Skip to main content
  1. Blog/
Journey

The Day I Got a Second Birthday

How failing the CISSP became the beginning of the journey that eventually helped me pass it.

Mete Demirci
Author
Mete Demirci
Documenting a cybersecurity journey through practical work, technical depth, and honest reflection.
Editorial basis First-hand experience Last reviewed How MeteSec verifies content

Starting now, whenever people ask me when my birthday is, I will tell them I have two.

One is my actual birthday.

The other is August 22, 2026—the day I passed the CISSP exam.

Getting there took much longer than I originally expected. It began with an ambitious decision at the start of my cybersecurity career, continued with a spectacular first failure and eventually became a lesson in what experience changes that studying alone cannot.

It Started Right After University
#

When I finished my undergraduate degree and started my first cybersecurity job, I already knew about the CISSP.

It was one of those certifications people seemed to discuss everywhere: at work, online, in forums and anywhere else cybersecurity professionals gathered. There was one point on which almost everyone agreed:

The questions are hard.

Not necessarily because every topic is impossible to understand, but because of the way the questions are written. People told me there would always be two answers that seemed correct. They said I could know the material and still have no idea what the exam wanted from me.

I was not even planning to take the exam yet, and somehow people were already making me nervous about it.

Then my employer gave me the opportunity to choose a training course and certification exam. I received an Excel sheet full of options and essentially thought:

Well… why not pick the biggest one?

From my initial research, CISSP was one of the most expensive certifications on the list—and certainly one of the hardest. An intensive training course through Firebrand was available as well. This is not an advertisement; I only knew that Firebrand had a reputation for concentrated bootcamps.

My logic was simple. If I could somehow earn the CISSP near the beginning of my career, it would be an extraordinary head start. I would hold one of the industry’s most recognized certifications while many people who had started around the same time were still deciding which certification to pursue first.

So naturally, I picked CISSP.

My First Attempt
#

The training experience itself was excellent. We stayed at Göbel’s Hotel Rodenberg near Rotenburg an der Fulda, with almost everything organized around learning.

The setting was unusually good for an intensive week of cybersecurity study. Readers who want to see it can view the hotel and its surroundings on Booking.com and the terrace where we had dinner on Hotels.com.

We could use the pool, sauna and other hotel facilities whenever we had some downtime. There was an open buffet, the food was great and the entire place somehow felt relaxed while still making it easy to stay focused.

We needed that balance because we studied for something like twelve hours a day.

It was intense, but I genuinely enjoyed it. We could spend the whole day completely locked in, then eat outside, switch our brains off for a moment and start again the following morning. Our highly sophisticated recovery strategy after twelve hours of CISSP material was dinner with a view.

Then came the exam.

And I completely failed.

Not almost passed. Not one domain was slightly below proficiency.

I mean failed failed.

Of all eight CISSP domains, there was only one in which I had achieved a sufficient level:

Identity and Access Management.

That was it. Seven domains essentially looked at me and said: Maybe come back later.

That was the moment I understood that CISSP really was as difficult as people had told me—perhaps even more difficult. There was no shortcut. Throwing myself into an intensive course at the beginning of my career could not magically replace years of knowledge and experience.

So I moved on.

Building the Knowledge First
#

Over the following years, I kept working in cybersecurity. I completed other certifications, worked with different technologies and learned more about security operations, identity, cloud security, infrastructure, networking, governance and risk management.

Slowly, topics that had felt abstract during my first attempt began to make much more sense.

Eventually, I received another opportunity to take the CISSP exam. This time, I wanted to do it properly.

And I studied. A lot.

My preparation combined Pocket Prep, practice questions, mock exams and video courses. Through Udemy Business, I completed two substantial CISSP courses containing roughly 40 to 60 hours of material each. That alone amounted to more than 100 hours of video.

On top of that came approximately 50 to 60 hours of practice questions, probably more. I worked through roughly 1,500 questions, including around 1,000 through Pocket Prep, and completed somewhere between 20 and 30 mock exams.

By the end, answering CISSP-style questions had become part of my daily routine.

Then I encountered one small logistical problem.

Apparently Nobody Wants to Take Exams During Summer
#

I was ready—or at least as ready as I was ever going to be.

But in the middle of summer, nearly every testing center near me seemed to have decided that exams were no longer a thing. There were no suitable appointments available.

After investing so much time in studying, I did not want to wait several more weeks and slowly start forgetting the details. So I did the completely reasonable thing:

I booked the CISSP exam in Frankfurt and travelled there specifically to take it.

Exam Day
#

I arrived at the testing center early. Very early.

I hoped they might let me begin ahead of schedule if someone else finished early. That had worked for me with other exams before.

Not this time.

The testing room was full. Many of the people there appeared to be taking the MCAT, the examination used for admission to medical schools in the United States. The important thing I learned about the MCAT that day is that its candidates apparently sit there for around seven or eight hours.

That is fantastic when you are in a waiting room hoping somebody will finish early.

I waited for roughly two hours. Then it was finally my turn.

I walked into the exam room, sat down and started.

Nothing Like the Mock Exams
#

The real CISSP questions were hard. Really hard.

What surprised me most was how different they felt from almost everything I had practised. I had completed dozens of mock exams, answered more than a thousand practice questions and watched more than 100 hours of CISSP courses. Yet many real questions still felt unfamiliar.

They were not simply asking:

Do you know what this technology does?

They were asking:

Do you understand the situation, the business context, the security implications, the responsibilities involved and what should happen FIRST, BEST or MOST appropriately?

Sometimes I understood every concept mentioned in a question and still stared at the four answers thinking: What exactly do you want from me?

The best description I can give is this: two answers are obviously wrong. Two look almost identical. Somehow one of them is still supposed to be more correct than the other.

After a while, CISSP questions begin to feel less like a security exam and more like this:

A parody multiple-choice question asking for the most appropriate first step when opening a door

An original parody of the CISSP decision-making experience—not a real exam question and not reproduced exam content.

The real questions obviously do not look like that. Mentally, however, that is exactly how it feels after staring at two almost equally plausible answers for five minutes.

That is where one of the most useful ideas from my preparation became important.

Finding the Golden Answer
#

With many CISSP questions, you can eliminate two answers relatively quickly. Then you are left with two options that both appear correct.

Somewhere between those two is what I began thinking of as the golden answer.

It is not merely technically correct. It is the answer that best fits the perspective the question expects from the security professional in that situation.

During the exam, I had to fight my own instincts several times. The technical part of my brain would say:

Pick this one. Fix the problem.

Then another part would respond:

You are not the engineer right now. Think about risk. Think about the business. Think about responsibility. What should happen first?

I repeatedly selected an answer, looked at it again and forced myself to challenge the reasoning behind it.

Not simply:

Is this answer correct?

But:

Is this the best answer?

Apparently, that worked.

And Then It Was Over
#

Eventually, the exam ended.

And I passed.

Years after failing my first attempt. After building my cybersecurity career, completing other certifications, working on projects, investing hundreds of hours in preparation, answering more than a thousand practice questions, taking dozens of mock exams, travelling to Frankfurt and waiting two hours beside people preparing to spend their entire day taking the MCAT.

I had finally passed the CISSP exam.

That is why August 22, 2026 will stay in my mind for a very long time.

My first attempt taught me something important:

Sometimes you are simply not ready yet—and that is fine.

Failing CISSP the first time did not mean I could never pass it. It meant I needed more knowledge, more experience and more time. The bootcamp showed me the size of the field. The years afterwards gave many of those subjects a real context. When I returned to the exam, I was not only better prepared; I was looking at the questions from a different point in my career.

So yes: from now on, I have two birthdays.

And one of them is August 22.

Related

Where My Cybersecurity Journey Began

··2424 words·12 mins
Before I started studying for my first certification, I did something that was probably both useful and slightly insane. I researched almost the entire certification ecosystem. Before answering a single practice question, I looked at the different providers, their certification paths, how employers viewed them, how useful their content appeared to be and where they seemed to fit into an actual IT or cybersecurity career. I looked at CompTIA, Cisco, Microsoft, AWS, ISC2, ISACA, OffSec, GIAC and many others. I compared entry-level certifications, professional certifications, technical certifications, management certifications and certifications that seemed to exist mainly because companies like putting logos into job descriptions.

Why I Built MeteSec

MeteSec started with a fairly simple realization: I understand things much better when I have to put them into words. Reading documentation, completing a course or working through a lab can create the feeling that a topic makes sense. Sometimes it really does. At other times, you only notice the gaps when you try to explain the same subject without looking at the original material. Writing changes the way I engage with a topic. I have to decide what the main point actually is, which details matter and how the individual pieces connect. I have to question whether I understood the reasoning or merely remembered the result. If I cannot explain something clearly, there is a good chance that I have not understood it as well as I thought.

Cybersecurity verstehen: Rollen, Wege und Einstiegsmöglichkeiten

·299 words·2 mins
Presented as a job I/O Deep Dive together with Leon Rohde from Deloitte, this session provides an accessible map of the cybersecurity field for people who are still deciding where they might fit. About the Host # job I/O by get in IT is a virtual live-event format for IT talent and professionals. It combines technical Deep Dives with career perspectives and direct insights from employers, while recorded sessions remain available through the get in IT magazine.
Continue exploring

Go beyond this article