Passed CCSP Today - 7/29
Sat the exam today and got through it in about 1.5hrs. I have been studying for the exam off and on (mostly off) since 2016 when I took the online ISC2 course, more recently (as in about 4-5 weeks ago) I started reading through the Carter All-in-One book and the CBK 2nd edition. I used those as well as the Sybex practice questions (briefly), read through everything I could find online about other peoples' experiences and tips, etc. I did not read the AIO or CBK books from cover to cover as I've been working in datacenters, with security, virtualization and now the cloud for years and some of it was very familiar. I did read through enough to understand the ISC2 terminology for the things I felt familiar with as it is not the same as industry standards in each of those areas. There is a lot of overlap with the CISSP, so having studied that will definitely help here.
As far as the test itself, there were mostly standard multiple choice questions. I think I had only two or three drag and drop matching questions. Definitely understand the cloud models and their differences in reference to the Shared Security Model. Be sure to study the regulatory requirements by country, I never got a question about the actual differences between the regulations but that doesn't mean you won't. Know the types of encryption in the cloud, key management options, ways to secure DAR, DIT, and DIU, types of API access and how to secure them, considerations for hypervisor security, SDN security, types of controls (identify administrative, physical, technical for example), BC/DR considerations and continuity planning, ITIL management categories, application security, data roles, basics of eDiscovery and chain of custody, even the basics of the FedRAMP ATO process (which is not in the current CBK, will be in the new one I assume). A lot of the questions were in the format of "while planning for xxxx, which of these would be the MOST critical consideration?", which can be tricky because the answer that seems like the most obvious "security" answer may not be the correct choice. You have to know the material pretty well, it's a tough exam.
Some of the questions were surprisingly technical while others were standard knowledge of the CBK terms types. There were a few where I was legitimately confused because one answer could be correct from the customer side while the other could be correct from the CSP side, and the question didn't give any clue as to which point of view it was looking for.
As far as the test itself, there were mostly standard multiple choice questions. I think I had only two or three drag and drop matching questions. Definitely understand the cloud models and their differences in reference to the Shared Security Model. Be sure to study the regulatory requirements by country, I never got a question about the actual differences between the regulations but that doesn't mean you won't. Know the types of encryption in the cloud, key management options, ways to secure DAR, DIT, and DIU, types of API access and how to secure them, considerations for hypervisor security, SDN security, types of controls (identify administrative, physical, technical for example), BC/DR considerations and continuity planning, ITIL management categories, application security, data roles, basics of eDiscovery and chain of custody, even the basics of the FedRAMP ATO process (which is not in the current CBK, will be in the new one I assume). A lot of the questions were in the format of "while planning for xxxx, which of these would be the MOST critical consideration?", which can be tricky because the answer that seems like the most obvious "security" answer may not be the correct choice. You have to know the material pretty well, it's a tough exam.
Some of the questions were surprisingly technical while others were standard knowledge of the CBK terms types. There were a few where I was legitimately confused because one answer could be correct from the customer side while the other could be correct from the CSP side, and the question didn't give any clue as to which point of view it was looking for.
CISSP, CCSP, CCSK, Sec+, AWS CSA/Developer/Sysops Admin Associate, AWS CSA Pro, AWS Security - Specialty, ITILv3, Scrummaster, MS, BS, AS, my head hurts.
Tagged:
Comments
-
E Double U Member Posts: 2,233 ■■■■■■■■■■Congratulations! I also saw the CISSP overlap as well as other certifications I have accumulated. I took the exam last year and felt overall it was a security exam with the word cloud thrown into it.Alphabet soup from (ISC)2, ISACA, GIAC, EC-Council, Microsoft, ITIL, Cisco, Scrum, CompTIA, AWS
-
SteveLavoie Member Posts: 1,133 ■■■■■■■■■□Congratulations... Thanks for sharing your experience, as CCSP is definitely on my list.