u/Organic_Morning_3746

▲ 8 r/cissp

More practice tests or domain drilling ?

My CISSP exam is on the 24th of August. I'm looking for guidance on how should I spend the next week, week before the exam.

Who am I : I have 5 years of experience, not in the US meaning English is not my native language. But I'm finishing up my Masters degree in Information Systems in the US.

How I studied : I read the official study guide (OSG) front to back, took every chapter quiz, all above 80%, took all domain quiz 75-80% except domain 4.
After finishing the book I started hammering practice exams :
1. QE as my hard CAT bank
2. OSG practice test as my near real difficulty cross check.

The idea is to take one of each then compare the misses across both to figure out weak domain (weak domain on both) or just QE being brutal (weak only on QE) and to figure out my parsing errors. I take QE on Monday and OSG on Tuesday.

Results from the practice exams are :
QE CAT #1 : 547 ->QE CAT #2 : 708,
OSG #1 : 78% -> OSG #2 : 82%

Problem : Taking QE on one day and taking OSG the next day is burning me. My classes are also eating into my CISSP study time, therefore I cant really fix my mistakes in only 2 days. This makes me feel like I dont study enough to take the next cycle of practice tests, where I just waste practice exam banks and get the wrong answer again.

Questions for the sub:

  1. For the final week is it better to keep taking full length tests or shift to targeted drilling on weak domains ?

  2. Is back to back full length practice exams counterproductive ?

  3. Some people recommend tapering, why ?

  4. Should I start tapering ? if then when ?

Appreciate any input from recent test takers and CISSP instructors.
Thank you.

reddit.com
u/Organic_Morning_3746 — 4 days ago

Pivoting from foreign government to US private sector

Looking for honest/serious takes from people in cyber, threat intel, consulting, or risk governance. Keeping employer specifics out for OPSEC.

Background:

  • BS IT (US federal top service academy), US defense grad cert Cybersecurity (2021)
  • ~5 years split between a national policy/intel shop and a national cyber command
  • Currently MS Information Systems at a US school, 3.94 GPA, graduating mid 2027
  • Foreign national, got that OPT thing after graduation.

What I did back home:

  • Influence ops analysis, coordinated inauthentic behavior, election integrity (pre/during/post-cycle)
  • Executive level briefings, including heads of state
  • Malware reverse engineering, APT attribution (Mostly Chinese), MITRE ATT&CK mapping
  • IR SOPs, incident response, some threat hunting
  • DLP ,EDR, AD work.

Target tracks (ranked):

  1. Cyber security

  2. Threat Intelligence

  3. Cyber Consulting (Big 4)

  4. Risk Governance

Questions:

- I feel like cyber security is the way to go, but in this market I dont know if me and my resume will make it to an offer, should I pivot to something else? such as AI safety, Trust and Safety?

- Does foreign government experience help, hurt, or wash on a US resume?

- MS IS sufficient, or do I need Security+ / CISSP / GCTI / stacked for ATS survival?

Not here for validation. Want the gaps called out.

Thanks you for you input.

reddit.com
u/Organic_Morning_3746 — 3 months ago