Even een crosspost van Reddit.
Today I have passed my CCSP exam, before CCSP I also passed CISSP, CySA+ and Security+ in the last 12 months.
My background is 20 years in IT, whereof 11 years as IT manager for a manufacturing organization and the last 18 months as full-time security analyst.
I spent about 6 weeks learning for this exam, which took up most of my free evenings and weekends. The exam itself was very doable with the preparation that I put in. Also having passed CISSP end of February 2019 helps a lot as a lot of the knowledge overlaps with the CCSP.
Resources used:
CCSP (ISC)2 Certified Cloud Security Professional Official Study Guide
Good book, but I dislike that the content is not separated by domain.
CCSP Official (ISC)2 Practice Tests
I registered this book on the Wiley Testbank website, the questions are of good quality.
CCSP Certified Cloud Security Professional All-in-One Exam Guide
Good book as well, I created my study notes with this book as the content is separated by domain.
Cybrary CCSP Kelly Handerhan
I only viewed half of the videos as I had already read the books once, and it felt too much duplicate.
CCSP: Certified Cloud Security Professional app on Google Play
A lot of the questions are copied from the CCSP Official (ISC)2 Practice Tests book and the CCSP Certified Cloud Security Professional Practice Exams. I disliked this app as most questions I had already taken.
CCSP (Cloud Security) Practice Tests - 400 Total Questions by Total Seminars
A lot of overlap with the All-in-One Exam Guide an CCSP Certified Cloud Security Professional Practice Exams (McGraw-Hill), not recommended.
CCSP Certified Cloud Security Professional Practice Exams (McGraw-Hill)
Not a big fan of their questions, I like the practice exams bt Ben Malisow better.
As for the content of the exam, I cannot disclose the questions but I would recommend to focus on:
know the Uptime Institute Tier system, understand APIs (REST vs. SOAP) and SAML, and read the OWASP Top 10
Key topics are
laws and regulations, especially privacy;
different types of storage (object/volume, etc);
different service/deployment models;
risks to cloud (notorious nine/treacherous 12);
federated ID;
contracts and SLAs; and
managing encryption.
SDLC, BC/DR, Risk and overall data center security.
US Government terms, NIST, FedRAMP, FIPS-,Etc, so make sure these are all in your head.
To end this post, hereby is a link to my exam notes that I made, which are 28 pages long
https://docs.google.com/d...CrodEgkE/edit?usp=sharing