Phase 9: Integration & Cross-Domain Practice

Phase 9: Integration & Cross-Domain Practice

Timeline: May 24-27 (Week 8, first half)

Stop studying individual domains. Start thinking across domains. CISSP questions often test concepts that span multiple domains.

Cross-Domain Connections

Connection Domains Involved

Risk assessment informs access control

Domain 1 (Risk) → Domain 5 (IAM)

Encryption protects data in all states

Domain 3 (Crypto) → Domain 2 (Asset Security)

Incident response requires logging

Domain 7 (Operations) → Domain 6 (Assessment)

Secure SDLC includes code review AND pen testing

Domain 8 (Software) → Domain 6 (Assessment)

Network security controls implement risk decisions

Domain 4 (Network) → Domain 1 (Risk)

DR/BCP protects availability (CIA)

Domain 7 (Operations) → Domain 1 (Risk)

Identity federation requires crypto (SAML/OIDC tokens)

Domain 5 (IAM) → Domain 3 (Architecture)

Full Practice Exams

Target: 80%+ on each full practice exam
Schedule:
  May 24: Boson Practice Exam #1
  May 25: Review missed questions, study weak areas
  May 26: Boson Practice Exam #2
  May 27: Review missed questions, targeted study

Exam Mindset Drills

For each practice question, apply this 5-step process:

  1. Read the question twice — what are they ACTUALLY asking?

  2. Eliminate two answers — usually one is absurd, one is too technical

  3. Think like a CISO — which answer is most managerial/complete?

  4. Safety first — if human life is involved, ALWAYS choose safety

  5. Don’t overthink — first instinct is usually right after study

Weak Area Focus

After practice exams, identify your bottom 2 domains by score and do targeted review:

# Track domain scores
# Domain | Exam 1 | Exam 2 | Target
# 1      |   %    |   %    | 75%+
# 2      |   %    |   %    | 75%+
# ...
# 8      |   %    |   %    | 75%+
Check Status

Boson Practice Exam #1 completed

[ ]

Score: _% (target 80%+)

[ ]

Weak domains identified and reviewed

[ ]

Boson Practice Exam #2 completed

[ ]

Score: _% (target 80%+)

[ ]

Cross-domain connections understood

[ ]