Getting Through the CISSP With Shon Harris

The Cissp Study Guide Shon Harris has been around long enough that people either swear by it or completely dismiss it, usually based on secondhand opinions rather than actual experience. I went through it twice, once when I was fresh out of CompTIA Security+ and thought reading a 1,100-page book would be enough, and again seven years later when I actually had real-world experience and could see where the explanations fell short. The book covers all eight domains like any other review guide does. Access control, cryptography, network security, incident response, business continuity, application security, legal and investigations, and risk management. The difference with Harris versus Kimbrell or Stewart is how she presents each topic. She starts broad, then drills down into sub-objectives with detailed bullet points. Some of those bullet points read like textbook excerpts because they basically are. The chapter on cryptography alone runs about 60 pages and still doesn't fully explain the math behind RSA key generation, which is fine for CISSP since you don't need to compute anything by hand. Here is what nobody tells you about the practice questions in the book. They are significantly easier than the actual exam. I remember finishing a practice test with a score in the high 80s and feeling confident until I logged into the official ISC2 practice portal and saw my real performance drop to the mid-60s. The Harris questions tend to ask straightforward recall questions. The actual CISSP asks scenario-based questions that require you to pick the BEST answer among four plausible options. You will get tripped up on questions where two answers look correct but one is more aligned with the CISSP mindset of risk management over technical fixes.

When I first studied, I made the mistake of memorizing answers instead of understanding the reasoning. That worked for the book quizzes. It failed on the real exam. One question asked about handling a suspected breach. I picked "contain the incident immediately" because that is what I would do in a SOC. The correct answer was "evaluate the scope and impact first." The exam wants you to assess before you act, even though real-world urgency sometimes demands immediate containment. You have to learn to think like a policy writer, not a technician. The book has gaps. Chapter 2 on access control models is thorough but skips over newer concepts like zero trust architecture and conditional access. If you are studying in 2025 or later, you will need supplementary material for those topics. Also, the law and legal section is US-centric. If you are studying for a non-US exam or working in GDPR-heavy environments, the compliance discussion feels thin. I used this guide alongside the official CISSP Official Study Guide from ISC2 and a subscription to Mike Chapple's practice exams. The Harris book served as my domain reference. When I hit a weak area, I read the corresponding chapter. When I needed exam-style questions, I switched to Chapple. This combination cut my study time by roughly half compared to relying on just one resource.

Another thing worth noting is that the 7th edition is outdated on mobile security. It discusses BYOD policies but doesn't address modern MDM solutions like Workspace ONE or Intune. The exam has moved toward cloud security and SaaS governance. Make sure you supplement with the Cloud Security Alliance guidance or at least read the ISACA cloud review guide sections. If you are on a tight budget, the Harris guide is cheaper than most alternatives and the content remains largely valid for the exam blueprint. But do not treat it as your only source. Pair it with a question bank that matches the difficulty of the actual exam, and you will spend less time confused on test day.

Get the Full Details

CISSP All-in-One Exam Guide by Shon Harris | Goodreads
CISSP All-in-One Exam Guide by Shon Harris | Goodreads

I keep meaning to return to this thread and update it with a few more things I’ve been thinking about lately, but honestly I just haven’t gotten around to it. Life got busy, the usual stuff, work piles up, kids need stuff, and before you know it a week has gone by and you’re still not back at your desk. Not complaining, just explaining. Maybe next weekend. Or maybe not. We’ll see.