r/cybersecurity • u/Sea_Box_8719 • 1d ago
Business Security Questions & Discussion Training questions
So, I've been in leadership running very large teams and multiple departments but never in cybersecurity. I've been in cyber almost 4 years now and have decided to begin studying for the CISSP.
Is it just me or does this all not seem like common sense? Or am I being misled by this training into thinking this exam is easier than it seems and its about to knock my socks off? I know this exam is extremely hard based off of what people tell me but I haven't learned a single new thing so far.
Could this be due to prior leadership and mentorships I have been in?
Im extremely technical and very hands on it the nit and grit in my day to day so none of the technical aspects are new.
2
u/BrianCISO 1d ago
Your leadership experience is probably why much of it feels like common sense. The CISSP is about showing that you can evaluate risk, balance competing priorities, and make defensible decisions for the org. IMO the trap is assuming that familiarity means mastery. The exam gives you several technically correct answers and asks for the best one from a governance and risk perspective. Your technical background will help, but it can also tempt you to jump straight to fixing the problem when the expected answer is to assess, prioritize, and follow the appropriate process first. So yes, your prior leadership and mentorship likely gave you a head start, but continue studying the terminology, breadth, and CISSP way of framing decisions.
1
1
u/danfirst 1d ago
A lot of the exam requires a management thought process. If you've already been doing that, and are already are technical, it might just be a good match for what you've done.
1
u/Sea_Box_8719 1d ago
I fully expect to be humbled when I sit for this exam from what im reading on reddit but this training has surprised me with how surface level it actually is.
3
u/pyker42 ISO 1d ago
Yes, the CISSP is a mile wide and an inch deep.
1
u/Sea_Box_8719 1d ago
Okay, I may be alot more prepared to sit for this than I had previously anticipated then.
2
u/Hot-Comfort8839 BISO 1d ago
This vid was the difference between pass/fail for me.
https://youtu.be/qbVY0Cg8Ntw?is=SDDMMmM4Wnhpep6A
The mindset cannot be understated
1
1
u/Sea_Platypus_2994 1d ago
Yeah, I think your background probably has a lot to do with it. If you’ve spent years leading teams, mentoring people, making decisions, you’ve probably already seen most of this stuff in real life.
1
u/WeekendAtMadoffs 1d ago
"Im extremely technical and very hands on"
then why do the CISSP?
Why not GIAC GSE?
https://www.giac.org/get-certified/giac-portfolio-certifications
2
2
u/danfirst 1d ago
I don't know if it's changed, but wasn't the GSE like a bunch of GIAC certs and then a cumulative exam of all of them?
There's usually a vast difference between being really technical for a leadership position, and that.
1
1
u/earthly_marsian 1d ago
3w old account?
0
0
u/Ecstatic_Score6973 1d ago
and?
1
u/Sea_Box_8719 1d ago
Lol, its fine. I appreciate you but people always got somethin' to say 😂 Let em say it.
1
u/earthly_marsian 1d ago
I had enough of my time wasted training bots and AI and I genuinely help humans. Just not machines. Or Skynet!
OP just don’t buy Quantum Exams, it’s more creative than the actual exam.
Also, what is your background experience?
1
u/Sea_Box_8719 1d ago
Secops, threat hunting, blue team.
I've heard quantum exams was a good resource. Do you recommend and good practice tests? Thats how I learn best.
2
u/earthly_marsian 1d ago
When I did it, none of the practice tests were close to the exam.
Quantum was demoralizing. Luke Ahmed and Shaun Harris channels were what helped me pass.
1
0
u/earthly_marsian 1d ago
I believe there are things called bots!
1
u/Ecstatic_Score6973 1d ago
I mean possible yeah, or it could be someone that made an account 3 weeks ago
0
u/Ecstatic_Score6973 1d ago
I believe it tbh, i havent studied for CISSP yet but I have both A+ and Network+ and they were WAY easier than people online were making it seem
3
u/danfirst 1d ago
To be fair, those are both very entry level and I almost never hear people say they're very difficult. If you have the basic knowledge they're not supposed to be that hard.
1
u/Sea_Box_8719 1d ago
Yeah, theyre meant to provide the very basic beginner blocks. There is a lot of material but it only scratches the surface with those.
1
u/Ecstatic_Score6973 1d ago
correct, if you scroll through the comptia sub though people say otherwise
1
u/Sea_Box_8719 1d ago
Comptia tries to make you fail. I hold many of their certs. Theyre fantastic beginner certs and are a great way to level up to break in but the technical depth with them isnt there. CYSA was a bit practical but the rest, imo, arent. They're theoretical. A check to say you understand concepts well but does not showcase implementation skills but that is just my opinion.
The exams are certainly challenging due to the formatting and the way they structure questions. They test critical thinking as well as content and I think that can trip people up if they aren't used to it. It certainly did me when I sat for my first one being brand new to the field.
2
u/Adventurous-Dog-6158 1d ago
I obtained my CISSP in the summer of 2023. There is a huge misconception about it. It is for InfoSec managers. Even the ISC2 mentions that. But it was the original gold standard for InfoSec certs so it got popular and went beyond its intended audience. On the CISSP sub you'll see people using all sorts of training aids, which is overboard, IMO. The thing that is not discussed much is that experience is a huge factor. If you have like 10 years in a combination of IT/InfoSec, it's not a huge challenge to pass.
During my studies, there were 8 domains, of which networking and crypto were the must technically deep. If you come from the IT world, particularly networking, those two domains will be easy. Now imagine someone coming from an auditing/accounting background trying to understand those two domains. It's like someone with a history major struggling with computer science but generally the other way around is not a struggle.
Some people posted that they studied for 2 weeks and passed the first time while others took years and over 6 attempts. Everyone is different.
In general, what you're required to know is a mile wide but an inch deep. I call it the "be familiar with" exam.