My experience passing CISSP exam 2013

Finally, after 14months or revision I passed my exam February 2013. I have put together 5 top tips on how to pass the dreaded exam
March 17, 2013
CISSP

1. Know every angle of each topic

When I failed in the pass, came to realize that my knowledge wasn't in-depth enough. I knew the syllabus front-to-back, though I didn't know the comprehensive relations between each other. For example, I know about RADIUS, Diameter and TACACS and all the characteristics, though I didn't know when you should use RADIUS over TACACS. Diameter is easier to understand because it's an enhancement over radius, though do you know when you should use RADIUS over Diameter? If I know RADIUS and TACAS, though not Diameter, then it's pointless knowing only 2 out of the 3, because you need to know the understanding between them all.


2. Don't rely on just one book

My previous mistake before was to read the Shon Harris 'All in one' book. Which you would assume has 'all the information' for the exam. You would be naive to think this because the exam is all about understanding concepts, not about "I know blah blah blah".

I have read some CISSP books gave the description of a particular topic then read the same topic in another book. You will be surprised on the difference. I would propose getting 3 books.

  • One very concise (I recommend Shon Harris all in one)
  • Cram exam book, (I recommend the Gibson cram book)
  • Something in the middle (maybe a new edition of your choice)


3. Know your stuff!

Every easy to say, very hard to achieve. This is very similar to number 1, though it's easier to say something like this and forget it without understanding the paramount objective.... you need to know the in's and out's along with scenarios and reason why you would use something over something else, not just the understanding of a topic.

For example:
Diffe-Helman was the first cryptographic algorithm for key exchange. It is however common to man-in-the-middle attacks and blah blah blah

This can all be useless because it's not explaining you the reason WHY it's used in situations or why you would use it over RSA or ECC, because they do key exchange plus more! So why use Diffie-Hellman at all?

(Hint: Diffie-Hellman is commonly used with Virtual Private Network (VPN). If that VPN is operating on the IPSec standard, then Diffie-Hellman is certainly in use).

Now think of a scenario on why you would use ECC for key exchanges over Diffie-Hellman or RSA...

I would recommend constructing a matrix all the possibilities of a particular topic. Fire extinguishers or which glass to use are easy ones for example.


4. Use every material possible

Books, forums, practice questions, audio books, videos etc. should all be used. Don't be an idiot and rely on the 'all-in-one' book


5. Dedicate and devote your time

The thing about the CISSP exam is that the syllabus is so large, once you've read the 1000+ book, you've probably forgot what the first chapter was all about. To put things in perspective, I read the book on the train and read the book when in bed, though I would be revising 10-14hrs a day for the remaining 3 weeks just so the CISSP is constantly on my mind. I also replaced my rocky songs to the CISSP audio whist at the gym or walking from one place to another. I was like a machine soaking in the final phase of the revision though I was happy I did this because the exam was much easier this time round, even though I failed by 1% last time.

About the author

Daniel is a Technical Manager with over 10 years of consulting expertise in the Identity and Access Management space.
Daniel has built from scratch this blog as well as technicalconfessions.com
Follow Daniel on twitter @nervouswiggles

Comments

Other Posts

AWS-PHP integration - Email not sent. SMTP Error: Could not authenticate.

phpsmtpaws

February 6, 2020
Created by: Daniel Redfern
AS I was migrating my environment into an S3 environment, I wanted to leverage off the SES services that AWS provide, more specifically, to leverage the off the SMTP functionality by sending an email via PHP
Read More...

SOLUTION: no headers files (.h) found in softwareserial - Arduino

Arduino

February 24, 2019
Created by: Daniel Redfern
The WeMos D1 is a ESP8266 WiFi based board is an extension to the current out-of-the-box library that comes with the Arduino installation. Because of this, you need to import in the libraries as well as acknowledging the specific board. This process is highly confusion with a number of different individuals talking about a number of different ways to integrate.
Read More...

NameID element must be present as part of the Subject in the Response message

ShibbolethSAML

August 7, 2018
Created by: Daniel Redfern
NameID element must be present as part of the Subject in the Response message, please enable it in the IDP configuration.
Read More...

HOW TO provision AD group membership from OpenIDM

OpenIDMICFAD-connector

June 15, 2018
Created by: Daniel Redfern
For what I see, there's not too many supportive documentations out there that will demonstrate how provision AD group membership with the ICF connector using OpenIDM. The use of the special ldapGroups attribute is not explained anywhere in the Integrators guides to to the date of this blog. This quick blog identifies the tasks required to provision AD group membership from OpenIDM to AD using the LDAP ICF connector. However this doesn't really explain what ldapGroups actually does and there's no real worked example of how to go from an Assignment to ldapGroups to an assigned group in AD. I wrote up a wiki article for my own reference: AD group memberships automatically to users This is just my view, others may disagree, but I think the implementation experience could be improved with some more documentation and a more detailed example here.
Read More...

ForgeRock OpenIDM - InvalidCredentialException: Remote framework key is invalid

ICFIDMOpenIDMOpenICF

November 8, 2017
Created by: Daniel Redfern
In the past, the similar error occurred though for the Oracle Identity Management solution. invalidcredentialexception remote framework key is invalid Because they all share the ICF connector framework, the error/solution would be the same.
Read More...

org.forgerock.script.exception.ScriptCompilationException: missing ; before statement

IDMsync.confforgerockopenidm

November 8, 2017
Created by: Daniel Redfern
org.forgerock.script.exception.ScriptCompilationException: missing ; before statement
Read More...

ForgeRock IDM - org.forgerock.script.exception.ScriptCompilationException: missing ; before statemen

OpenIDMsync.confForgeRock

September 17, 2017
Created by: Daniel Redfern
ForgeRock IDM - org.forgerock.script.exception.ScriptCompilationException: missing ; before statement
Read More...

Caused by: org.forgerock.json.resource.BadRequestException: Target does not support attribute groups

OpenIDMForgeRockICFConnector

September 17, 2017
Created by: Daniel Redfern
When performing the attempt of a reconciliation from ForgeRock IDM to Active Directory, I would get the following error
Read More...

ForgeRock OpenIDM - InvalidCredentialException: Remote framework key is invalid

OpenIDMForgeRockICFConnectorAD

September 17, 2017
Created by: Daniel Redfern
In the past, the similar error occurred though for the Oracle Identity Management solution. invalidcredentialexception remote framework key is invalid Because they all share the ICF connector framework, the error/solution would be the same.
Read More...

ERROR Caused by com.google.api.client.auth.oauth2.TokenResponseException 400 Bad Request - invalid_g

OpenIDMIDMGoogleGoogle-AppsICFreconciliation

September 12, 2017
Created by: Daniel Redfern
During the reconcilation from OpenIDM to the ICF google apps connector, the following error response would occur. ERROR Caused by com.google.api.client.auth.oauth2.TokenResponseException 400 Bad Request - invalid_grant
Read More...