It was a long and stressful process at times, but I'm glad it is finally over. I know there are some people who pass this thing with a week or month of studying, but even with some very relevant real world experience it was not anywhere near that easy for me. My background includes networking, systems, and infosec in the Marine Corps and a few years of private sector risk management consulting. I also have a degree in Information Systems Security. I finished the exam in about 3 hours with around 15 questions flagged for review. I realized I probably didn't magically learn or remember something at the end that I didn't know 2-3 hours ago, so I didn't end up changing any flagged questions. There were times during the exam where I was extremely confident, and other times where I was convinced I failed it and started going over my strategy for a re-take in 30 days. Enough about me, here are the details of my prep (My personal favorites are in bold):
- Started by reading the
Shon Harris AIO 6th edition (Every last word). A bit dry, but Shon really makes it a point to teach you the actual concepts, rather than giving just enough material to pass.
I personally was not in this just for a piece of paper and appreciated her approach.
- Supplemented each chapter with the Shon Harris mp3's after the reading was done (These are a bit dated, but I loved them)
- Tried watching the CBT Nuggets, but they didn't do much for me at all.
- Took all the Skillsoft courses, provided due to my Veterans status (These were brutal and even counterproductive)
- Spent some time on Youtube and other sources like this site to fill in small gaps like new material, success road-maps, etc.
- Watched the
Cybrary videos. These are awesome and really helped me a lot.
Kelly really knows how to explain the material without coming off as boring or robotic. She is the truth when it comes to adding context to this material.
- Read through the entire CISSP 11th Hour book the final week, while taking practice questions (Started with practice questions about three weeks to a month out and took about 4-5,000..)
Practice Questions:
- Started with using Skillset since it was free. This database of questions is strange and many are completely out of scope, but it helps a bit with basic knowledge. I wouldn't use this as a primary source.
- McGraw Hill questions were great for challenging me, and even kicked my ass just a few days ago. These questions seemed like they went out of their way to confuse you, which I don't personally think the real exam does.
-
CCCure questions were the ones that put me over the top. These questions were worth every penny and then some. Without a doubt, this is where I got the closest simulation to the real thing. I wouldn't recommend memorizing these because you won't see a single one on the exam, but they are worded in a similar way and stay within the same scope as the real thing.
Another thing I wanted to mention... I definitely noticed the new material on this exam. Quite a bit, actually. I would definitely recommend looking here
https://cccure.training/m/articles/view/CISSP-CBK-2015-WHAT-WAS-ADDED for the changes. I spent a few days on these new topics and doing my own research on them.
Thanks to everyone here who has provided some kind of useful information. I really combed through this forum and gathered some awesome information that certainly helped or saved time along the way.