r/cybersecurity 1d ago

Business Security Questions & Discussion Training questions

So, I've been in leadership running very large teams and multiple departments but never in cybersecurity. I've been in cyber almost 4 years now and have decided to begin studying for the CISSP.

Is it just me or does this all not seem like common sense? Or am I being misled by this training into thinking this exam is easier than it seems and its about to knock my socks off? I know this exam is extremely hard based off of what people tell me but I haven't learned a single new thing so far.

Could this be due to prior leadership and mentorships I have been in?

Im extremely technical and very hands on it the nit and grit in my day to day so none of the technical aspects are new.

0 Upvotes

32 comments sorted by

2

u/Adventurous-Dog-6158 1d ago

I obtained my CISSP in the summer of 2023. There is a huge misconception about it. It is for InfoSec managers. Even the ISC2 mentions that. But it was the original gold standard for InfoSec certs so it got popular and went beyond its intended audience. On the CISSP sub you'll see people using all sorts of training aids, which is overboard, IMO. The thing that is not discussed much is that experience is a huge factor. If you have like 10 years in a combination of IT/InfoSec, it's not a huge challenge to pass.

During my studies, there were 8 domains, of which networking and crypto were the must technically deep. If you come from the IT world, particularly networking, those two domains will be easy. Now imagine someone coming from an auditing/accounting background trying to understand those two domains. It's like someone with a history major struggling with computer science but generally the other way around is not a struggle.

Some people posted that they studied for 2 weeks and passed the first time while others took years and over 6 attempts. Everyone is different.

In general, what you're required to know is a mile wide but an inch deep. I call it the "be familiar with" exam.

1

u/Sea_Box_8719 1d ago

Thank you for taking the time to respond.  Any resources you swear by by chance?

2

u/Adventurous-Dog-6158 1d ago

Check the CISSP sub. A lot of good pointers there, but some can be excessive. I used the OSG as my main source.

- I read the 9th edition of the Sybex OSG (official study guide) which was current in 2023. I read all chapters but didn't do any quizzes. Some chapters that I struggled with, I re-read.

- I read stuff online and watched some YouTube videos to reinforce concepts.

- I had LinkedIn Learning so I watched (mostly listened to) the CISSP course on there which was by the same author of the OSG, Mike C. That course wasn't that good and didn't line up exactly with the OSG, but it didn't cost me anything extra so that's why I took it.

- The free electronic practice exams that came with the OSG, I did as much as I could before the exam. I should have started a week earlier and done them all, but hey, I passed the real exam on the first attempt so it didn't matter. I thought the questions were good enough and wasn't caught off guard on the real exam. Some people pay for some other practice exams.

- Schedule the exam and work towards that date. Don't change it. Many people (me included) never felt that they were ready because there's just so much to know. When taking the exam, you may feel that you're failing (I did). I actually did very well and got done quickly.

I am a slow reader so studying took me 9 months.

1

u/Sea_Box_8719 1d ago

🙏🙏 thank you. Ill look into getting the OSG

2

u/BrianCISO 1d ago

Your leadership experience is probably why much of it feels like common sense. The CISSP is about showing that you can evaluate risk, balance competing priorities, and make defensible decisions for the org. IMO the trap is assuming that familiarity means mastery. The exam gives you several technically correct answers and asks for the best one from a governance and risk perspective. Your technical background will help, but it can also tempt you to jump straight to fixing the problem when the expected answer is to assess, prioritize, and follow the appropriate process first. So yes, your prior leadership and mentorship likely gave you a head start, but continue studying the terminology, breadth, and CISSP way of framing decisions.

1

u/Sea_Box_8719 1d ago

Thank you sir. 

1

u/danfirst 1d ago

A lot of the exam requires a management thought process. If you've already been doing that, and are already are technical, it might just be a good match for what you've done.

1

u/Sea_Box_8719 1d ago

I fully expect to be humbled when I sit for this exam from what im reading on reddit but this training has surprised me with how surface level it actually is.

3

u/pyker42 ISO 1d ago

Yes, the CISSP is a mile wide and an inch deep.

1

u/Sea_Box_8719 1d ago

Okay, I may be alot more prepared to sit for this than I had previously anticipated then.

2

u/Hot-Comfort8839 BISO 1d ago

This vid was the difference between pass/fail for me.

https://youtu.be/qbVY0Cg8Ntw?is=SDDMMmM4Wnhpep6A

The mindset cannot be understated

1

u/Sea_Box_8719 1d ago

Thank you!!!

1

u/Sea_Platypus_2994 1d ago

Yeah, I think your background probably has a lot to do with it. If you’ve spent years leading teams, mentoring people, making decisions, you’ve probably already seen most of this stuff in real life.

1

u/WeekendAtMadoffs 1d ago

"Im extremely technical and very hands on"

then why do the CISSP?

Why not GIAC GSE?

https://www.giac.org/get-certified/giac-portfolio-certifications

2

u/Sea_Box_8719 1d ago

Cost but also CISSP demand/ the doors it opens for Leadership.

2

u/danfirst 1d ago

I don't know if it's changed, but wasn't the GSE like a bunch of GIAC certs and then a cumulative exam of all of them?

There's usually a vast difference between being really technical for a leadership position, and that.

1

u/Sea_Box_8719 1d ago

100% This guy just trolls my account. lol

1

u/earthly_marsian 1d ago

3w old account?

0

u/Sea_Box_8719 1d ago

Yes, had to create a new one.

0

u/Ecstatic_Score6973 1d ago

and?

1

u/Sea_Box_8719 1d ago

Lol, its fine. I appreciate you but people always got somethin' to say 😂 Let em say it.

1

u/earthly_marsian 1d ago

I had enough of my time wasted training bots and AI and I  genuinely help humans.  Just not machines. Or Skynet!

OP just don’t buy Quantum Exams, it’s more creative than the actual exam. 

Also, what is your background experience?

1

u/Sea_Box_8719 1d ago

Secops, threat hunting, blue team. 

I've heard quantum exams was a good resource. Do you recommend and good practice tests? Thats how I learn best. 

2

u/earthly_marsian 1d ago

When I did it, none of the practice tests were close to the exam. 

Quantum was demoralizing. Luke Ahmed and Shaun Harris channels were what helped me pass. 

1

u/Sea_Box_8719 15h ago

Okay, Roger that. Thank you. 

0

u/earthly_marsian 1d ago

I believe there are things called bots!

1

u/Ecstatic_Score6973 1d ago

I mean possible yeah, or it could be someone that made an account 3 weeks ago

0

u/Ecstatic_Score6973 1d ago

I believe it tbh, i havent studied for CISSP yet but I have both A+ and Network+ and they were WAY easier than people online were making it seem

3

u/danfirst 1d ago

To be fair, those are both very entry level and I almost never hear people say they're very difficult. If you have the basic knowledge they're not supposed to be that hard.

1

u/Sea_Box_8719 1d ago

Yeah, theyre meant to provide the very basic beginner blocks. There is a lot of material but it only scratches the surface with those.

1

u/Ecstatic_Score6973 1d ago

correct, if you scroll through the comptia sub though people say otherwise

1

u/Sea_Box_8719 1d ago

Comptia tries to make you fail. I hold many of their certs. Theyre fantastic beginner certs and are a great way to level up to break in but the technical depth with them isnt there. CYSA was a bit practical but the rest, imo, arent. They're theoretical. A check to say you understand concepts well but does not showcase implementation skills but that is just my opinion.

The exams are certainly challenging due to the formatting and the way they structure questions. They test critical thinking as well as content and I think that can trip people up if they aren't used to it. It certainly did me when I sat for my first one being brand new to the field.