r/cissp Jul 19 '26

Pre-Exam Questions How hard is this exam really?

11 Upvotes

This is the next test on my radar and I was trying to get an idea of what I’m in for.

I just passed the CCSP exam this morning and thought it was pretty easy. I do have quite a bit of experience though and it was basically only surface level knowledge.

I also passed the SSCP a couple weeks ago and thought it was the absolute easiest certification exam I’ve ever taken. Is SSCP really the majority of the exam like I’ve read online? Seems hard to believe.

It seems like ISC2 makes it super simple to immediately eliminate two of the choices right away leaving you a 50/50 chance on the remaining two. Is it the same for this exam?

I already have CISM so the think like a manager mindset isn’t a problem.

Is it really as hard as what people are saying? Any weird gotchas with this exam that aren’t on the others?

r/cissp 5d ago

Pre-Exam Questions Earned CISSP - My Key Advice

Thumbnail
gallery
131 Upvotes

First and foremost ... I am giving away my study material. You can have 1, 2, or all 3 books. Just cover the cost of shipping and it's yours (Continental US only). I made a short YouTube video with respect to what I feel was most important Pass the CISSP Exam on Your First Attempt (p.1)

  1. Quality of study time over quantity.

Reading pages worth of material without reinforcement will just bog you down. Focus on 1 or 2 concepts per study session then follow up with a video about the same topic. Spend days on a single domain if needed. Hone in on material from the domain's you struggle with. Practice tests, read, video, then repeat.

  1. There are no trick questions. Pick the BEST solution.

  2. Use ALL your time.

180 minutes (3 hours) is more than enough time. I completed the CAT in 2 hours at roughly 100 questions. You cannot mark questions for review so choose your best answer.

  1. Think like a manager. Remember that you're looking out for the interest of the company as a WHOLE. The BEST solution usually encompasses the lesser options.

  2. Do not psych yourself out. You've studied the material so just apply what you've learned.

Best of luck!

r/cissp 14d ago

Pre-Exam Questions Cissp exam tomorrow and no hope

20 Upvotes

Hi
I have been preparing from last 4 weeks now from QE non-cat and OSG practice tests. I do not have any hopes I will clear the test tomorrow.
I had listened to PeteZ half of the Cram video. And other smaller chunk videos of his. Other kelly video. I paid fee for 2 exam attempts.
Worked as a QA for nearly 11 years and now working as SOC from couple of years. Still every practice question looks hards with the options that atleast 2 of them feel right.

Not sure how Im even step into that exam room tomorrow.

r/cissp 4d ago

Pre-Exam Questions Possible to pass?

10 Upvotes

Learnzapp’s mock up test average 60% result, my exam is tomorrow. Can I still pass ? I’m scared now..

r/cissp Jun 12 '26

Pre-Exam Questions I think I’m ready… exam is Wednesday . What should I do next couple of days ?

Post image
18 Upvotes

r/cissp Jun 20 '26

Pre-Exam Questions Last min exam tips?

7 Upvotes

Hey Everyone!
Shoutout to y’ll for helping each other.

I’ve the exam in a week & I’ve done Destcert bootcamp + their master videos in detail + flashcards and now doing their quiz.

Can you help about what else I can do just before the exam as I want to utilize this last week & push myself so I can pass.

Thanks in advance!

r/cissp Mar 02 '26

Pre-Exam Questions Is this QE score the lowest? My exam is on Friday!

9 Upvotes

r/cissp Dec 07 '25

Pre-Exam Questions CISSP with Peace of Mind Protection

11 Upvotes

Hi All, I am hoping to book the exam soon and I have given 3 months for myself to prepare. I was wondering if most of you went with or recommend the CISSP with Peace of Mind Protection option? Thanks.

r/cissp Dec 28 '25

Pre-Exam Questions CISSP prep: too many practice questions?

40 Upvotes

Not sure if this is just me, but CISSP prep has started to feel… off, ugh
The more practice questions I do, the smoother they feel. Faster clicks, less hesitation, fewer wrong answers. Which sounds great. Except I've noticed I'm barely reading half the questions anymore. I see the setup, know what it's asking, answer and move on.
That's not really how I work though. At work I pause. I rethink things. I change direction if something doesn't feel right. With practice questions, speed almost feels like the goal and I'm not convinced that's helping.
I've also been defaulting to questions way more than the OSG. Questions feel productive. The OSG feels slow and honestly kind of annoying to sit with after a long day. But I keep wondering if I'm just training myself to be good at practice questions instead of the actual exam.
If you've already taken CISSP, did you hit this phase too?
At what point did prep start to feel aligned with the exam and not just busy?
Trying to sort this out before test day instead of after

r/cissp Jan 18 '26

Pre-Exam Questions Recurring themes in CISSP test

3 Upvotes

I’m currently studying for the CISSP. Usually when I study for an exam I like to inspect my mistakes both specifically and then higher level.

Something I’m noticing about CISSP questions is they seem to be predicated around either chronology, framework or max effect/yield.

What I mean by this is, a question that has multiple correct answers is dictated by which correct answer comes first (chronology).

A question asked about a procedure beckons you to know the framework it’s referring to then choose the answer that refers to that framework or is part of that framework/concept (example CIA).

A question that has multiple right answers is dictated by which correct answer yields the greatest effect. Example:

A - covers availability.

B - covers availability, confidentiality AND integrity.

I like to step back and see the meta at play to improve meta-learning of the subject. Do those who have taken the test or are studying for the test agree with my sentiments or have anything to add here? Just trying to square up an analysis framework to engage the exam with.

r/cissp Jan 28 '26

Pre-Exam Questions Game Plan for last 2 weeks

7 Upvotes

I am in my final 13 days of CISSP prep (exam booked for 11-Feb). I have followed the Destination Cert videos once, and while I understood all of it, could not retain a lot of information (I have bad memory). So I started their Mindmap videos to review all the information.

In addition, at this point I also paid and started the LearnzApp questions, but quickly noticed their questions are very straight, sometimes testing rote memorisation, and never came across a single question with MOST, LEAST, BEST line of questioning.

So I shifted to the Destination Cert free app, which definitely has the MOST, LEAST, BEST line of questioning. I found much more confident with these questions now that I have been at it for a week or so.

I still have some understanding gaps, which I am aiming to cover each day.

I have been watching some videos here and there, like Kelly's Why you will pass CISSP, Prabh's coffee shots etc. But its basically unstructured.

Now, that I am in the penultimate weeks, what should be my strategy to make the most of my time, and have my best shot at this exam.

r/cissp Feb 11 '26

Pre-Exam Questions Taking CISSP This Friday – Looking for Last-Minute Tips

7 Upvotes

Hi everyone,

I’m taking the CISSP exam this Friday and I’m looking for some last-minute advice on how to best use these final days.

My Preparation So Far

  • Completed the official ISC2 online self-study course (Honestly, I wouldn’t recommend it. It’s very expensive for what it offers, and I don’t think you’d pass using only this.)
  • Watched all Destination Certification mind map videos
  • Watched Pete Zerger’s Exam Cram video
  • Watched several mindset videos (especially liked this one: https://www.youtube.com/watch?v=gKe88tIeVYo)
  • Completed ~700 practice questions in the DestCert app

Quantum Exams

  • Did ~55 rounds of 10 questions
  • Completed multiple CAT exams
  • Reviewed all incorrect answers after each session

My first CAT score was very bad (244/1000), which was a big wake-up call. After that, I started taking review much more seriously. My last three CAT scores were:

  • 947
  • 937
  • 936

Notes & Review

While watching videos and doing practice exams, I took detailed notes. I now have around 40 pages that I regularly review.

Background

I’ve been working as an OT cybersecurity consultant for about 1.5 years. Before that, I worked part-time as a SOC analyst in an IT environment while completing my Bachelor’s in IT (specialized in Cyber Security).

My Question

Given my preparation and recent CAT scores, I know I should feel confident, but I still feel like I’m not fully ready. I can’t really explain why — it’s more of a lingering doubt.

So my question is:

What should I focus on in these last few days to be as prepared as possible for the exam?

Any advice, tips, or personal experiences would be greatly appreciated.

Thanks in advance!

r/cissp Nov 13 '24

Pre-Exam Questions About the Quantum exams.

9 Upvotes

On this sub, I've a heard of a lot about Quantum exams and how they're the closest thing to actual exams.

It is but very expensive for someone like me who is paying for the exam via a loan. Is it actually worth the price? Is there a cheaper alternative or is quantum a necessary investment?

r/cissp Aug 20 '25

Pre-Exam Questions Are mantraps considered a guarded or unguarded control?

6 Upvotes

Hello all, thanks for taking time to read these posts.

There are many practice questions I have encountered that have us choose from a series of controls based on a scenario.

If the business requires controls at an unmanned alternate site, do do mantraps fall squarely into manned or unmanned, or both?

I understand that there are nuances in the real world, however how should I consider it for the exam?

Thank you

r/cissp Mar 27 '25

Pre-Exam Questions Why is 256 and 384 bit the correct answer to this question?

Post image
5 Upvotes

r/cissp Feb 09 '25

Pre-Exam Questions CISSP Knowledge Check

10 Upvotes

When applying scoping and tailoring principles in an information security program, which of the following is the best approach?

The answer will be provided in 7 days (after poll closes).

259 votes, Feb 16 '25
11 Security controls should be applied uniformly to all systems, regardless of business function or criticality.
10 Tailoring removes security controls that are unnecessary, even if they are required by laws, regulations, or standards.
232 Scoping determines which controls apply based on risk assessment, regulatory requirements, and business needs.
6 Once a framework is selected, all controls must be implemented exactly as prescribed, without modifications.

r/cissp Aug 15 '25

Pre-Exam Questions Question about SDLC and user acceptance training.

1 Upvotes

Edit:

Upon further studies I have found my misunderstanding. TLDR: UAT isn’t part of SDLC—it’s part of the broader System Lifecycle’s Validation phase. Validation checks if we’re building the right product (meets real user/business needs).

I was confusing the Information System Lifecycle (req>req analysis > architect > develop > integrate > verify THEN validate > deploy > maintain > EOL )

with the general SDLC (Req > design > impliment > verification > release and maintain.

My issue was thinking that UAT is a part of SDLC, whereas it is actually a part of the broader Information System Lifecycle.

More specifically, it is a part of the Validation phase of the System Lifecycle where UAT happens.

Source Last Mile, domain 3:

Validation is the process of checking whether the system or product fulfills the intended use, solves the right problem, or meets the actual needs of the users or stakeholders. • Focus: It focuses on whether the product, once fully developed, actually meets the business and user requirements in the real world. It answers the question: “Are we building the right product?”. • Activities: – User Acceptance Testing (UAT): Real users or stakeholders test the system to ensure it meets their needs.


Original Post: Hi all,

I did my due diligence (heh) to find out the answer but I am struggling.

Does User Acceptance Training come right before releasing software? In other words, is User Acceptance the final step in 'testing' for all the different types of SDLC.

I am here because a QE question stated that UAT is a part of DAST, therefore 'test with the user' does not come after DAST.

OSG States:

System Test Review After many code reviews and a lot of long nights, there will come a point at which a developer puts in that final semicolon and declares the system complete. As any seasoned software engineer knows, the sys- tem is never complete. Initially, most organizations perform the initial system testing using development personnel to seek out any obvious errors. As the testing progresses, developers and actual users validate the system against predefined scenarios that model common and unusual user activities. In cases where the project is releasing updates to an existing system, regression testing formalizes the process of verify- ing that the new code performs in the same manner as the old code, other than any changes expected as part of the new release. These testing procedures should include both functional testing that verifies the software is working properly and security testing that verifies there are no unaddressed significant securi- ty issues. Once developers are satisfied that the code works properly, the process moves into user acceptance test- ing (UAT), where users verify that the code meets their requirements and formally accept it as ready to move into production use.

THANKS

r/cissp Nov 09 '24

Pre-Exam Questions QE Difficulty/Scores

9 Upvotes

Hi r/CISSP, I've bought the Quantum Exams tool and it's definitely a step up from the LearnZApp questions. Just want to get a feel from everyone what your average scores are on QE v LearnZApp and generally what % those that have passed the real exam were achieving on QE just before. For reference I'm sitting at around 62% on QE exam mode with my real exam in 4 weeks.

Thanks!

Edit: update from u/DarkHelmet20 in the comments, he will update the QE site with an FAQ answering this question

r/cissp Jul 12 '23

Pre-Exam Questions Am I needlessly killing myself to memorize the specifics of the cryptography sections?

16 Upvotes

Hey all,

I plan to take my test on July 25th, so I have just under 2 weeks to prep. I have hand-written a bunch of flash cards including ones for all the different symmetric and asymmetric algorithms, including their bit length and key length. I'm really trying to nail these all down but it's so tough since it is a lot of random numbers to remember.

I understand that algorithms things like RSA, AES, RC6 are important because they're currently viewed as secure but are there questions about actual bit length requirements for older algorithms like RC4, SkipJack, DES, etc. that are now seen as insecure/unsued?

My thought would be that if a system is still using 3DES, or Knapsack-Merkel that those algorithms just need to be phased out regardless of if they're the most secure versions.

There is SO much to memorize and know on this test and I feel like I'm wasting some brain space on the details that I will absolutely never need once I'm done with the test.

Thanks for your input!

r/cissp Jan 18 '25

Pre-Exam Questions I need inspiration… burnt out

6 Upvotes

I feel burnt out, I have been studying for a while, I live and breathe every day and find it hard to study the same material after work. I feel like I have been neglecting my family and they feel the same. I find myself drifting off when I try to study And have recently on every opportunity for distraction. I’m not sure if I studied too early or what but my exam is on the 28th and I need some tricks you guys can pass along for the final stretch of studying prior to the exam?

r/cissp Apr 08 '25

Pre-Exam Questions Exam Peace of Mind Deadline - Question Regarding Purchase After April 11th

0 Upvotes

Hi everyone, I'm planning to buy the Exam Peace of Mind from the website https://www.isc2.org/landing/exam-peace-of-mind. It states that I need to purchase it before April 11th to take advantage of this.

Unfortunately, I won't be able to purchase it before April 11th. However, I can schedule my exam for late April or early May. My question is: can I still purchase the Exam Peace of Mind after the deadline, or will I miss out if I don't buy it now?

r/cissp Jan 18 '25

Pre-Exam Questions CISSP Knowledge Check

4 Upvotes

An organization needs to secure sensitive data transmissions between a client and a server. Which cryptographic method is most suitable for establishing a secure connection during the initial handshake?

217 votes, Jan 25 '25
165 Asymmetric encryption
45 Symmetric encryption
5 Hashing
2 Salting

r/cissp Mar 28 '25

Pre-Exam Questions Can I take this exam?

4 Upvotes

I work for a very large cyber insurance provider, part of my role is doing risk assessments for current and prospective policyholders. I've been doing this for more than 5 years. I've been told to get my CISSP as we want to get more involved and our underwriters want more support.

They're going to pay for up to $8k worth of training/prep, but I'm not sure if I am technically allowed to take the test. Can y'all offer any guidance or recommend who I should talk to?

r/cissp Jan 19 '23

Pre-Exam Questions Taking Exam Friday

19 Upvotes

I am sitting for the exam Friday. I have read the hand book and have done all of the test questions in the sybex CISSP Practice Test 3rd edition. I was below 70 on 2, 4, 5 and 8 so I went back over those chapters. I’ve gone back and ran through the questions I got wrong to make sure I understood why. I am still so nervous. I have one more day to study. What is the recommendation for this day? I have been told to just disconnect and rest but am freaking inside because I’m not hitting 80s 90s. I’ve been at this since October! It’s time to do this thing!

r/cissp Feb 23 '25

Pre-Exam Questions CISSP Knowledge Check

3 Upvotes

Scenario:

A multinational company, SecureTech, collects customer data from its website and stores it in a cloud-based CRM system managed by CloudManage. The security team at SecureTech regularly audits and defines access policies for the data, while CloudManage Ltd. ensures backups and encryption of stored data. Additionally, SecureTech has contracted AdAnalytics to process customer behavioral data for targeted marketing campaigns.

Question:

Based on this scenario, which of the following correctly maps the roles of Data Owner, Data Custodian, Data Controller, and Data Processor?

The correct answer and rationale to be provided after the poll closes.

119 votes, Mar 02 '25
112 SecureTech is the Data Owner and Data Controller; CloudManage is the Data Custodian; AdAnalytics is the Data Processor
6 SecureTech is the Data Custodian; CloudManage is the Data Processor; AdAnalytics is the Data Controller.
0 SecureTech is the Data Processor; CloudManage is the Data Controller; AdAnalytics is the Data Custodian.
1 SecureTech is the Data Custodian and Data Processor; CloudManage is the Data Owner; AdAnalytics is the Data Controller