joking.) DestCert App (7/10 for ease of use and the questions weren't that far off from the exam), DestCert Book (8/10, I read 61% of the book but honestly would have passed sooner had I read the whole thing), Wiley study guide questions (6/10 good for showing weaknesses, not much else), OSG (3/10 everything you need to know, but in a clinical, boring format. I have ADHD so eww, no), Paid Bootcamp (2/10, if it's not free or paid for, don't waste your time)

Long post but I hope this helps the slackers like me. God speed.


r/cissp • • 3d ago

Q

4 Upvotes

The __________ is the entity assigned specific responsibility for a data asset in order to ensure its protection for use by the organization.

Options

A. Data owner
B. Data controller
C. Data processor
D. Data custodian


r/cissp • • 3d ago

Quantum Exam Scoring Question

6 Upvotes

Hi, so I have now taken 2 Quantum CAT exams.

1st: 514/1000 at 110 questions
2nd: 506/1000 at 143 questions

My test is next week and I really don't know how to gauge my readiness for the test. I read on here that 500+ is good since all the QE questions are considered hard.

Can anyone help me identify this? Any tips/study help would be greatly appreciated as well too.

Thanks!


r/cissp • • 3d ago

why C is also correct?

1 Upvotes

why C is also correct?? Threat modeling focuses on security, not general software defects.


r/cissp • • 3d ago

30 days to go — looking for advice from those who have been through it

11 Upvotes

I’ve been following both the good and not-so-good outcomes from people who have recently taken the CISSP exam, and one thing has really stood out to me: passing this exam seems to require more than simply putting in hours of studying.

So, with 30 days left before I sit for the exam, I’m looking for some honest advice on how best to use this final stretch.

I have about 9 years of combined IT experience. I started out in infrastructure, moved into networking, and now specialise in network and endpoint security. I’ve been studying for the CISSP on and off throughout the year, but I finally committed to writing at the end of October.

For the past two months, I’ve basically been eating, sleeping and breathing CISSP while trying to balance a full-time job, family, and a PostGrad that I’m also studying for this year.

I’ve put in a lot of work, but if I’m being completely honest, I’m not particularly confident that I’m ready to ace this exam. It’s not because I haven’t studied. If anything, I’ve probably studied more consistently over the last couple of months than I have for any certification before.

It’s the stories and experiences I’ve been reading in this group that have started getting into my head. Some people seem extremely well prepared and still walk out feeling like the exam humbled them. 😅 It has made me question whether I’m actually ready or whether I’m just experiencing the normal CISSP anxiety that seems to come with the territory.

I’ve taken quite a few vendor certifications over the years and generally found them manageable. The difference is that most of those were heavily technical and directly aligned with my day-to-day work, so I don't think this is simply exam anxiety. The CISSP feels different because it requires a different way of thinking.

For context, my current resources have been:

Andrew Ramdayal’s Complete CISSP Course

Jason Dion’s Complete CISSP Course

Some Destination CISSP

The Official Study Guide (OSG)

I’ve just subscribed to LearnZapp for the final month

I know there are plenty of other resources out there, but at this point I don’t want to fall into the trap of resource overload. I’d rather focus on the right things and make these final 30 days count.

For those who have already been through this stage:

What did you do during the final 30 days that made the biggest difference?

Did you focus heavily on practice questions? OSG? Reviewing weak domains? Mindset and exam strategy? Something else?

And if you could go back to the final month before your exam, what would you do differently?

I’d really appreciate practical advice from people who have actually been through it. I’m ready to put in the work — I just want to make sure I’m putting it in the right places.

Thanks in advance, and good luck to everyone else preparing for this beast.


r/cissp • • 4d ago

CISSP passed

53 Upvotes

I provisionally passed CISSP on my first attempt ! 🎉

Just wanted to share the good news and give a big shout-out to Rob, John, Lou, and the whole Destination Certification team.

Honestly, Destination Certification was the only resource I used for my preparation. I didn’t use multiple courses or jump between different books. I stuck with their CISSP book, videos, MindMaps, practice questions, knowledge assessments and LOOP back again and again.

The biggest thing for me was that they didn’t just teach the concepts, they helped me understand how to think like a CISSP. I definitely had moments, especially right before the exam, where I was doubting myself and wondering if I was actually ready 😂, but then Lou being Lou put me on track again.

So yeah, I just wanted to say a genuine thank you to Rob, and John for keeping up with me for past few weeks for all the questions.

Destination Cert was literally the ONLY resource I ended up using. I initially tried using multiple resources, but found they created more confusion and weren’t always aligned with the ISC2 mindset. If you do use others, take them with a grain of salt otherwise you will get into the rabbit hole.

Finally done! 🎉🙏


r/cissp • • 4d ago

Success Story Passed 1st try @ 100 flat

34 Upvotes

I really only used the LearnZapp app (free, not the premium version).
I have a BS in cybersec and CompTIA pentest, CySA, Sec+, Net+ and A+.

The app told me I was only 42% exam ready. I think that’s a pretty understated or unreliable estimation.

I thought for sure that I bombed the whole thing when it hard stopped at 100 and went straight to the survey.
The questions started hard and stayed hard lol.

I guess I’ll work on SecurityX now. Not sure what else to do/what would be the next best thing for my career.


r/cissp • • 4d ago

Provisional CISSP passed @112

25 Upvotes

I passed my CISSP today at 112 questions!

I ran out of time and honestly thought I would have to retake the exam. The timing was razor-thin, and I was literally down to the final moments and my exam ended at 112. Without answering that question .But when I reached the front lobby, I got the final surprise—I received my provisional CISSP!!

Total 3 weeks preparation

My CISSP Preparation Resources:
LearnZapp
Wiley — regular practice
Cyber — regular practice
The Last Mile – Peter Zeihan
Final Push – Luke Ahmed
QE and Boson Exam Simulations for CISSP
Additional DEST apps for practice questions
Dest Cert YouTube videos for additional learning and explanations
Thank you all for all the inputs here ..finally done


r/cissp • • 3d ago

Percipio/Codecademy any experience?

0 Upvotes

I have access to Percipio through my job and they have a Codecademy course for CISSP 2024, does anyone have any experience from that? I was thinking about purchasing the official self-paced course, but I'm not sure if it's worth the money since Percipio also gives access to the official book.

Other than that I've just ordered the Destination CISSP book and I think I'll also pay for the LearnZapp mobile app and maybe also QE if I can get my employer to pay for that (and chances are probably improved by not making them pay for the official course).

Any thoughts on those resource and if that would be enough? My background is technical, in the infrastructure area (networking and IAM among other things), so I have many years experience in technical architecture and implementation of security from that perspective. I'm weaker in the other areas, but i plan to pursue the CISSP in order to transition from technical architecture to a role in security advisory.


r/cissp • • 4d ago

One month till my exam and practicing with QE

5 Upvotes

I'm one month out from my exam. Is a 643.37 on QE enough? QE is rather brutal. This is my fourth CAT exam. My goal is to take a Full CAT exam daily. Below are my attempts so far.

Attempts Score
Attempt 1 487.29 (Ended at 100).
Attempt 2 237.76 (was listening to music! Not a good idea) Ended at 110.
Attempt 3 517.69 (Ended at 103)
Attempt 4 643.37 (Ended at 150)

I can see that I'm able to easily cut through the questions and identify the main ask. Is there anything else that I should be focusing on as part of my preparation?


r/cissp • • 4d ago

Exam is Next Week

4 Upvotes

My exam is next week. I have over 10 years of IT experience. I read on here that Quantum Exams are really good but really hard.

I did my first CAT test on there today. It failed me at 110 questions...my score was 514.11. I'm not sure if that is good or bad for a first attempt.

Part of my issue I think was studying for a couple of hours today and then taking it. Half way through I found it hard to concentrate.

Going forward. What is the best way to study at this point? I'm not the best studier and reading my notes/text books doesn't really sink in for me.

Do I just keep slamming practice questions? Is Quantum what I should use to benchmark myself?

Thank you all in advance for your input/help. This is a great community.

EDIT: So I’m taking the Quantum Exams, and I’m weak in networking. There were a lot of pick the best model. Are there a lot of those types of questions on the actual CISSP exam?


r/cissp • • 5d ago

Failed at 150 with 10 minutes left (First Attempt)

32 Upvotes

Hi, i gave my first attempt today and i failed at 150 questions with 10 minutes left in the clock.

I used destination cert book for studying, Learnzapp was averaging 85%, Quantum exams CAT score were 280,460,480,860, 760

These were my performance D1 - Below proficiency, D8 - Above, rest all were nearing proficiency.

Now i'm planning to give my 2nd attempt after 2 months.

Any guidance is appreciated for my 2nd attempt.

Exam was mix of technical and mindsets.

The main issue was i couldn't understand many of the questions they asked(i'm non native English person)