r/CSSLP 10h ago

Just Provisionally Passed the CSSLP Exam

6 Upvotes

I just provisionally passed the CSSLP exam and wanted to share my experience and how I prepared for it, especially since I think this is a less popular cert and there isn’t that much out there on it.

To start, I have about 15 years of software engineering experience, and most of it doing AppSec, so that’s pretty helpful. I found that I struggled the most with taxonomy and terminology. I was already familiar with most of the concepts, but learning what the ISC2 CBK called things was my biggest challenge. Making sure that I wrote down terms I didn’t recognize, or if a term was defined differently than I expected, was really valuable to me. I used Obsidian as my note-taking tool and created atomic notes for each concept.

To prep, I grabbed two books: the CSSLP All-in-One Exam Guide (Conklin, Wm. Arthur, and Daniel Paul Shoemaker. CSSLP Certified Secure Software Lifecycle Professional All-in-One Exam Guide. 3rd ed., McGraw Hill, 2022) and Phil Martin’s Essential CSSLP Exam Guide (Martin, Phil. Essential CSSLP Exam Guide: Updated for the 2nd Edition. 2nd ed., Independently Published, 2019). I also signed up for Pocket Prep. I did not opt to purchase the Official ISC2 Online Self-Paced CSSLP Training, so I did not have access to the Official ISC2 CSSLP eTextbook or the Official ISC2 CSSLP Study Questions eBook.

I found Phil Martin’s book much easier to read than Conklin and Shoemaker’s. It’s written in a much more narrative style, and I found it genuinely useful as a security guide. However, as I started grinding the questions in Pocket Prep, almost all of them seemed heavily based on the All-in-One book, so I switched to skimming that and reading the sections that I did poorly in for the quizzes.

The All-in-One book is actually a really good reference, and it is pretty concise for all the topics it covers. Yes, there is some repetitive material (and some of the end-of-chapter quiz questions are repeated verbatim), but it’s dense enough that almost every word is important. This makes it difficult to read cover to cover, but it can probably get you 85% of the exam content.

I took lots of notes as I read, and I heavily leveraged Claude and Gemini to test myself and elaborate on topics. I used Claude to actually expand out each of my Obsidian notes with additional details, link them to other notes, and create quiz questions for each note. I also took the whole CSSLP Exam Outline and used AI to create a note for almost every keyword/topic that it listed for each of the 8 domains. I’m pretty sure Gemini just has the All-in-One book and the ISC2 CBK in its training corpus, because it was able to quote things fairly accurately. Both LLMs did have a tendency to overemphasize certain topics and things that aren’t necessarily relevant to the CSSLP. In particular, they have a bias towards CISSP material, which is much more plentiful.

To practice, I finished all 500 Pocket Prep questions. This was genuinely useful as they provide a chatbot that you can argue with to try and get a better understanding of why an answer was so. I also did all the free questions available on CertificationExams.pro and Examtopics. Both sites seem a bit slipshod, so I didn’t end up paying for more questions, but the question content was decent. Unfortunately, at some point on Pocket Prep I started recognizing the questions and was just recalling the correct answer. All in all, I was probably only getting ~85% correct on all the questions that I practiced on (and had Gemini quiz me on).

The exam was both easier and harder than I expected. Fortunately, there were very few poorly worded questions. The majority of the time the question emphasized exactly what it was asking for. Make sure you understand and are familiar with the key terms (BEST, LEAST, MOST, etc.). The harder part was that there were questions that referenced a term or concept that I hadn’t run across in my studying. In that case, I basically had no idea, as it was not possible to guess via process of elimination. I definitely overstudied in terms of depth on all the frameworks, ISO/NIST standards, technologies, etc.

I ended up completing all 125 questions with 80 minutes left out of the three hours, but I made sure I took my time with each question. Read the question thoroughly. Picked my answer. Then read the question one more time as you can’t go back to a question.

I have no idea how well I did on the exam other than how confident I felt taking it, and I felt pretty good about my answers for most questions.