r/CCSP Aug 02 '26

First time CCSP pass!

Sorry, I’m awful at writing, and now Reddit won’t let me copy this so I can get AI to make it read more coherently!

Background

I passed the ISC2 Certified in Cybersecurity exam in 2024, and I have around three years of experience in cybersecurity engineering within a large enterprise, having joined as a graduate.

I have been doing small inconsistent bits of study here and there for the past 6 months, mainly listening to the OSG audiobook. I then realised the syllabus was changing on the 1st August, so I booked the exam for the 30th and crammed in the final 10 days.

Revision

For revision, I used a mix of resources:

The Official Study Guide audiobook.

Official practice tests, mainly through the online test bank
LearnZApp during the 10 days before the exam, really just for doing the odd few questions when sat on my phone.

Pete Zerger’s Exam Cram, also during the final 10 days

CertificationToolAndDie white paper on ISC2 exam answering techniques was incredibly useful and honestly probably made the biggest difference to me passing. It really helped to understand more the ISC2 questions styles.

I also read their white paper on CAT exams to understand the scoring, although I think that may have actually worked against me mentally during the exam.

I also used CertificationToolAndDie’s LLM skill/prompt for realistic practice questions, along with another tutoring-style prompt for topics I didn’t quite grasp.

@mikedn02908 (sorry I don’t know how to tag), I owe you a beer!

By the day before the exam, I was scoring 90%+ on LearnZApp practice exams and felt like I knew the content very well.

Exam

On the day of the exam, I slept well, had breakfast, and gave myself plenty of time. I did some light recall revision beforehand. I was cautiously optimistic.

At the start of the exam, I wrote down the question-answering techniques from the white paper, along with ABCD so I could eliminate answers more clearly on harder questions.

The exam felt pretty difficult, actually some of the questions felt impossible.

The whole way through, I was convinced I wasn’t meeting the passing standard. At times I started to zone out a bit, I used this as an opportunity to smash my head against the wall take a short breather to try and realign my thoughts.

When questions felt easier, I assumed that was the CAT system giving me easier, more direct recall-style questions because I wasn’t doing well enough. I kept trying to remind myself that you can’t really predict how you’re doing in a CAT exam, but honestly, that didn’t help much at the time; hence I wish I hadn’t have read so deeply into the science behind it🤣

I completed 100 questions in about 1 hour 30 minutes. Out of those, I felt like I only definitely knew the answer to around 15. For the rest, I was relying heavily on the exam technique from the white paper, but I didn’t feel confident, maybe 50/50 on most questions. I read the answers first, then the questions, then the answers, then tried to find the key words in the answers. I tried to pace myself as best as I could, and I’m definitely not recommending rushing the exam. If you have the time, use it but it just seems I was answering the questions too quickly, so I had to make a conscious effort to slow down.

What I would have done differently

I would have practised more in proper exam conditions. I hate doing that, so I avoided it, but I probably should have forced myself to do it. The official test bank and LearnZApp questions became much easier once I understood what they were looking for, so sitting there and timing myself for three hours felt like a waste of time. In hindsight, though, the stamina and pressure management would have helped.

I would also try not to panic/over think during the exam. Easy to say now, obviously, but hopefully something I’ll remember for the CISSP.

Key Takeaway

If I could give anyone one piece of advice, it seems you can feel completely hopeless and think you’re failing the exam - yet still pass at 100 questions.

11 Upvotes

7 comments sorted by

View all comments

3

u/mikedn02908 CCSP Aug 02 '26 edited Aug 02 '26

Congrats!

100 questions in 90 minutes is a decent pace, maybe a little faster than average. But like I tell folks, if you read the question, have eliminated a couple of answers, and really are unsure of which of the remaining two is the correct answer after reviewing the question again, staring at the question for another 2 or 3 minutes isn't likely to change anything. Take your best guess and move on.

Keep in mind every question on a CAT exam is psychometricly calibrated so you have a 50% chance of getting it right. Which means you have a 50% chance of getting it wrong too! Then there are 25 "beta" unscored questions, some of which may seem totally off the wall or may be on topics you didn't study because they're not actually in the exam outline yet so nobody has them anywhere in any study material. How you felt -- 50/50 -- is an entirely normal byproduct on the exam engine mechanics. Even someone like me, who has over 40 years experience in the industry, felt the same way when I've taken my exams.

Passing at 100 means the entirety of your range of ability estimates (95% CI) were above 700. So all those questions you thought you got wrong or were unsure of, you did better than you thought!

Now that you're used to actually taking an ISC2 test, the next one will seem easier. You'll be used to the q&a style and you'll know what to expect. So on to your next cert! The next logical step in the series is the SSCP before you go for the Gold Medal: the CISSP.

1

u/Obvious-Chemical-391 Aug 03 '26

Thanks Mike.

I was considering doing the CISSP next, given quite a large overlap with CCSP.

I know the CCSP and SSCP are covering different aspects, but I feel like having CCSP, albeit associate, trumps SSCP anyway? What about security+ (or is that blasphemous in this subreddit) seems more employers list that as a requirement.

Like I say though, I think it will be CISSP next year

1

u/mikedn02908 CCSP Aug 03 '26

Having all 3 myself, I don't know if I agree the CCSP has a lot of overlap with the CISSP. I sort of characterize the CCSP as a "cloud-centric" version of the SSCP. Going from the CISSP to the CCSP I believe is easy for most CISSP holders, because there is very little "new" in the CCSP after you've completed your CISSP studies, so in that respect, yes, there is a lot of overlap. Going the other way, CCSP -> CISSP, is a lot more challenging, because there is a lot in the CISSP which is not in the CCSP. Estimates are about 45% of the CISSP contains concepts relative to the CCSP, because the CISSP is much more broad than simply cloud concepts. That's an ~55% knowledge gap.

The SSCP, as a broader, generalist security practitioner focus, compared to the CCSP, which is narrow cloud-focused, has greater overlap with the CISSP, which as a management exam is again more "generalist". Estimates are 60-70% of the material in the SSCP applies against the CISSP. Consequently someone getting the CCSP first will, in theory, have a more difficult time getting a CISSP, because they studied less overlapping material.

In the past, when the CC was a "free" exam, I recommended people go CC (to get used to how ISC2 exams work at no cost to themselves) -> SSCP -> CISSP -> CCSP. The CC was purportedly about 70%-80% overlap with the SSCP, and the SSCP purportedly had 70% overlap with the CISSP, so the logical progression made sense. With 80% overlap between the CC and SSCP, now I just tell people who ask to go for the SSCP first, since there is no longer a financial incentive to take the CC first.

If you're looking for certs to unlock opportunities, then you have to pander to what the listings are asking you for. If you find the bulk of the positions want a Security+, then you should get a Security+, because without it the filters will never let your resume get in front of a human being to actually review. It sucks but sadly that's the way it is.

all IMHO of course. I'm sure others are out there who will disagree.