8 August 2026
How I Prepared for CISSP and CCSP — and Passed Both First Time
The study approach I used for CISSP and CCSP: ISC2 official material, instructor-led training, practice questions, Pete Zerger's Last Mile resources, and more than 20 years of practical experience.
I have taken a lot of technical certifications over the years, across Microsoft, AWS, Google Cloud, Cisco, VMware, security and architecture.
CISSP and CCSP were different.
They are not exams I would approach by trying to memorise a large collection of facts the night before. They test whether you can recognise the best answer in context, often when several answers look technically possible.
I passed both exams first time.
There was no single magic resource behind that. My preparation was a combination of:
- the official ISC2 course books
- ISC2 instructor-led training
- large numbers of online practice questions
- Pete Zerger’s The Last Mile material and Inside Cloud and Security training
- and, importantly, more than 20 years of working with infrastructure, cloud, identity, networking and security
This is the approach that worked for me.
This is my personal study experience, not a guaranteed formula for passing either exam. Exam objectives and formats change, so always start with the current ISC2 exam outline.
Experience helps — but it does not replace studying
Coming into CISSP and CCSP with a long infrastructure and architecture background was useful.
I had already spent years dealing with many of the things the certifications describe:
- identity and access
- Active Directory
- networking
- cloud architecture
- business continuity and disaster recovery
- infrastructure security
- governance
- risk
- operational security
- Azure, AWS and Google Cloud
- Zero Trust
- automation and change control
That makes some concepts much easier to understand because they are not abstract.
When a book talks about least privilege, separation of duties, recovery objectives, identity federation, shared responsibility or network segmentation, I can associate those concepts with systems and decisions I have encountered in practice.
But experience can also work against you.
In the real world you may know how your organisation would solve a problem.
The exam is asking something different:
Given the information in this question, what is the best answer from the perspective expected by the certification?
Those are not always the same thing.
That distinction was one of the most important parts of my preparation.
My study stack
I deliberately used several different learning methods rather than depending on one source.
1. ISC2 official course material
The official material gave me the baseline.
I wanted my preparation anchored to the terminology, domains and concepts ISC2 expected me to understand rather than relying entirely on third-party summaries.
For both certifications I worked through the course material and used it to identify areas where my practical knowledge was weaker.
That last part matters.
Someone coming from networking will have different gaps from someone coming from governance, software development or risk management.
The goal is not to spend equal time on everything.
It is to find the areas where your knowledge is uneven.
2. Instructor-led training
I also used instructor-led training.
For me, its value was not simply having someone read material from slides.
A good instructor gives you another way of looking at a concept.
It also gives you opportunities to ask:
- Why is that answer better?
- What distinction is the exam making?
- Where do people commonly misunderstand this?
- How does ISC2 frame this subject?
Those conversations help turn a definition into something you actually understand.
Instructor-led training also imposed some structure on the preparation. With a large syllabus, that is useful.
3. Practice questions — lots of them
Practice questions were a major part of my preparation.
Not because I expected to see the same questions in the real exam.
The useful part was learning how to reason through the question.
For every question I got wrong, I wanted to know why.
I also paid attention to questions I got right for the wrong reason.
That distinction is important.
Guessing correctly does not mean you understand the subject.
My process became roughly:
Read the question carefully
↓
Identify what is actually being asked
↓
Remove obviously incorrect answers
↓
Compare the remaining plausible answers
↓
Choose the BEST answer
↓
Review the explanation
↓
Understand why the alternatives were weaker
The explanation after the question was often more useful than the score.
Don’t just memorise the answer
If you repeatedly answer the same question bank, eventually you start recognising the question.
That creates false confidence.
You are no longer solving:
Which control is most appropriate here?
You are remembering:
Last time I selected C.
Those are completely different skills.
I tried to focus on the principle behind the answer.
A useful test is:
Could I explain why this answer is correct without seeing the four options?
If not, I probably had more work to do.
Pete Zerger and “The Last Mile”
One set of resources I found particularly useful was Pete Zerger’s Inside Cloud and Security material.
For my preparation I used his CISSP: The Last Mile and CCSP: The Last Mile resources alongside his video content.
What I liked about this material was where it fitted into my study process.
I did not use it as a replacement for the official material.
I used it closer to the end.
By that stage I had already covered the syllabus and answered a lot of questions. What I wanted was something that helped consolidate the material and expose areas that still felt weak.
That is exactly where the idea of a last mile makes sense.
The goal changes from:
Learn the entire subject.
to:
Find the gaps that could still cost me marks.
Useful resources:
The mindset shift
One of the biggest changes I made was moving away from thinking purely like the engineer who has been asked to fix something.
Engineers naturally want to solve the technical problem.
Security and architecture questions may require you to think first about:
- business requirements
- risk
- policy
- governance
- legal and regulatory obligations
- data ownership
- roles and responsibilities
- process
- and only then the technical control
A question might contain an answer that would technically fix the immediate problem.
That does not automatically make it the best answer.
Sometimes the better response is to understand the requirement, assess the risk, follow the appropriate process and then select the control.
That way of thinking is especially important for CISSP.
CISSP and CCSP overlap — but they are not the same exam
There is useful overlap between the certifications.
Concepts such as:
- risk management
- identity
- cryptography
- business continuity
- legal and regulatory considerations
- application security
- data security
appear in both worlds.
But I would not treat CCSP as simply “CISSP with some cloud questions”.
Cloud changes the context.
You need to think about:
- shared responsibility
- cloud service and deployment models
- cloud data lifecycle
- provider responsibilities
- portability and interoperability
- virtualisation
- cloud infrastructure
- cloud application security
- cloud operations
- contracts, audit and assurance
For someone already working across Azure, AWS and Google Cloud, a lot of this feels familiar.
Again, though, practical familiarity is not enough. You still need to understand the formal security concepts and terminology around it.
How I used my final revision period
Towards the end, I stopped trying to consume huge amounts of new material.
I concentrated on weaknesses.
My final revision loop looked more like this:
Practice questions
↓
Identify weak domain
↓
Return to official material
↓
Use concise revision material
↓
Explain the concept to myself
↓
More questions
If I repeatedly missed questions on the same subject, that was telling me something.
Rather than answering another hundred random questions, I would go back and fix that specific gap.
Build connections between concepts
One thing that helped me enormously was connecting exam concepts to things I had actually built or operated.
For example:
Least privilege
→ administrative roles and Zero Trust policy
Identity federation
→ Entra ID / SAML / OIDC
Network segmentation
→ traditional networks and Zero Trust private access
Shared responsibility
→ Azure / AWS / Google Cloud
Change control
→ CI/CD and policy-as-code
Business continuity
→ datacentre, cloud and DR architecture
Device trust
→ endpoint compliance and device posture
That made the material easier to retain because I was not learning isolated definitions.
I was attaching formal terminology to practical experience.
If you do not yet have that experience, build examples.
Draw architectures. Create scenarios. Ask yourself where responsibility sits and what happens when a control fails.
The exam is not the objective
This is probably the most important point.
Passing the exam is obviously the immediate goal.
But if everything disappears from memory two weeks afterwards, the certification has limited value.
The useful outcome is being able to take something from the syllabus and recognise it later in an architecture discussion.
You want to be able to say:
This is the risk-management concept I studied.
or:
This is exactly the shared-responsibility problem the CCSP material was describing.
That is where certification starts becoming professionally useful.
What worked for me
If I condensed my preparation into a sequence, it would be:
1. Start with the current exam objectives
↓
2. Work through official ISC2 material
↓
3. Use instructor-led training to deepen understanding
↓
4. Answer lots of quality practice questions
↓
5. Investigate every weak area
↓
6. Use concise resources for final consolidation
↓
7. Connect theory to real-world examples
↓
8. Practise selecting the BEST answer
↓
9. Stop cramming and trust the preparation
↓
10. Sit the exam
That approach worked for me twice: first-time passes for both CCSP and CISSP.
What I would recommend to someone starting now
Do not start by buying ten books and subscribing to five question banks.
Start with the exam outline.
Understand the size of the syllabus.
Choose one strong primary source.
Then add resources because they solve a specific problem:
| Need | Resource type |
|---|---|
| Understand the official syllabus | ISC2 material |
| Structured learning | Instructor-led course |
| Test understanding | Practice questions |
| Hear concepts explained differently | Video training |
| Final consolidation | Last-mile/revision material |
| Make it stick | Practical examples and experience |
More material is not automatically better preparation.
The goal is understanding, not collecting resources.
Twenty years of experience — and still studying
I had more than 20 years of technical experience when preparing for these exams.
I still studied.
I still found areas I did not know well enough.
I still got practice questions wrong.
And that is part of why I value certifications like these.
Used properly, they force you outside the parts of technology you work with every day.
CISSP makes an engineer think more broadly about security, risk and the organisation.
CCSP forces cloud practitioners to look beyond deploying services and think about security architecture, governance, data and responsibility across the complete cloud lifecycle.
Passing is satisfying.
But filling those gaps is the part that lasts.
Resources I used
ISC2
- Official ISC2 CISSP / CCSP course material
- ISC2 instructor-led training
- Practice questions and exam preparation
Pete Zerger — Inside Cloud and Security
- CISSP: The Last Mile
- CCSP: The Last Mile
- Inside Cloud and Security on YouTube
- Pete Zerger on LinkedIn
Certification objectives, training materials and exam formats change. Check the current ISC2 exam outline and current versions of any third-party study resources before beginning your preparation. This article describes my own study experience and is not affiliated with or endorsed by ISC2 or the resource authors mentioned.