I took the test last week and passed. I have years of experience in the field, implementing, supporting, and auditing, and I personally believe that more material is needed, and something very important: knowing how to apply the concepts.
Beyond the Official Course
While the official ISC2 Certified in Cybersecurity (CC) course is an excellent starting point, especially for building a solid foundation across the five key domains, the experience of professionals in the field suggests that you'll need more than just the course to ensure you pass.
A crucial aspect of this exam is the practical application of concepts, not just memorization. It requires a consultative rather than a purely technical mindset. This means you must understand how to use cybersecurity principles in real-world scenarios.
Key Strategies for Your Preparation:
- Domain 1: Your Foundation: Domain 1 (Security Principles) is the bedrock of the entire exam. Mastering these concepts, and crucially, knowing how to apply them, will give you a significant edge. Invest extra time in thoroughly understanding this domain.
- Essential Additional Resources:
- Official ISC2 Study Guide: This is the most comprehensive resource and is designed by the creators of the exam.
- Third-Party Courses (Udemy, LinkedIn Learning): Instructors like Thor (Udemy) or Mike Chapple (LinkedIn Learning) often offer deeper explanations and additional perspectives that complement the official material.
- Intensive Practice Questions: Don't limit yourself to the questions within the course. Seek out third-party practice exams (like those from Prabh Nair on YouTube) that force you to apply concepts and think consultatively. Analyze every incorrect answer to understand the "why."
- Focus on Application: Exam questions aren't just multiple-choice; they require you to apply your knowledge to different situations. Think about how access controls, risk management, or business continuity would be used in a real business context.
In summary, go beyond the theory. Supplement the official course with additional materials, focus on the practical application of security principles (especially those in Domain 1), and develop a consultative approach. Your experience in the field will be a major advantage if you channel it towards understanding how to apply these concepts!