top of page

ISC2 CC Retake Debrief- Round 2: and this time, it let me finish.

  • 4 days ago
  • 6 min read

Two months ago, my first attempt ended at question 90 — not because I finished, but because the exam did. On August 15, I walked back in. Here's what changed, what the exam actually felt like, and where I'm pointing next.


Two months ago, my first attempt at the ISC2 Certified in Cybersecurity exam ended at question 90. Not because I finished — because the exam terminated early, an anomaly that cut the session short before I could complete it. I wrote about that experience in detail, filed formal inquiries, and was granted a retake.


On August 15, I walked back in for Round 2. This time, it let me finish.


I passed — and I'm now officially ISC2 Certified in Cybersecurity.


This post is the debrief I promised — what I did differently, what the exam actually felt like the second time, and where I'm pointing next. If you're preparing for the CC, especially if you're coming from a non-traditional background like I am, I hope the specifics help.

01 / The moment at Q90


The number that stopped me the first time


I have to start here, because it's the part I'll remember longest.


The CC is an adaptive exam. It can run anywhere from 100 to 125 questions, serving items until the engine is confident about where your score sits. I knew that going in. But knowing it intellectually and living it are two different things — because the last time I sat this exam, question 90 was where everything stopped.


So this time, as I worked through the exam and the counter climbed toward 90, I felt it.



Watching the numbers roll past 90 was its own kind of relief.

The anomaly didn't get a vote this round.


The exam ran its full course, all the way to 125, and I finished every question. For anyone who has had a testing experience go sideways, you'll understand why crossing that specific number mattered more than the pass itself did in that moment.


If your exam keeps going past 100, don't read it as a bad sign. The engine serves questions until it's sure. Plenty of people who pass go the full 125. Length is not a verdict.



02 / What changed


What I did differently for the retake


The honest answer is that Round 1 didn't fail me on preparation — it failed on circumstances outside my control. The retake still gave me a chance to sharpen, and I used it. Here's what actually moved the needle.


I worked through Thor Pedersen's CC course on Udemy


It's one of the most-used CC prep resources for a reason — the domain coverage is thorough, and it lines up well with what the exam actually tests. It gave me the structured foundation to build on before I moved into heavy practice testing.


Practice tests were the backbone — at least three full 100-question tests, across different platforms


This mattered more than any single resource. Using different platforms (LinkedIn Learning was a big one for me) exposed me to different question phrasings and kept me from memorizing one provider's style instead of learning the material. If you only drill one test bank, you risk learning that test rather than the concepts. Spreading across platforms forced real understanding.


Here's the key: I didn't take those tests for the score. I honed in on every wrong answer and dug into why the correct answer was correct until the reasoning stuck — not the memorized fact, the logic underneath it.


The score was never the point. Understanding my misses was.


For what it's worth: the LinkedIn Learning tests especially felt genuinely close to the real exam in style and difficulty. If you're consistently landing in the mid-to-high 80s or better across multiple platforms and you can explain why you missed what you missed, that's a strong signal.


I gave encryption extra focus


This is the domain that maps least cleanly onto my day-to-day work as a data analyst, so I knew it needed more attention than the areas I already live in. Symmetric versus asymmetric, hashing versus encryption, and — most importantly — where each one actually gets used. Not just definitions. Application.


I drilled concept distinctions, not definitions


This is where the CC tries to trip you up. It's less about "what is X" and more about "which of these closely related things fits this situation." The access control models were a big one for me — DAC versus MAC versus RBAC. Attacks versus their corresponding defenses. I knew the terms cold; the work was in the lines between them, because that's what the scenario questions test.


If I could give one piece of advice to someone studying right now, it would be this: stop memorizing definitions and start mapping the boundaries between similar concepts. That's the actual exam.



03 / Why it clicked


I wasn't starting over


Here's the reframe that carried me through the whole thing.


I spent the last decade asking questions of data. Atmospheric science. Healthcare analytics. Government-adjacent work. Different domains, same core instinct: know what normal looks like so the anomaly stands out. Trace the outlier to its source. Document what it means.

That is not a different skill from what security asks for. It's the same skill, pointed at a new kind of data.


When I studied the CC material, concept after concept had a hook into something I already understood. The frameworks were new. The vocabulary was new. But the underlying question — what's normal, what's not, and what does the deviation tell me — I've been answering that my whole career.


The tool changed. The question didn't.


That's the thread that runs through everything I do here at DataSec Chronicles, and the CC is one more piece of evidence for it: a career-changer isn't starting from zero. You're translating.



04 / What's next


The roadmap from here


The CC is the first cert on the roadmap, not the destination


Update

It's official: I've completed the certification application, paid the membership fee, and I'm now ISC2 Certified in Cybersecurity — awarded September 1, 2026. The exam is behind me, the credential is in hand, and here's where I'm headed next.


DONE ISC2 CC certification — earned September 1, 2026 ✅


SC-900 Microsoft Security, Compliance & Identity — a foundational, ecosystem-vocabulary win


Security+ The load-bearing cert — the one that clears the résumé filter for the roles I want. The real gate before applying in earnest.


The lane SOC & detection work — threat hunting, monitoring, anomaly detection, where a data background is an asset, not a liability.


That's the storm-to-SOC arc this whole brand is built on, and the CC is the first credential that makes it official.



05 / If you're next


For anyone studying for the CC


A few things I'd leave you with:


  • The exam is entry-level and foundational — it tests whether you understand the concepts across the domains, not whether you can execute a pen test. If the questions feel more definitional than scenario-heavy, that's the design, not a fluke.


  • Prepare with practice tests, but treat the review of wrong answers as the real study — not the score. Take at least three full-length tests across different platforms.


  • Focus your energy on the distinctions between similar concepts, because that's where the exam lives.


  • Give extra time to whatever domain maps least onto your existing background — for me that was encryption; for you it may be something else.


If you're a career-changer wondering whether your past experience counts: it does. The tools of cybersecurity are new. The instinct to hunt anomalies isn't. Point what you already know at a new target.


One small full-circle moment I have to share: months ago I built a Foundations Bingo board — a set of early-career milestones for anyone starting this journey. This week, my CC pass checked off the "earn a certificate" square. For real. I'm not just handing out the board; I'm playing it alongside everyone else who's using it to mark their own firsts. That's the whole point of building in public — the milestones are real, and we're hitting them together.


I document this entire transition openly — every investigation, what I found, and how I found it. If you're on the same path, come follow along. Grab the board, mark your own squares, and let's fill them in together.



Onward to SC-900. 💜


THE TOOL CHANGES · THE QUESTION DOESN'T

Comments


Let's learn this together. Have a question, a better query, or just want to say hi? Drop a line below.

© 2026 by DataSec Chronicles. Data-Inspired, Instinct-Driven.    Privacy Policy    Terms & Conditions

bottom of page