CISSP exam results - My experience and how I studied...
I bought the Shon Harris All-In-One (AIO) book (downloaded on my iPad) and started studying in March 2011. I originally scheduled the exam for September, but work commitments involving travel forced me to push out till another few months (another $100).
Sure, other stuff came up that would have made it easier on me to push out again, but with the domains changing in Jan, 2012, I wanted to take it before then.
I need to rant for a moment
I would like to say that I HIGHLY recommend that no one plan to use an iPad as your only resource. Sure, it is light and easier to schlep around than the doorstop that is the AIO hardback book, but you CANNOT figure out where you are in the chapter or how to fast forward a few pages or go back a few pages quickly.
The iPad page contains the equivilant of perhaps 2 paragraphs of the AIO physical book's page. So it seems like you've been reading *forever* but you've only covered 6 pages of the actual hardcopy book pages. Think about this: 1,200 physical pages turns into about 4,800 iPad pages!
To turn a page, you have to "swipe" your finger across the screen in the direction you want (forward or backward). So, if you are reading along and think, "Hm, yes I remember something about topic xyz, I'd like to check that out again...". Forget about it. The best you can do is hit the TOC and start at the beginning of a chapter to try to find it again.
Even more frusterating - it takes about 2 seconds for the iPad to reset once you swipe a page forward or backward. That doesn't seem long to you? Oh, yes, my friend, it is. It is an eternity when you have about 30 swipes to get where you want to go (which is about 5 pages in the physical book).
Also, if a figure/diagram is referenced, you may not see it for 15 more page swipes. Sure, there is a hyperlink to get there, but you still have to swipe you way back to where you came from.
I gave up when there was about 10 days to go until the exam. I broke down and paid again to buy the physical book to study from. It saved my hiney.
OK, rant over
So, here's my experience: A co-worker and I decided to study together and ponied up our money to make sure we were committed to studying. We made a schedule to tackle all 10 domains. We gave ourselves 3-4 weeks for each domain due to work and family commitments we both had. But honestly, because our deadline was months away, there were many times that several weeks went by where we didn't crack a book.
After we finished each domain, we took some practice exams. These included the AIO end-of-chapter questions and some from the ISC(2) CISSP book my co-worker bought. I was scoring about 60-65% on those tests, but I didn't sweat it because the exam date was far away and sometimes I either hadn't finished reading, or hadn't reviewed before I took the practice exams.
During the first 6 months of study, it was so helpful to have a study buddy. We kept each other motivated to finish the domains - even at our snail's pace, we were making forward progress.
During the last 3 months, we were rushing to finish domains more quickly and making study a priority and telling our families that we had to study. I began putting in about 7 hours of study per week (I found it hard to eek out even that time while working full time with a family at home).
With 3 weeks to go, my attitude altered greatly. I buckled down and read every spare chance I had (about 3 hours per day).
In the last week, I took 4 days off of work and studied 15 hours per day each of those 4 days. I took the Shon Harris CD practice exams and was scoring 80 - 90% consistently.
I had to go to a work conference that 5th day, and the next day was the exam. It was probably good to rest my brain from any studying that last day, but I still only got 5 hours or so of sleep before the test day because I got home and did some last-minute cramming for a few hours.
I got to the test center Saturday morning at 8:12. Check in was by 8:30. I'd been in line for 10 minutes when they told us we better go to the bathroom before we were checked in because after that point we'd have to be escorted. Woe was me, who'd gulped down 3 cups of coffee on the way there.
**Edit: One thing worth noting: A guy in line with me said he'd heard it was a good idea to write down all your memorized facts and anagrams floating around in your head in the worksheet before you even read a single question. This is the stuff you are worried you'll forget. Just get it out on paper when you first open your packet, and THEN start taking the test. I did this, and found that I didn't even need to go back and read any of what I'd written -- but I think writing it down before I got sidetracked by those tough questions was a good idea, and gave me some peace of mind that I wouldn't confuse/forget my little memorization tricks.**
The exam started and the first question made my stomach drop. This wasn't the specific info. I'd crammed for. It was some vague, scenario-based question. OK, I thought. I'll make my best guess. 2nd question was the same type. 3rd, 4th, 5th...Oh crap. I had no idea how to answer. This was nothing I could have studied for or memorized. I guess that is why you have to have the number of years of work experience to even qualify for this cert., and why they say to answer the questions from a management perspective. Or, perhaps those first few questions were the "research" questions that didn't count. I don't know. But they threw me for a loop.
I soldiered on. I will say that these questions are based on a set of variables, and you must know the inherent implications of these variables - the strengths and weaknesses of each - to be able to select the best answer. So, studying was not a waste, even if I couldn't nail down a specific correlation to most questions...the foundation is what you need to make a judgment call.
It was important for me to take it slow, and carefully read the questions to fully understand WHAT was being asked. I read each question thoroughly and marked my best guess - and it did feel like a guess a lot of the time!
Looking back, I think there were about 10 questions that were specific, you-could-memorize-this questions that I just didn't know (stuff like key-bit size - there were 2 domains I didn't get a chance to review my notes on, and one of them was Crypto - a HUGE chapter in the AIO). Knowing I could miss about 50-60 questions, I didn't worry about these 10. Likewise, I have the impression that about 30 questions like this I got right. The rest of the questions...well, I had NO IDEA how I did on them.
I just concentrated, focused, read the question, interpreted it the best I could, and went with my best answer. I finished in 5 hours exactly. I'd had to take 2 bathroom breaks. I didn't bring food, but wouldn't have had time nor inclination to eat anyway. I wanted to get this bad boy over with.
I forced myself to take the last hour to go back to the questions I'd circled in the handbook and review my answer. I clearly remember changing one answer from B to C, then to A. Then back to C. Then back to B. Then laughing at myself and realizing that second-guessing my answers was fruitless. I went over about 15 questions and realized I wouldn't change my answer because I'd given it such good thought the first time through.
I also marked my bubble sheet as I went. The last thing I wanted was to hear them call time and not have ANY answers marked - or just as bad, to mark them in a hurry and get mis-matched one question off and not realize it until I'd gotten to the end. Nightmare stuff, that.
I walked out of the exam room mentally numb and physically exhausted. But, I slept like a champ that night. A few days later I was resigned to the fact that I probably failed and was itching to start studying again. But, the exam wasn't in my area again for a few more months. So, I decided to wait for the results.
I was concerned that the holidays would mean a delay in getting our results, but they arrived exactly 3 weeks later). My co-worker and I both passed.
I used:
- Shon Harris* AIO (huge, but easy to read)
- Eleventh Hour CISSP by Conrad (but I only read 3 domains...I found some info. didn't correlate to what I'd already studied and I didn't want to muddy the waters, so I stopped reading. My co-worker read the whole thing (it's a nice, small, easy read) and praised it highly.)
- Domain practice exams on the CD that came with the Shon Harris AIO book
- Practice exam from my co-worker's copy of ISC(2) CISSP book (my co-worker read some domains in this book thoroughly, and skimmed some. She said it was a dry read compared to the AIO.)
*Shon, if I ever meet you in person, the drink is on me!
May you all do well!