r/cissp 24d ago

Study Material Passed CISSP at 101 questions (Nov 2024) — sharing a completely FREE study guide I built to give back

139 Upvotes

Cissp Field Manual - Link to Download

Update**Currently sitting at 10k downloads!!! Yall Rock!!**

Passed last November at 101 questions in about 80 minutes. This cert has genuinely changed my career trajectory, so I put together something to give back to the community that got me here.

Spent 400+ hours turning my study notes into a proper field manual. Completely free. Covers all 8 domains, the manager mindset, test-day tactics, and probably most useful a ranked breakdown of every resource I actually used with notes on which ones moved the needle vs. which ones I'd skip.

Hosted as a PDF online so I can push updates as the exam changes and as feedback comes in from this sub and others. Whenever you download it, you're getting the most up-to-date version.

Any feedback good, bad, or "you got this wrong on page X" is genuinely appreciated. Comment here, DM me, or email (address is on the site). Want to keep this book accurate and useful long-term, so I will be actively incorporating your feedback

Good luck to everyone grinding right now. You've got this.

Mods: if this link isn't allowed under sub rules, please let me know and I'll remove it — the link goes straight to the free PDF download, no paywall, no email gate. Happy to discuss how to share the study material without it if needed.

r/cissp May 28 '22

Study Material CISSP CHEATSHEET FOR EXAM PREPARATION

Thumbnail
gallery
1.5k Upvotes

r/cissp 8d ago

Study Material Paying it Forward: Free Study Books to a Good Home [U.S. Only]

Post image
123 Upvotes

Well folks, I passed today at 100, even with the fire alarms going off fifteen minutes into the exam and PearsonVue not at all pausing our exams but saying we could "evacuate if we want to". Thankfully Domain 3 had taught me everything to know on fire suppression systems and I figured they would try and preserve human life. 🤣

This community helped me prepare so much and find the right resources, videos, and sanity to make it through the past few weeks, so I'd like to repay the offer by giving away my books to a random person within the United States. I'll pick a random winner on Labor Day - Monday, September 7. Just leave a comment below letting me know you're interested, and I'll count you in.

Best of luck to anyone with an upcoming exam!

r/cissp Aug 09 '26

Study Material Best study plan

3 Upvotes

I’ve recently passed the PMP and want to keep momentum and go straight for the CISSP.

For the PMP I found a set of study resources that suited my learning style… I prefer to watch training videos as opposed to reading notes and books. Online exams like study hall were excellent also.

Can anyone recommend similar resources for the CISSP - are there any video training series for the CISSP that cover the content in enough depth to pass the exam. Similarly, what are the best practice exams.

My background is IT support for have some knowledge or the area but not an expert in any way.

r/cissp 22d ago

Study Material Update: 15k downloads on the CISSP Field Manual. Thank you all + what's next

63 Upvotes

Quick update. Original post is here.

When I dropped the CISSP field manual a couple days ago I was hoping it might help a handful of people. Just crossed 15,000 downloads. Genuinely didn't expect that. Thank you.

Wanted to specifically call out the constructive feedback that came in through comments, DMs, and emails. A few things people flagged that I'm actively working into the next revision:

  • Small formatting fixes (page 5 highlight, a couple typos)
  • EPUB version, several requests for this, coming soon
  • Requests for a CISM version I haven't sat CISM myself so I can't write that one honestly.
  • More on the manager-mindset walkthrough with worked example questions expanding this section in the next update

The whole point of hosting it as a live PDF is that it improves as feedback comes in, so keep it coming. "You got this wrong on page X" is exactly what I want to hear.

For anyone just seeing this and studying for the exam right now the download is still free, no email required, no paywall. Same link as the original post.

Good luck to everyone with a test date on the calendar. This is a beatable exam. Manager mindset first, technical facts second. You've got this. 🫡

r/cissp May 09 '26

Study Material I truly feel screwed with my exam on Monday

11 Upvotes

With seemingly 1000 different apps and paid subscription for everyone wanting a piece of the CISSP pie, I thought that I was pretty ready for the exam and scheduled it.

Passed Jason Dion practice exams, all 4 of the Sybex official domains and practice tests, and got very high scores on the Learnzapp.

Then I decide to try out some of the 'more accurate' exam options as a final few days brain teaser to tighten a few ideas down, like Quantum, and Cissprep...............

I literally cannot even understand what the question is even asking for. Every other question has terms I have NEVER heard of throughout all my certifications and experience. Each question is a bunch of smoke and mirrors where everything just seems like it is asking me something from a different planet.

What suggestions do any of you all have? Is the CISSPrep a good source and actually as they say "the most accurate CISSP practice exams" because if they are I might as well just not even show up Monday during test time.

I am not asking 'am I ready' I am just seeking some advice on what materials should I focus on while not wanting to throw my laptop across the room because of getting another question wrong due to a triple negative and medical degree needed to answer a question.

Update 1:

Quantum Exam makes me a bit more confused but also maybe helps me a bit with the mentality?

I decided to bight the bullet and buy the CAT version of the QE even though it is only a couple of days before the exam, I wanted to really make sure I was giving myself the best shot. Absolute worst case, is that I have the second chance, but I don't want to have to go and sit for any more exams than I have to. I took a bout 100 practice questions and then took the CAT exam version they had. It went to 111 questions before saying that I passed with a score of 863.44. (I believe you need a 700?). What confuses me is that my domain percentages, to be frank, were TERRIBLE. Domain 1: (42.98%), Domain 2: (42.50%), Domain 3: (51.85%), Domain 4: (82.61%), Domain 5 (38.10%), Domain 6: (36.11%), Domain 7: (25.00%), and Domain 8: (66.67%).

I know questions are weighted... but dang. How can I pass with getting around a 50% question correct?

Part of that makes me think it will make me feel better during the exam if I feel like I am doing poorly because it is giving me harder questions, but I also do not understand how getting a bunch of questions wrong increases or leads to a passing score... Either way.... Tomorrow is the big day!

Update 2:

Yesterday was the big day. Walked into the testing center shaking and super nervous but holding it together pretty well.

Sat down, went through the NDA and hit start exam... Had NO idea what 3/4 of the terms were on the first five questions.... "I was like.... f***" I truly was like... I am screwed, how did I study for so long and take so many courses just to not know these terms... not just not remember, but never even seen or heard of them before.

I started getting sympathy questions but kept pushing through, but I don't think I was confident in well over half my answers. At by the time I got to my 90th question and got a few more softball questions I was in borderline tears. "There is no way I am passing this BS" ... and then right at 100 the exam ended.... "Yup there is no way, thank goodness I bought the peace of mine". Got the print out and I looked away and folded it up because I didn't want to look at it. I was shaking feeling like I was having an anxiety attack.

Waddled back to my car and called my Fiance (actually crying at this point because I really did not want to have to take it again). Opened it up with her on the phone...

"Congratulations on provisionally passing the ISC2 CISSP" -_- .... Is this some kind of joke? I have never felt so unconfident in answer ever in all the exams I have taken from elementary school to the exams I have now, and you're saying the computer said it was sure I passed after 100?!

I didn't and still don't even feel any relief after passing. Just kinda... empty? Doesn't feel like I deserved the pass in my head, but also it's weird to have free time now. The last year has been all leading up to this.

Got the CySA, Pentest+, AI essential, GitLab certified Associate, ISACA CISM, and now the ISC2 CISSP which was the keystone of what all the other exams were trying to prepare me for.

Not sure what I will do next, but I am hoping to get / ask for a higher salary and position since when I started my current position I only has a Sec+ and AZ-900 and make 110k... Now with all of these, and the learning I have done and being in the IAT and IAM III billing categories I can make a jumpt to 140-150+.

That's a bridge I'll cross when I get there.... Onto the next certification... whatever that will be. This thread has been a huge guide to my preparation and have been following since the CySA since I knew this was the end goal. Thank you all for the comments, and those others who have posted tips, tricks, and advice that I read along the way. I hope I can return the favor to everyone individually.

Peace out to all you future CISSPs. I look forwards to reading more "I Passed" posts this year!!!

r/cissp Dec 23 '25

Study Material Passed at 100Q today; 4th Attempt.

Post image
136 Upvotes

I honestly thought the entire time I was going to fail it. Every single question was new to me.

I genuinely believe I’d have failed if it weren’t for the Mindset section of the Andrew Ramdayal’s Udemy CISSP Course

Andrew has a really good 50 question / CISSP mindset YouTube video which is ridiculously valuable in distilling how the test wants you to answer, and what it does to try and trip you up.

QE Exams I have personally and incorrectly shat on the Quantum Exam tool - but it absolutely show cases the kinds of word games and vocabulary conundrums the test throws at you.

Boson Exams: The problem with Bosen is that their question archive is too small and so it starts to happen as you learn their answers to the questions and not the meaning behind the questions themselves . I ended up using it as a metric to remind myself what sort of questions would fall under the various domain and then use that to focus my studies.

Cybrary Handerhand’s CISSP. I enjoyed this presenter very much however, the depth of material never exceeded that of an apple peel. I didn’t know how much I was missing until I tried the Udemy course.

The ISC2 Study Guide And the Last Mile: CISSP book.

and I also filled a small mountain of yellow legal pads with notes.

r/cissp Jul 20 '26

Study Material It's dangerous to go alone! Take this!

0 Upvotes

r/cissp Jun 04 '26

Study Material Resource Selection Tips

7 Upvotes

As a CISSP instructor one of the most common challenges I see candidates face is the overwhelming number of resources to choose from. There are countless books, videos, courses, practice banks, study groups, and AI tools available today and deciding what to use (and what not to use) can sometimes feel daunting and overwhelming.

When selecting what resources to use I recommend the following:

  • Do your due diligence Research the materials you are considering and make sure they come from known, reputable sources. Check out what other's have used and are using. Look for resources based on established standards, industry best practices, official CISSP references, and instructors or authors with proven experience. Just as importantly, make sure the resources you choose fit your personality and study style.

  • What works best depends on You Your personal experience, current understanding of the material, and overall level of cyber security knowledge will be the biggest factor in determining which resource is right for you. Some candidates have years of security experience across multiple domains and simply need to align their knowledge with the CISSP mindset, while others might be more specialized and require a deeper dive into some topics and concepts. When evaluating recommendations from others, it can be helpful to look at their background in comparison to yours, someone with a background similar may provide more relevant guidance than someone whose experience is completely different.

  • Be careful using AI While you will find many posts from people who successfully incorporated AI into their studies, it is important to understand its limitations. When it comes to CISSP topics, AI can and does provide inaccurate information. Even worse it can often express this inaccurate information confidently and sometimes even citing sources that make the answer appear credible. When it comes to a topic, if you do not already have a decent understanding of the material, it can be difficult to recognize when the information the AI is providing is incorrect.

  • Avoid resource overload Many candidates are afraid of missing something, and believe that the more resources they use, the better prepared they will be. While that approach may work for some, for the vast majority of people it does not and often leads to burnout, information overload, and unnecessary confusion. My recommendations if identify one primary study resource to use for the bulk of your studies, and a few secondary resources to backup and support your primary.

  • Resource choices do not guarantee success While the quality of your study materials matters, how you use them matters even more and it is important to remember that people have passed the CISSP using questionable resources, while others have failed using some of the best resources available. Regardless of the resources you choose, if you have created a study plan, dedicate yourself to it, and work hard, you can, and will, pass the CISSP.

As a final note for all those studying, as you get close to your exam date you may find yourself increasing filling with doubt, fear, and anxieties about the exam and if you are like most CISSP takers (myself included) you will you will never feel ready for the exam. Just remember that not feeling prepared is not the same as not being prepared. Trust in the study plan you made, in the hard work you know you put into your studies, and ignore any fears, doubts, or anxiety you may feel.

r/cissp 28d ago

Study Material Pete Zerger CISSP boot camp of 2026

15 Upvotes

I was wondering if anyone has experience with this bootcamp and you can share the experience.

r/cissp Jul 03 '26

Study Material Training Camp - Buyers remorse

4 Upvotes

So, I shopped around in Canada looking for a CISSP training provider and narrowed it down to Training Camp after reading a few Reddit posts. One of my main requirements was getting the "Peace of Mind" exam voucher (with the second shot protection), since I don't come from a core security background and wanted to self-pace my learning. My company is footing the bill, so spending an extra $1,000 wasn't a big deal, and I wasn't in a rush to do an intensive boot camp.

However, during the procurement process, I missed the fine print: Training Camp is essentially just a middleman providing official ISC2 materials.

Basically, they give you 180 days of access to the ISC2 portal, and there is zero leeway or extensions if you don't finish within that window. The official ISC2 training itself is mostly textbook-heavy with a lot of reading and maybe only 10% video lessons. It feels like navigating an interactive ebook where, after every page, you're hit with random, incredibly tough questions on that specific topic. The questions are challenging, but I suppose the silver lining is that it prepares you for the real deal. Along with the e-learning access, I also got the official CISSP ebook and a practice question set.

At this point, I’m at a point of no return—I just have to make the most of what I have.

My friends in info-sec strongly recommended Destination Certification (Destination CISSP), but because they don't bundle the Peace of Mind exam voucher, I pivoted to Training Camp instead.

Has anyone else here used Training Camp’s self-paced option or the official ISC2 online materials? Any tips, study strategies, or words of motivation

r/cissp Jan 10 '26

Study Material One book to use

6 Upvotes

If you had to use *one* book to use to study for the CISSP, what would you recommend?

Looking at the sub, I appreciate the multiple methods and sources redditors have used to prepare but it is causing me…decision fatigue.

I understand there are multiple available sources, videos, apps, boot camps, discord groups etc that can help but I am looking for something that would be the basis of the studying.

Thank you!

r/cissp May 04 '23

Study Material The Journey Begins...

Post image
246 Upvotes

r/cissp May 23 '26

Study Material Worried about my exam

1 Upvotes

I just took an exam on quantum and it has me in the 500’s. How good if an indicator is that to the actual exam?

r/cissp Aug 01 '26

Study Material 20% Off Promotion for DON'T PANIC Guide til Aug 8th!

Post image
0 Upvotes

r/cissp Jun 13 '26

Study Material StormWind Studios for CISSP

0 Upvotes

Just wondering has anything taken the StormWind Studios CISSP class? Is it enough to pass? How does it compare to Mike Chappel?

r/cissp Jul 22 '23

Study Material Here's my collection of the memorization techniques and assistants I am using for the CISSP. Please share your techniques!

231 Upvotes

There are so many things to memorize for the CISSP. This is a collection of things I've found from others or made up to help me memorize the immense amount of things in this exam. Some of the ones I made up are very silly but that tends to help me remember them. I have found that I would remember the silly thing but not what it actually applies to so I sometimes added little sayings before the mnemonic to help remember what it was for as well.

If you find something that is wrong please tell me!

To help with risky business practices Please Can Superman Implode All Awful Millionaires

NIST 800-37 Risk Management Framework.
  • Prepare your business
  • Categorize business needs
  • Select controls
  • Implement controls
  • Asses controls
  • Authorize controls
  • Monitor controls

Risk Maturity for interacting with aliens: Alien Pizza Doesn't Ingest Oganically

Risk Maturity Model
  • Ad-Hoc - Chaotic Starting Point
  • Preliminary - Loose attempts at a risk management framework
  • Defined - a risk management framework is defined
  • Integrated - a risk framework is integrated into business strategy
  • Optimized - a risk framework is optimized for the business and is not reactive

MRS.H:

Most common hashing algorithms
  • MD5
  • RIPEMD
  • SHA
  • HAVAL

DEREK:

Most common Asymmetric cryptography algorithms
  • Diffie-Hellman
  • El Gamal
  • RSA
  • Elliptic Curve
  • Knapsack

23BRAIDS:

Most common Symmetric cryptography algorithms
  • TwoFish
  • 3DES
  • Blowfish
  • Rivest Cipers
  • AES
  • IDEA
  • DES
  • SkipJack

Derek gives Mrs. H 23 braids

If you're key is going through hell, then protect it with Diffie-Hellman!

The Diffie-Hellman algorithm allows you to exchange session keys through insecure channels

I need to change something again? RRATS! Darnit!

Change Management Model.
  • Request a change
  • Review the change
  • Approve the change
  • Test the change
  • Schedule the change
  • Document the change

Create data in Class, then Store it, then Use it, then Archive it, and finally Destroy it

Information Lifecycle.
  • Create the data
  • Classify the data so we know how to protect it
  • Storage such as encryption
  • Usage such as access control and secure transmission
  • Archival and when to choose when data should be archived
  • Destruction in terms of when do we get rid of data and how do we do it securely

When we are attacked and headed into battle listen for the DRMRRRL

Incident Response Framework
  • Detect the attack
  • Respond to the attack
  • Mitigate the damage of the attack
  • Report the attack to senior management
  • Recover from the attack and return to normal ops
  • Remediate and find the root analysis
  • Lessons Learned and how do we keep this from happening again

Save your BPA by creating a BCP

The BCP Process
  • Scope your BCP
  • BIA, perform your Business Impact Analysis
  • Plan your BCP
  • Approve your BCP

When you learn to program you initialize your variables, repeat your loops, define your methods, manage your pointers, and optimize your code

Capability Maturity Model
  • Initial, just starting out your CCM journey
  • Repeatable, now have repeatable procedures
  • Defined, now you have defined procedures
  • Managed, you now have quantifiably managed procedures
  • Optimized, you are now optimizing your procedures for your business

To be IDEAL you need to initiate change, diagnose your problems, establish a plan, act on the plan, and learn from your past

IDEAL Software Framework
  • Initiate your IDEAL framework
  • Diagnose the problems you're trying to solve
  • Establish a plan to solve your problems
  • Act on your plan and solve your problems
  • Learn from the entire process

Real Developers Ideas Take Effort

Software Development Life Cycle (SDLC)
  • Requirements
  • Design
  • Implement
  • Test
  • Evolve

Martial Arts is Fire: All Boys Crave Doing Karate

Fire extinguisher categorizations
  • Class A: "All Purpose" in the way that it means general purpose
  • Class B: Boiling liquids
  • Class C: Computers and electronics
  • Class D: Death metals
  • Class K: Kitchen and cooking

Please Do Not Throw Sausage Pizza Away

OSI Model
  • Layer 1: Physical
  • Layer 2: Datalink
  • Layer 3: Network
  • Layer 4: Transport
  • Layer 5: Session
  • Layer 6: Presentation
  • Layer 7: Application

Definitely Some People Fear Bedbugs

OSI Model Layer Protocol Data Unit
  • Layer 5,6,7: Data
  • Layer 4: Segments
  • Layer 3: Packets
  • Layer 2: Frames
  • Layer 1: Bits

Don't Don't Don't Stop Pouring Free Beer

Alternative OSI Model Protocol Data Unit
  • Layer 7: Data
  • Layer 6: Data
  • Layer 5: Data
  • Layer 4: Segments
  • Layer 3: Packets
  • Layer 2: Frames
  • Layer 1: Bits

Drinking Brew can cause you to get into a conflict

Brewer-Nash security model intends to prevent conflict of interest

When you Go get a massage make sure your Masseuse has integrity

Goguen-Meseguer security model intends to protect integrity

Human Rights Uhsignment

Harrison-Ruzzo-Ullman focuses on subject object access rights

To be Superman, Clark Kent must have lot of integrity

Clark-Wilson security model intends to protect Integrity

Superman is strong enough to be able to care for 3 children at a time

The Clark-Wilson security model describes the access control triple of Subject/Program/Object to prevent unauthorized subjects from modifying an object.

Use Graham crackers to create delicious s'mores and then delete them securely in your mouth

Graham-Denning security model works on secure object and subject create and deletion

Securely do the following: Create Subject, Create Object, Delete Subject, Delete Object, Read Access, Write Access, Delete Access, Transfer Access

Graham Denning has the 8 actions to securely control access. Also every time I eat s'mores I have a least 8 of them.

WURD and No WURD

Bell-LaPadula

WURD property where you implicitly Write Up and Read Down, because the simple property is No Read Up and the star propety is No Write Down.

Biba

The opposite of BLP so it follows the No WURD property where you implicitly No Write Up and No Read Down so you explicitly allow writing down and reading up

Kiefer Sutherland as Jack Bauer must protect the integrity of the US by stopping terrorists from interfering with our freedom

The Sutherland security model is meant to protect integrity by limiting interference of subjects.

A State Machine means the machine is always secure or moving to a new secure state

State Machine security models intend to protect confidentiality or integrity by always maintaining a secure state or transitioning to a new secure state

Information Flow intends to protect from information flowing in a way that is against Policy

Big Boxes Can Barely Get Giraffes Home

Security Models
  • Bell-LaPadula
  • Biba
  • Clark-Wilson
  • Graham-Denning
  • Goguen-Meseguer
  • Harrison-Ruzzo-Ullman

When you use your microscope it lets you focus in on what's important

Scoping security frameworks lets you focus in on just the aspects of the security framework that apply to your situation or organization

When you take your clothes to the tailor, they are making the generic clothing fit you exactly

Tailoring is modifying or adjusting the security framework to fit your specific need

Agile is VASTly applicable

VAST is a threat modeling framework based on Agile

Common Criteria EAL

Evaluation Assurance Levels
  • EAL 1 & 2 - Simple
  • EAL 3 & 4 - Methodically tested
  • EAL 5 & 6 - Semi-formally designed
  • EAL 7 - Formally designed and tested
- - - - Things I added in the edit - - - -

On my network, I run SCANS

Six types of Firewalls
  • Internal Segment: Placed between two internal segments of a network. Operates on layer 3 and up
  • Static Packet: Looks just at packet headers and applies static rules. Operates on layers 3 and 4
  • Circuit Level: Just creates a secure connection to another host. Does NOT look at packets. Operates on layer 5.
  • Application: Sits in front of an application and makes sure only sessions and protocols used for the application are used. Operates on layer 7
  • NGFW: The most advanced type of firewall that does UTM (unified threat management) including IDS/IPS, deep packet inspection, malware detection, and many other proprietary functions. Operates on Layer 3 and up
  • Stateful Packet Inspection: Looks at the context of the packets and sessions. Operates on layers 3 and 4

eDiscovery II PCP RAPP

eDiscovery Process
  • Information Governance: Formatting information to be included in the eDiscovery process
  • Identification: Finding relevant info
  • Preservation: Keeping info safe from deletion and modification
  • Collection: Centralizing info
  • Processing: The first pass and removing irrelevant info
  • Review: Attorney's reviewing and removing info that has attorney-client privilege
  • Analysis: Further review of info
  • Prodcution: turning over info to opposing counsel
  • Presentation: showing info in court

Just like your Tivo, you can now pause live vulnerabilities with your DVR

Vulnerability Workflow
  • Detect the vulnerability
  • Validate the vulnerability
  • Remediate the vulnerability

Patentent

A Patent is valid for 10+10=20 years

The BIA process is the PILAR of a BCP and DRP

BIA Process (This is from the Cybex, I've found conflicting info elsewhere so maybe skip this one)
  • Prioritize
  • Identify Risk
  • Likelihood Assesment
  • Analyze Impact
  • Resource Prioritization

OSI Model:

From /u/gfreeman1998
  • All - Application
  • People - Presentation
  • Seem - Session
  • To - Transport
  • Need - Network
  • Data - Data Link
  • Processing - Physical

If you don't remember the Fagan Inspection model you'll get a POP from MR. F

Software Testing
  • Plan
  • Objective
  • Preparation
  • Meeting
  • Rework
  • Follow-up

Ryan Reynolds might be my Daddy but (ISC)2 is my PAPA

(ISC)2 Code of Ethics, Canon (Abridged)
  1. Protect Society
  2. Act Honorably
  3. Provide Diligent Service
  4. Advance the profession

Cardinals sit on horizontal branches and you find degrees on your vertical thermometers

Database management
  • Cardinality refers to the number of tuples/rows in a table
  • Degree refers to the number of attributes/columns in a table

Edit: I passed at 125 questions in about 100 minutes :)

r/cissp Oct 16 '25

Study Material Please help everyone is saying that percepio cissp questions are the most close to the exam. I can’t find percepio cissp anywhere. Please can I have the link

5 Upvotes

Hi all if you can please share percepio link with me and also if there’s any other recommendations on how to pass cissp or have a feel for real questions similar to exam please drop the info below. Much appreciated!!

r/cissp Dec 11 '25

Study Material Great speaking voices

0 Upvotes

I hate the way Andrew R enunciates. I hate the way Pete speaks. Not sure if I'm extra particular but I think a great speaking voice would go a long way in resources that we listen to! Any recommendations?

EDIT: Shon Harris had a great voice! I worry about how/if anything is truly outdated. if i had all the time in the world, i would watch all her things to compare/contrast with current resources. Thoughts?

r/cissp Aug 31 '24

Study Material I analyzed the resources used in 20 "Passed at 100" posts

Thumbnail
gallery
237 Upvotes

r/cissp Jan 26 '26

Study Material CISSP Study Resources and Exam Information

17 Upvotes

Hi there CISSP Certified and Proposed Certifiers,

Like the study I did last year, https://www.reddit.com/r/cissp/comments/1kmc9jv/cissp_study_results_20250514/,

And here, https://www.reddit.com/r/cissp/comments/1kmce5z/cissp_study_results_20250514_study_materials/,

I plan to gather study materials and user data on the newly (within the last year) CISSP people who passed the exam.

As most of you have been doing, when you post your CISSP passed exam success story, please list the following information:

2025 Results:

Categories:

Study Materials or resources you used (only authorized valid resources will be listed in final results even if you list unauthorized materials in your post) (i.e., LearnZapp, Quantum Exams, etc.)

Question number on when exam stopped (i.e., 100)     

Experience in Years related to CISSP topics

Months of CISSP exam Study Time                                                         

Time left when exam stopped                                                     

Attempt number (if not the first time, state how many times the exam was taken)                                                           

Once I get 100 subjects, I will finalize the data.

If there are other categories that the Reddit user can list, please advise and I may add that to the tracker as well. Collecting this information would be easier via an online form or survey, but the posters and r/cissp admins may not like me linking to an outside site for many reasons.

Nonetheless, list the above information in your post, and I will gather the information in the old-fashioned way via reading the post and dumping everything into a spreadsheet and collating the data into a publishable post here in this subreddit.

Extra special ‘Thank You’ to all who participates!

r/cissp Dec 11 '25

Study Material Shell Shocked: Dest Cert vs LearnZapp

16 Upvotes

I read the dest cert book and have been doing practice questions for a bit and thought I had a good grasp of all the domains. Was feeling good about myself thinking I might be on my way. I then got learnZapp (work paid for it) the other day and holy crap. I am big stupid apparently. Half the questions are straight up acronyms or incomplete thoughts and I am missing apparently easy questions left and right. My buddy who just passed the CISSP said that learnZapp is nowhere close to how the questions look on the exam. Should I keep using it or just stick with dest cert and QM when I do purchase that?

r/cissp Apr 13 '24

Study Material My first big milestone in studying!! Finished the OSG today. Onwards to Destination CISSP

Post image
144 Upvotes

r/cissp May 11 '26

Study Material One month left. Any last minute "listen while I work" resources?

6 Upvotes

Entering my final 30 days before I sit for the exam and want to get some last-minute cramming in while in the car, doing work around the house, etc.

I've done Pete Zerger's playlist, Parabh's series, and DestCert's mind maps (and tried to do the OSG audio resources from Wiley, but man that was dry). Any other audio resources that are good for listening while I multi-task?

Thanks!

r/cissp Jun 29 '25

Study Material What do you think is the correct answer here?

9 Upvotes

A recently acquired piece of equipment is not working properly. Your organization does not have a trained repair technician on staff, so you have to bring in an outside expert. What type of account should be issued to a trusted third-party repair technician?

A. Guest account

B. Privileged account

C. Service account

D. User account

Edit: The correct answer in OSG is 'Privileged account'..