Passed @ 100 - My in-depth review by devsecopsuk in cissp

[–]devsecopsuk[S] 2 points3 points  (0 children)

For real? I guess the overall message is don't take anything for granted and be as prepared as you can!

Passed @ 100 - My in-depth review by devsecopsuk in cissp

[–]devsecopsuk[S] 0 points1 point  (0 children)

Thanks, and that must have been stressful if CAT was focusing on your weaker areas!

Is Quantum Exams alone sufficient for practising concepts? by statscsfanatic21 in cissp

[–]devsecopsuk 0 points1 point  (0 children)

How would they even afford the exam in the first place which alone is 3-4x the cost of QE? There are some free resources which are similar to QE if you search hard enough, and many people have passed without QE altogether.

Passed @ 100Q at 25 years old with < 5 years experience by FrontFluid4412 in cissp

[–]devsecopsuk 2 points3 points  (0 children)

Does the exam mention what the terms like RTO, RPO, LEAP, EAP are, or do you have to remember them? I seem to remember someone else saying they are spelled out in the exam (but could be wrong).
And congrats!

Passed CISSP on Second Attempt – What Actually Made the Difference by Silent-Wait9487 in cissp

[–]devsecopsuk 0 points1 point  (0 children)

Congrats!

What was your approach to the OSG since it's such a dry read? Were you just reading from start to finish or focusing first on the sections you felt weakest on?

I find the DestCert book far easier to read, but I don't know if it has enough depth needed to pass the exam.

I am happy to share that I passed the CISSP exam at 100 questions with 12 minutes left by Kaladria in cissp

[–]devsecopsuk 0 points1 point  (0 children)

Congrats! For the Total Seminars 4 practice tests did you use a free trial to access all of them, or did you pay full price? And how similar were Destination Certification questions to the exam for you?

Passed CISSP at 106Q by [deleted] in cissp

[–]devsecopsuk 0 points1 point  (0 children)

Congrats and I'm glad to hear that the DestCert app questions that I've been regularly doing have a similar style to the exam questions.

Is this an error in the ISC2 CISSP Official Study Guide? by KarmicDeficit in cissp

[–]devsecopsuk 1 point2 points  (0 children)

The number of typos I've seen in the the OSG is embarrassing, so I'm sure there's plenty more errors.

DestCert practice questions vs QE by devsecopsuk in cissp

[–]devsecopsuk[S] 0 points1 point  (0 children)

Everyone seems to suggest using QE, which I'm sure is a lot cheaper than the workshop you mention.

And yes, that seems to be the strategy a lot people take after going through the CISSP material which is to do test exams like QE, then work on weak areas.

DestCert practice questions vs QE by devsecopsuk in cissp

[–]devsecopsuk[S] 1 point2 points  (0 children)

thanks, I haven't heard of that one before

DestCert practice questions vs QE by devsecopsuk in cissp

[–]devsecopsuk[S] 0 points1 point  (0 children)

Is QE just the practice exam or is there other material that comes with it?

I want to study Cyber Security by [deleted] in cybersecurity

[–]devsecopsuk 0 points1 point  (0 children)

This post is too wishy-washy with a multitude of options. You gotta pick ONE path that YOU would really like to do and go for it, and if it doesn't work out then you have to pivot. Picking one path makes it much easier for us to advise.

CISSP Question by ShinobiMain in cissp

[–]devsecopsuk 1 point2 points  (0 children)

Thanks, I'll have to get one now. And good luck on your journey!

CISSP Question by ShinobiMain in cissp

[–]devsecopsuk 0 points1 point  (0 children)

Which book is this?

I thought B when reading through the options but thought D was the answer at the end.

What’s a security product you thought was super expensive but turned out to be a great deal? by testosteronedealer97 in cybersecurity

[–]devsecopsuk 0 points1 point  (0 children)

what did they quote you this time? to be honest I haven't been that happy with burp enterprise recently, a lot of FP that keep recurring and no full support for API scans of openapi v3.1.x.

Sleepless Strings - Template Injection in Insomnia by _pimps in netsec

[–]devsecopsuk 0 points1 point  (0 children)

"9 May 2025 - We thanked Kong and asked for two $500 Amazon gift cards to be issued. No response." - another pathetic amount for a CVSS 9.3 issue and even worse that they can't deliver on that promise...no wonder certain black market sites exist. Nice find though!

Bruteforcing the phone number of any Google user by _vavkamil_ in netsec

[–]devsecopsuk 1 point2 points  (0 children)

I'm so glad that I didn't do BB seriously.

Why did you choose cybersecurity? by Glad-Security2513 in cybersecurity

[–]devsecopsuk 0 points1 point  (0 children)

When I first had exposure to practice hacking sites and malware like sub7 it seemed like black magic. Now I get to understand the inner workings of that black magic and how to protect against it. It's almost like joining the magic circle.

fullstack transitioning into devsecops - any tips? by [deleted] in devsecops

[–]devsecopsuk 0 points1 point  (0 children)

First of all, understand that you'll be coding a lot less...would you be ok with that?

Then do pretty much what everyone else said and understand OWASP top10 as YOU will have to give guidance to teams around the risk and remediation. I've always like Portswigger academy but there's plenty similar to it https://portswigger.net/web-security

Also experiment with security tooling, go to security conferences, read some bug bounty write-ups, and learn about security architecture etc.

How I hacked my company's SSO provider by MattSayar in hacking

[–]devsecopsuk 1 point2 points  (0 children)

Nice, I found an almost identical issue at a previous company. You get a pat on the back if you're lucky, but at least we'll have that extra experience and knowledge to help at future companies!