What is the CISSP Exam like?
The CISSP exam is long, with 250 questions. Although I am a fast test taker, it still took me nearly three hours to complete. This is because many of the questions required a fair amount of critical thinking and judgment calls.
CISSP Test Prep and Study Plan
There are a lot of resources available to study for the CISSP exam, and now that the exam has come and gone, I realize many were not all that helpful. If I were to do it all over, I would distill down my study materials to only a few key items. The Sybex CISSP Official Study Guide
The Sybex CISSP official study guide is thick and long, but very readable. I liked the study guide because it offered a lot of real-world context to the subject matter and helped me understand the big picture of how a certain subject fits into the overall realm of Information Security. This was extremely helpful for subject matters and domains I had no previous professional experience with. The book is also very reasonably priced, and Sybex offers a free digital copy, an online test bank, and online flashcards to accompany it, making it a no-brainer to purchase. CCCure Quiz Engine for CISSP
The CCCure CISSP Quiz Engine site is deceptive. The website is dated and it has a spammy URL (FreePracticeTests.org, when there is in fact nothing free about the site), but the content is great for directing your CISSP study efforts. The reason the site is so useful is that many of the questions promote additional study through the explanations. My only serious criticism is that some of the material appears to be dated and over represented in the practice tests, only to never show up a single time in my mix of CISSP questions ( I’m looking at you TCSEC…), but I have no problem stating that I would not have passed the CISSP without it! My approach was to start in ‘Study Mode’, tackling questions from all domains on the hardest question setting and practicing 50 questions at a time until I discovered my weak areas. Then, I started directing my study efforts to specific domains where I was weaker and supplemented my weak areas with reading the CISSP study guide. I studied until I consistently scored above 80% in each respective domain. On average, I completed at least 50 questions a day, five days a week for three months until I decided to sit for the exam. CISSP Crib Sheet I found a few different CISSP crib sheets floating around in various forums. I settled on one by Maaren de Frankrjiker and used it to keep me fresh on key concepts. Maaren’s summary aligns to the old CBK Domains, but is still completely relevant. The CISSP Summary by Maaren de Frankrjiker, CISSP and revised by Christian Reina, CISSP can be downloaded directly here.
Conclusion
The CISSP is a challenging exam, definitely more so than the CISA. However, with the right study materials and work ethic, I feel the exam is reasonable and attainable. Passing the CISSP will not make you a Cyber Security expert or really an expert of anything. Instead, I view the exam as a great foundation and launching point for thinking more critically about Information Security. I learned a ton during my studies, and it has already enhanced my performance on IT security audit engagements! Good luck, and leave additional questions in the comments.
Christian Hyatt
Like our content? Subscribe and stay informed.
Related posts
Tags
- Access Control (3)
- Amazon (1)
- Artificial Intelligence (3)
- Assessment (1)
- Attack Surface (2)
- Attack Surface Management (3)
- Attestation (1)
- Audit (1)
- Awareness Week (3)
- AWS (2)
- Backup And Recovery (1)
- BCAW (4)
- BCMS (1)
- Blackbasta (1)
- Business (16)
- Business Continuity (6)
- Business Continuity Planning (2)
- Caas (1)
- Certification (1)
- Christian Hyatt (19)
- CI (1)
- CISO (8)
- CISO Discussions (24)
- Cloud (1)
- CMMC (1)
- Competitive (1)
- Compliance (17)
- Compliance As A Service (5)
- COVID (1)
- Cyber Risk (6)
- Cyber Risk Management (59)
- Cyber Security Law (2)
- Cybersecurity (26)
- Cybersecurity Controls (4)
- Disaster Recovery (5)
- Engineers (1)
- Ethical Hacking (1)
- EU AI Act (3)
- Exercises (1)
- GDPR (4)
- GRC Tool (6)
- Grit (1)
- Hacking (3)
- Hashcat (1)
- HITRUST (16)
- IaaS (1)
- Information Security (11)
- Internal Audit (2)
- ISO (3)
- ISO 22301 (1)
- ISO 27001 (18)
- ISO 27001 Compliance (19)
- ISO 27018 (1)
- ISO 27701 (2)
- ISO 42001 (6)
- ISO 42005 (1)
- IT Audit (9)
- IT Audit And Compliance (33)
- Kahoot (1)
- Leadership (6)
- Management (1)
- Network Security (4)
- News (5)
- News And Events (20)
- NIST 800 Series (2)
- NIST 800-171 (1)
- OSINT (1)
- Outsourced Pci (1)
- P2pe (1)
- Passwords (3)
- PCI DSS (13)
- Penetration Test (7)
- Penetration Testing (31)
- Pentest Report (1)
- Phishing (1)
- PIA (1)
- Press Release (3)
- Privacy (8)
- Privacy Compliance (7)
- Privacy Impact Assessment (1)
- Privacy Shield (1)
- Ransomeware (1)
- Regulatory Compliance (12)
- Report (2)
- Risk Assessment (5)
- Risk Management (19)
- SDLC (2)
- Security (22)
- Security Advisory (1)
- SOC 2 (18)
- SOC Reporting (23)
- Soc2 (1)
- Strategy (1)
- System Backdoor (1)
- Tabletop (1)
- Training (5)
- VCISO (7)
- Vendor Management (2)
- Vulnerability Management (2)
- Vulnerability Scan (1)
- Wannacry (1)
- Webinars (9)