Looking for advice on the CAP
I'm not quite sure specifically what I want, but any sort of recommendations, feedback, or advice would be much appreciated. I apologize in advance if my post is a bit disjointed.
I've been studying the past month or so for the CAP, and I'm having a really hard time gauging how ready I am for the exam. Unlike any other exam that I have taken to this point, there have been a wide variety of available choices in terms of study and preparation tools. Thus far, I have read the CBK once cover-to-cover while highlighting important concepts, which I later typed out in the form of a study guide in a text document. I just started listening to the (ISC)2 podcasts/web casts and I am presently working through the (ISC)2 provided flashcards. Once I complete my review of those, I will have no which other resources to use. Most notably, there is a dearth of practice questions. I know better than to try to memorize practice questions, but I think it is invaluable to study with the mindset of the types of questions that you will see on the exam. I am likely going to spend the $15 to buy all 75 available CAP questions from (ISC)2, but honestly, I was very underwhelmed by the types of questions (and content in general) provided from the CAP and CISSP CBKs, so I was hoping to find something more applicable at a somewhat cheap price or free. I have read a few posts on the TE forums which have helped, but there doesn't seem to be a lot of discussion.
In regards to my studying, I feel pretty comfortable with most of the steps in the RMF. I have a pretty sound understanding of which roles perform which tasks (although I sometimes struggle on differentiating which role will do which job if the question provides two answer with similar positions) and the deliverables/documents generated from the various steps in the RMF. I am very comfortable with what I consider the 'common sense' questions that pertain to a lot of the project management, the necessity of assessor independence, team assembly, etc. What I am most concerned with at this point is how heavily tested are the specific NIST SPs, FIPS, and OMBs. I was previously only studying the cursory, high-level concepts of these laws/guides/regulations, but I have read on these forums that you are expected to know them in-depth - which is not something the CBK really focused on.
As for myself/background: Lately, our company has been assisting with DIACAP authorizations, and I wanted to familiarize myself with the RMF before we made the change. Most of my role/experience is under assessing/testing web applications (STIGs) and tracking vulnerabilities with a POAM, but I am lacking in a lot of the bigger picture concepts and felt this was a good opportunity to educate myself. I have passed a number of other exams before, but I have only sat for one exam from (ISC)2, which makes me a bit uncomfortable in terms of lack of familiarity with their format and styles of questions. While I have yet to fail a certification exam, I don't think I am the best test taker and typically rely on a greater than usual amount of study and preparation, which is unavailable for the CAP. This would also be a pretty poor time for me to be setback $419, as I do not have the highest salary and it's around Christmas time.