Is CISSP as hard as they say?

The amount of studying is definitely a lot but if I cover Thor Pederson Udemy videos and practice test will that be enough?

I have 2 years of experience in cloud security assessment if that helps.

like
Posting as :
works at
You are currently posting as works at

The content itself isn’t very difficult, it’s the way the test is written that’s difficult.

likesmarthelpful

This part

like

Depends on how hard you study. I took a boot camp, read the shon Harris book cover to cover and took like a half dozen practice tests and analyzed each question including why the wrong answers were wrong. Passed it on the first try in the minimum number of questions.

likesmarthelpful

11th hour book is your friend. It is more how it is worded as others said

likehelpful

Caveat: I haven’t read the other comments, so apologies if there’s repetition.
I passed the exam last year in February, I prepped for 3 months.
Here’s what you need to understand- the exam may seem technical, but it’s not. Rule of thumb- read the question and think what a manager would do. You need to respond to questions from a Manager point of view even if your first instinct is to choose the most technically correct option. 80% questions can be answered this way.
Take the Thor P Udemy course. It’s updated to cover the latest format.
Use the CISSP Official test guide for practice questions
And make sure to use the Boson exam simulator. Out of 5 exam simulations, I took two in study mode and 3 in exam mode. Don’t let your confidence shatter if you don’t perform well in the practice test. Just take them so you understand the language of the questions on the actual test.
Remember, the course is a mile wide and an inch deep. Take the Udemy course, make your notes, use the sunflower notes( Google it and you’ll know what I mean) for last minute revision.

The KEY to pass this exam is to read the questions carefully. Read it 2/3 times until you understand it completely. Questions are written to confuse you, so READ THEM CAREFULLY.

Good luck and I’m sure you’ll do well!

like

I've failed it twice so far and am taking it again next week

likehelpful

Bootcamp is OK but does not replace requirement for intense revision. Use the official study-guide practice tests. You’re exam ready at 80%, on all domains. You can get test exam questions on audible. I found those very useful.

I failed twice. I did 2 separate bootcamps and put forward a good study regimen for a good 6 months maybe.

likehelpful

For context I have an English degree and a law degree and here’s what I studied with approximate percentages of how much I think they contributed to me passing.

1. Security Now podcast - 50%
2. One week bootcamp - 15%
3. Self study (all books, nothing online) - 15%
4. Hundreds of practice questions - 20%

like

It’s from a business perspective. Think of saving human life and supporting business and people rather than a straight technical solution. Always think high level business oriented and not in the weeds technical and you will pass. Definitely take practice tests and Kelly Handerhan. She is great at the mindset.

like

So on my side I did the Kelly Handerhan cybrary course (highly recommend) and read 30% of the 11th hour book, that’s it. But I did a lot of practice questions on the cissp app and some on the boson practice test. I think it helped. I studied one hour per day for around 3-4 months. Consistency is key.

I had 3 years of cyber risk experience, and around 5 years of general IT (more technical - think helpdesk and cloud).

The exam was challenging. The CAT format makes it challenging throughout the complete exam. I passed on the first try at 100 questions with only 20 mins to spare. So if I had to go to 150, I would have probably ran out of time. But with consistency, it is definitely achievable.

Think of it as an English exam as well - re-read the questions multiple times. One word may change the best answer.

Read the answers from bottom up.
And it’s a known tip, but think like a CISO/a manager. Think long term.

The endorsement process took around 3 weeks. I had an endorser.

like

This

like

Not for me.
You need to understand what isc2 is looking for, otherwise you will always pick the wrong answer.

likesmart

Yes.
Specifically, what isc2 wants may not actually be the best (or even viable) answer. This is different from a math test where there is a clean right answer.
For example, isc2 will always prioritize human life before security, so if there is a control that is better for security but worst for safety (doors that fail close), isc2 would not want it(they want a door that fails open), even if it is technically more secure.
They also like solutions that are extreme but not viable. For example, to secure a building, isc2 wants to use a man trap instead of cameras. A mantrap is obviously not going to work for high traffic area, but it's more secured and that's why isc2 wants it.
They also almost always favor physical controls. If there's a answer that uses a physical control, it's likely the correct answer.
They also don't like it when you do technical stuff. The answer is never the hands on approach.

likesmarthelpful

I don’t think it was hard - just remember, think like a CEO. Base all your questions on that mindset. I took a bootcamp for a week and studied for another week and took it.

like

Just remember that your role when answering CISSP questions is a "risk advisor" not a technical implementer.

like

I studied for about 4 weeks with the following:
1 - Training Camp Bootcamp. This was super helpful
2 - Official Study Guide. Read, take the end of chapter quizzes, focus on what you're missing
3 - Boson practice exams. REALLY read the explanations. I only took each practice exam once so I wasn't memorizing answers.

Do you have experience in other domains? If not, be sure that you actually qualify for the CISSP years of experience. Otherwise, you'll be an Associate of ISC(2) instead of a CISSP after passing the exam.

Didn’t find it difficult, it is just a lot of content and you should do the practice exams to get better at analyzing the questions.

I was a uni graduate from polisci with no cyber or it background, did the 11th hour book for about two weeks, failed once then succeeded the second time.

Related Posts

First year (ug level hire) and got email from apple recruiter. Would love to exit to FAANG but not sure I'm ready to leave BCG in my first year but maybe after 2-4. What is best practice?

like

Any good recommended books on how to build a scalable product and team? I'm looking for recommendations for two areas: 1) in general laying the groundwork in a startup to have the tools and especially processes in place to scale, and 2) tactical focus on building a SaaS project. I've been promoted into a management role from Dev roots, so need to learn more PM processes to be an effective manager in day job, plus would like to start building my own SaaS solution.

like

What level Azure certification do recruiters start to express interest in? Administrator? Dev? Anything more advanced than fundamentals?

like

Have any of you transitioned from a software consulting role to a product owner role? What was that transition like?

like

Hi everyone, I've been working in Data Migration for the past 2 years and now I want to make a switch as a Java Developer. I am looking for a Mentor who could guide me to the right path so if anyone is interested in mentoring please let me know. Would appreciate some help and guidance. Thank you.

like

Is it worth it to go back to school for a better track to a FAANG company? The division I’m currently in seems like there are no good opportunities, and I have the funds available to finish my undergraduate full time (Canada). I applied to Amazon before for a highly senior position and made it to final interview so I think I would have a better chance for a new grad type role.

like

How hard is a career pivot from digital advertising to a product manager or even developer? I’m learning python 🐍 and at the point where I’m working on a pretty advanced project. I think having technical skills in combination with digital marketing can increase my net worth in the long run .

like

Is there special experience or knowledge you'd need to be effective at a GCD level in Pharma? Or is it like any other account, just different products? I'm considering making the switch from general market advertising.

like

I’ve been reading a lot of FIRE books lately and want somewhere to discuss. What are the biggest takeaways from your FIRE journey/ research?

like

I’m a designer in the planning/landscape architecture dept. of a CE firm. Extremely frustrated that after 4+ years and multiple asks, I’m not getting the in-field construction experience I’ve asked for. I know that my designs could be better if I could see how things are actually built but I get slapped in the face with “I need you in the office designing/drafting” or “there’s no budget to have you go out” and then sends an intern to inspect instead. I’m 5 yrs out of college. Any advice?

like

How Much Increment can one expect when getting promoted from ITA to Assistant Consultant in TCS ?
Also how many years do we need to stay in ITA role to be eligible for Assistant Consultant Position ?

like

Are the recent economic troubles translating to slower hiring or lower salaries in life sciences industry? I want to transition to industry this year but am worried it may not be the best time to.

like

Currently working as radiology access specialist that is a regular 10 to 6 Monday through Friday. I want to branch out to remote position in healthcare I have about 3 years of working administrative part of healthcare. This will be a second job in a sense. Does anyone have any ideas ?

like

I want to get middle school cert (for ELA) My degree is K-8. My current cert. & EdTPA is K-5. What's the quickest & easiest path to middle school certification?! (I'm in TN, specifically Sumner Co.)

like

Corporate ➡️ tech transactions/commercial. Anyone done the transition? Any advice for how to best position yourself to make the jump, either by laterling to a new firm or jumping practice groups within the same firm?

like

Is it possible to transfer from Risk Assurance to Tax as a senior and keep your title? I have my CPA and one year exp in audit and tax

like

Audit > FDD > t15 MBA > BB IB

Thoughts?

like

Can anybody please tell me What is the hierarchy level in eli lilly. Recently Received an offer for Associate consultant position

ZS 🐠 - can you receive sponsorship for MBA prior to having tenure of 3 years? If not, what is the downside of applying after 1 or 2 years? I am coming in with 3+ YOE in consulting, so my application would be competitive for next fall (or ‘23)

like

Pros and cons on getting a designation? Been considering going for the CPCU designation to gain some professional development. Which designation did you go for and why?

like

More Posts

Any book recommendations on change management?

like

Coming from ACN, senior analyst, 3yrs total experience so far & wanting to get into the data analytics/BI work. Currently have had experience working with SQL developer, OBIEE/OBIA, Teradata in ERP and Healthcare projects. I also have my AWS Cloud Practitioner Cert, hoping to eventually get the Data Analytics Cert later. What are my chances of finding a role with another company that'll let me work in BI/data analytics and build up my skill at the same time? Been thinking of leaving ACN.

like
like

Recommendations on slim fit denim shirts. Not for the office of course but I feel like it’s a staple I need in my wardrobe.

Risk Senior Manager here mostly focused on Sox but some M&A. How do I move to PE?

Got this beauty today. Patience was totally worth it!

Post Photo
like

Left a career in banking for consulting. Ended up working on M&A post merger/Documentation as I’ve experience in the field. Life is funny.

like

Bounce tomorrow/Tuesday then going short with oct expirations

like

The past two days I’ve spent to my entire day doing things that really can be done by a paralegal. So I hired a freelance para. Any tips to make this a success? What’s your tips to train and get your para up to speed?

like

Happy Saturday!
9/17 Check-In: What’s everyone up to today?

I am on my way to my HIIT class.

like
like

As a chemical engineer, I have a lot of job opportunities, but as a recent graduate, I have had a hard time getting my first job. After my internship, I have only had 3 interviews. Does anyone know about any job bank for chemical engineers?

like

Hi! Have any here gone the natural cycle IVF route? What was your experience like? Did you have success in growing your family this way? Would you recommend it to others?

like

Can someone please help me get a referral at Goldman?

I joined on Nov 2020 in EY GDS as Senior 1,so when I will be getting progression for senior 2?

like

Hi! Does anyone know what kind of knowledge is needed to crack the Data Scientist interview at Google?

I'm currently working in Marketing Analytics (primarily using SQL and a bit of pyspark). Apart from mastering SQL, I wanted to know from people working at Google what does it take to get there as a Data Scientist? (I'm very interested in Strategy Ops)

I plan to another 6-8 months in preparation and upskilling myself before I even apply.
Any help and guidance is appreciated! Thanks :)

like

Can one make a transition from salesforce to SAP functional consulting.If yes then how and will it be helpful in long run.

like

Hi People, I am interested in a role at Oracle Canada. I have a couple of years of experience in that role. Can anyone please provide me with a referral?
Oracle

like

Any thoughts on Phillips Lytle? If you could please provide insight on culture/billable requirements? Thank you.

like

Hyperbolic, yes, but it got a chuckle out of me nevertheless

Post Photo
likefunny

Additional Posts in Cyber Security Bowl

Anyone else at CyberArk Impact this week? Anything exciting going on?

Any tips or tricks for CSX certification?

like

What are some of the hot skills in cyber security which we can acquire?

like

Tell me it’s not true.

Post Photo
funnylike

Would you expense a speeding ticket on your way to an IR?

funnylike

Anyone here able to provide insight into company culture and WLB at SentinelOne? Please share your salary/position as well if you are currently working there or previously did.

like

Any recommended study material for CIPP and/or CIPM (still debating the two)?

We’re hiring across the board at KPMG for cyber / cyber risk work - shoot me a DM if interested. (Pays well!)

likehelpful

Anyone ever heard of or worked for Sygnia?

like

Thinking about getting the AWS Cloud Practitioner certification. Does EY have any amazon resources or training materials that they provide? Any advise from people who have taken it before? Thanks!

like

Any EY PPMD 🐠 willing to chat/connect? Interested in learning more about the cyber practice. I’m a new campus hire in the Hoboken office. Thanks in advance!

like

Accenture or Deloitte for cyber security strategy? Who’s on top?

like

I’m a recent graduate in a cyber analytics consulting role with a traditional business background, is Security+ a must have certification? Would you consider Network+ a critical prerequisite?

Looking for experienced threat intel /CTI folks to help lead a growing team. We have great support from leadership and the right focus, tooling, and culture.

like

Privacy fish - Anyone taken the CIPM and can share what the exam is like?

Content outline seems like application of standard consulting approach, so how do they test it on an exam?

Thinking of moving from Big4 cyber to Accenture cyber. Any major differences (other than no channel restrictions).

like

Does Krebs have any credibility left?

like

Message me if you need a referral to PwC cybersecurity, financial crimes, or regulations. Please no noobs. Only experienced professionals with at least 1 YOE

likefunny

Any thoughts on the CISM certification?

like

Anyone working in Pharma industry?

like

New to Fishbowl?

Download the Fishbowl app to
unlock all discussions on Fishbowl.
That was just a preview…
Sign Up to see all discussions
  • Discover what it’s like to work at companies from real professionals
  • Get candid advice from people in your field in a safe space
  • Chat and network with other professionals in your field
Sign up in seconds to unlock all discussions on Fishbowl.

Already a user?
Login here

Share

Embed this post

Copy and paste embed code on your site

Preview

Download the
Fishbowl app

See what’s happening in your industry
from the palm of your hand.

A phone with Fishbowl app

Scan your QR code to download
Fishbowl app on your mobile

Download app

Sign up for free to view this conversation on Fishbowl

By continuing you agree to Terms of Use and Privacy Policy

Already have an account? Log in

Sign up for free to continue using Fishbowl

By continuing you agree to Terms of Use(New) and Privacy Policy(New)
Messaging rates may apply

Already have an account? Log in

For account settings, visit Fishbowl on Desktop Browser or

General

Legal