I passed the CISSP on April 6, 2026. The exam stopped at 100 questions, and I had around 60 minutes left.
I bought the Official Study Guide in April 2025, then studied inconsistently for several months. Focused preparation began on December 25, 2025. From that point, I studied for at least two hours on weekdays and four to five hours on weekends.
The method that worked was simple. I studied one topic, answered questions on it the same day, and returned to the material when my mistakes showed a pattern. Separating months of reading from a later practice phase would not have worked for me.
My preparation timeline
- April 2025: Bought the Official Study Guide and started preparing.
- April to December 2025: Studied inconsistently.
- December 25, 2025: Began focused preparation.
- March 7, 2026: Paid the exam fee.
- April 6, 2026: Took the exam and passed at 100 questions.
I wanted a slot in the last week of March, but no seats were available. Most of the useful preparation happened during the final three and a half months.
Why I chose CISSP
I had an Information Security and Computer Science background and around four and a half years at Infosys. My work covered network security, assessments, operations, compliance, and control validation. I wanted a certification that represented that range.
Experience helped in familiar domains, but it did not remove the need to study. CISSP tests broad coverage and judgment. Several answers may be technically possible. The task is to choose the one that best fits the business, risk, and management context in the question.
The study loop
My routine was:
- Study a focused topic.
- Answer related questions that day.
- Review every mistake.
- Add the missing idea to my notes.
- Repeat until the mistake stopped recurring.
Questions exposed weak areas faster than passive reading. If I missed the same concept twice, I stopped treating it as a careless error and revised the topic.
Resources that earned their place
The Destination Certification CISSP book became my primary book because I could read it consistently. I used the Official Study Guide for Domain 1 and as a reference when I needed more detail. Prashant Mohan’s Memory Palace helped with final revision.
LearnZapp was my main practice app. Before the exam, it showed 71% readiness. I had completed 1,476 questions and around six or seven full-length mock tests.
I also completed around 800 questions in the Destination Certification Android app. During the final two to three weeks, I used a one-month subscription for Thor Pedersen’s Udemy practice tests and completed roughly eight to ten tests and question sets. Pocket Prep supplied a smaller set of extra questions.
For video revision, I skimmed Pete Zerger’s full CISSP video in a day. I used Prabh Nair’s Coffee Shots for individual topics, Andrew Ramdayal’s hard-questions video, and IT Dojo for explanations.
Reddit’s r/cissp and the Cyber Security Station Discord helped me compare study approaches. I treated community advice as another input, not a substitute for the books.
How I used AI-generated questions
I asked Gemini, ChatGPT, and Claude to generate questions from the topic I had just studied. Claude gave me the closest answer choices in my tests, although the free-tier limits interrupted longer sessions.
AI-generated questions were useful for repetition, not authority. When an explanation looked doubtful, I checked the book or my notes.
Prompt used for AI practice
Act as a CISSP study partner. Use the study notes I provide and ask me multiple-choice questions from the relevant CISSP domain.
Make the answer choices close to each other, with more than one option sounding reasonable. The goal is to practice choosing the most correct answer from a security manager’s perspective.
Ask one question at a time. Do not move to the next question until I answer.
If my answer is wrong, explain why the correct answer is better and why the other options are weaker.
Continue with questions from the same domain until I answer 10 correctly.
Notes and weak areas
I filled a 100-page diary with handwritten notes. By the final phase, those notes were more useful than reopening every book and video. They contained my repeated mistakes and explanations in my own wording.
Domain 3 took the most work. Cryptography, key lengths, algorithms, and related details needed repeated revision. Network Security and Risk Management were easier because of my work experience.
Familiarity could still be a trap. A technically detailed answer often looked attractive even when the question called for a governance or risk decision.
The final weeks
I concentrated on Domains 3, 6, 7, and 8. I revised my handwritten notes, mixed question sources, and returned to weak topics instead of adding new material.
The day before the exam, I skimmed the notes and answered a small number of Udemy questions. That kept me in rhythm without turning the final evening into another mock exam.
Exam day
I reached the centre around 8:30 AM, entered around 9:15, and started between 9:30 and 9:45. I had slept for around six hours.
The exam felt medium to hard. Only two or three questions covered material that felt completely unfamiliar. The harder pattern was more common: I could remove two choices, but the remaining two both sounded reasonable.
I did not take a break. The exam stopped at 100 questions with around 60 minutes left.
What I would repeat
- Use a routine that fits ordinary weekdays.
- Answer questions immediately after studying a topic.
- Track repeated mistakes instead of chasing a readiness score.
- Write notes in your own words.
- Use several question sources, but do not expect any of them to reproduce the exam.
- Practice choosing the best management answer when several technical answers look valid.
Consistency mattered more than finding one perfect resource. The diary, repeated question practice, and review of mistakes carried most of the preparation.