I'm studying for #CISSP after 9 years of being #cybersecurity practitioner and 24 years of working in IT as a whole.
Some questions/theory in there is so old that it hurts (and I can totally imagine how the course may be hard for youngsters who for example never have seen nor erased an EPROM with UV light).
Some parts are hard for me as an European, because I didn't deal much with US laws and standards and have to memorize them now.
Some parts are just tiring as I am constantly re-learning them and forgetting again over the years, like the subtle differences between various roles in data management or the many abbreviations which are variations on the same in different contexts - many key indicators, formulas etc.
TL;DR: I hope I'll pass and then don't need to repeat it for a few years... I don't like certifications, but in this world, they're a handy proof of "knowledge" or at least of ability to memorize a lot of stuff.
Also, a friend of mine is trying to persuade me to go for #OSCP - and that one is something I'm both intrigued with and afraid of it 