▲ 11 r/isc2

Passed the CC today — and this time it let me finish

Provisionally passed the Certified in Cybersecurity exam this morning. Wanted to share a few things that might help people still prepping.

Quick background: I'm a data analyst moving toward a SOC/detection role, so a chunk of this material connected to work I already do — but a lot of it was genuinely new (the security-specific frameworks, access control models, and the BC/DR/IR vocabulary especially).

What helped me most:

LinkedIn Learning practice tests. These were the backbone of my prep. I didn't just take them for a score — I honed in on every wrong answer and dug into why it was wrong until the reasoning stuck.

Encryption. I gave this extra focus since it doesn't map to my day job the way data concepts do — symmetric vs asymmetric, hashing vs encryption, where each one actually gets used.

Concept distinctions, not definitions. Especially the access control models (DAC vs MAC vs RBAC) and attacks vs defenses. That's where most of my missed practice questions were coming from — I knew the terms, but not the lines between them.

On the exam itself: it went the full 125 questions for me. I'll be honest — I had a rough moment around Q90, because a previous attempt of mine terminated early at 90 due to a testing anomaly. So watching it roll past 91, 92, 93... 100... was its own kind of relief. If yours keeps going past 100, don't read it as a bad sign — the exam serves items until it's confident about your score, and plenty of people who pass go all the way to 125.

Happy to answer questions if you're studying for it. Onward to SC-900. 💜

reddit.com
u/iris925 — 5 days ago
▲ 5 r/isc2

Update: I dug into the data behind my anomalous CC session (the one that ended at 90 questions)

First — thank you, r/isc2. I have to start here. When I posted about my session the first time, I was honestly spiraling and second-guessing myself. Almost immediately, someone commented that it "doesn't smell right," and someone else said the same thing had happened to them around the same time. Those two replies did something I couldn't do for myself in that moment — they told me the anomaly was real and I wasn't imagining it. This whole write-up exists because this community gave me the footing to trust what my gut was already telling me. So genuinely, thank you.

A few weeks back I posted here about my CC exam ending at 90 questions with no error message and time still on the clock. That thread got way more traction than I expected.

And to be clear about where I was coming in: I didn't just grind practice tests. I went through Chapple's book and videos, ISC²'s official training and webinars, the Codecademy course, daily question banks, and spent most of my review time on why I got things wrong, not just what the right answer was. I walked in prepared.

And look — I'm fully prepared to find out I failed fair and square on the 15th. This was never about refusing to accept a result. It's that the session itself didn't behave the way it's documented to, and separating "did I fail" from "did the exam run correctly" is exactly the kind of thing my job trains me to do. I'm a data analyst — about a decade of staring at anomalies for a living — so instead of just stewing on it, I treated the session like an incident and pulled every data point I had. Here's what I found, in case it's useful to anyone else who has a weird session.

The question count. The CC minimum is documented as 100, with a maximum of 125. Mine stopped at 90. Early termination by confidence is a real CAT feature, but per ISC²'s own docs, the confidence rule can't even be applied until you've cleared the 100-item minimum. A stop at 110 I could explain. A stop at 90 I can't — not without the session log.

And before anyone says it: yes, I know a chunk of CAT questions are unscored beta items. But those are counted within the total you answer, not on top of it — so they don't explain stopping at 90. If anything, they make it weirder, since the count already includes the padding.

The score report. This is the part that made me stop cold. My practice data was consistent for weeks: Domain 4 (Network Security) was my weakest at 80–90%, everything else sat at 100%. The report came back with Domain 4 as my only Above Proficient and all four of my strong domains as Below Proficient. A complete inversion of my prep pattern.

I'll be fair about this one, because I've chewed on it a lot: practice scores aren't exam scores, beta items muddy which questions actually counted, and it's normal to underperform your bank under pressure. With only 75 scored items spread across 5 domains and compensatory scoring, a rating can swing on very few questions — so honestly, the inversion probably has an ordinary explanation, and I've stopped treating it as the anomaly. It caught my eye, but it's not the thing that held up. The question count is.

The community signal (that's you all). The original thread hit #1 here. The consensus was that 90 was anomalous. Folks shared their own counts — all at or above the 100 minimum. Nobody who replied could point to a normal session that ended below the floor.

The log. I formally requested the Pearson VUE event log — the one artifact that could actually confirm or rule out a technical fault. It never came. Enough time has passed that I'm no longer counting on it. In an investigation, the request for comment that goes unanswered doesn't end the story; the non-response becomes part of the record.

What I'm NOT claiming: that I definitely hit a technical error, or that anyone's results are routinely wrong, or that the system is broken. I don't have the log. I can't prove what happened at question 90.

What I AM saying: the data doesn't fit a clean session. The one fact that survived every attempt to explain it away is a question count that the exam's own published rules don't account for. ISC² granted me a complimentary retake — which is consistent with their standard policy, so I'm not leaning on it as proof of anything. It's just part of the record.

The retake is August 15. That'll be my clean shot at it, and I'll walk in reading the session with the same clear eyes.

Mostly I'm posting this because when my session felt off, I didn't know I had options. You can request an inquiry. You can ask for the event log. You can document what you saw and escalate it. Nobody tells candidates that, and I wish someone had told me. If your session ever feels wrong — write down everything while it's fresh.

Thanks again to everyone who chimed in on the first thread. You helped me trust that the anomaly was real and worth chasing.

reddit.com
u/iris925 — 24 days ago

I made a free beginner roadmap you can work through in any order — looking for feedback on what's missing

One thing I struggled with when I started learning cyber was the order-of-operations problem. Every roadmap assumed you'd do things in a specific sequence — but "learn networking" assumes Linux, which assumes the command line, which assumes… and it turns into something overwhelming before you've actually done anything.

So I made a simple board of 25 beginner steps you can tackle in any order — things like learning the CIA triad, completing your first TryHackMe room, reading a real incident report, writing your first SQL query, understanding common threats. The point is less about sequence and more about making the path feel finite and checkable instead of infinite.

Full disclosure: this is mine, and I used AI as a tool to help build it — but the roadmap itself, the 25 steps, the "ordering is a trap" idea, all of it comes from my own path into cyber from a data background. It's free, no signup needed to use it, and it saves your progress in your browser.

I'm sharing it here because this sub is exactly who I built it for, and I'd genuinely like feedback from other learners: is there a beginner step you think belongs on it that I left off? Anything on it you'd cut?

labs.datasecchronicles.com/bingo/

reddit.com
u/iris925 — 1 month ago

How Holidays Change Behavior in Security - and Why That Matters More Than We Think

Happy 4th! Wrote a quick post today on something I keep thinking about, holidays don't weaken systems, they change how we interact with them.

New login locations, mobile dashboards instead of full setups, faster approvals because of someone's waiting, assumed coverage because someone else is watching it. That is where risk quietly creeps in.

The 10 AM weekday login vs the 2 AM holiday weekend login from a new location - same action, completely different signal. That's what baseline behavior is actually for.

Curious if anyone in the SOC space notices upticks in alerts or incidents around long weekends - would love to hear from people who've seen this firsthand.

Full post here if interested: Datasec Chronicles - 4th of July + Cybersecurity Thoughts

u/iris925 — 2 months ago
▲ 7 r/isc2

Failed ISC2 CC on First Attempt - Here's What I Learned

I'm a Data Analyst currently transitioning into cybersecurity and I took the ISC2 CC exam on June 20th and didn't pass. I'm a little down but I have a much clearer picture of the exam now.

​

Quick recap:

​

The adaptive format ended before 100 questions with over 60 minutes still left. That threw me off a bit.

​

I really struggled with the "Least", "Most", "Minimum" and "Best" style questions even though I thought I understood the concepts.

​

Performance-wise: Above Proficient in Domain 4 (Network Security) - which I actually thought was my weakest area going in. But Below Proficient in Domain's 1, 2, 3 and 5, which I believed were my stronger ones (I was scoring over 85% in practice tests). The mismatch was eye-opening.

​

I walked away with way better test-taking awareness and a solid list of topics to drill deeper. Planning to retake in about 30 days.

​

Has anyone else had a similar experience where your strong/weak domains flipped on the real exam?

​

Looking for advice on:

​

Tips on handling those tricky "Least/Most/Best" questions

​

How you adjusted your study approach after a first fail

​

Any other lessons from your CC journey

​

Appreciate any feedback or shared experiences. Thanks in advance - this community has been helpful already!

​

​

reddit.com
u/iris925 — 2 months ago