Hi, it’s me, Erich, a CISSP-certified cybersecurity professional who got into a discussion a couple of weeks ago about whether or not AI models can pass the CISSP exam.
I’ll be honest here: I truly believed there is a certain type of question that AI models will struggle with, and therefore I will be able to make the AI fail.
Well, all tested models scored 100%. Every single time. No matter how much I tried, they aced it.
That result surprised me, and it changed what I think you should be spending your study time on. So let me walk you through exactly what I did and what it means for you.
What you can expect from this article:
Exactly how I ran the experiment: the models, the setup, and how the questions were designed
What the result of this experiment means
What is the one thing that AI models still cannot do
What I think it means for cybersecurity professionals and their work
Note: CISSP (Certified Information Security Systems Professional) exam is one of the most complex exams and most recognized certifications in the field.
About the experiment
First, let me describe the details of my little experiment, because the input variables are essential for interpreting the results.
CISSP questions
First, the questions. I did not use real CISSP exam questions. Those are under the ISC2 NDA, and I would not touch them. I did not pull from a paid question bank either.
I wrote all 150 myself, in CISSP style, across all eight domains. So the result can be slightly influenced by my personal bias. However, I really think that I am quite experienced with the style of the questions.
AI models
I used three independent and widely used models.
ChatGPT: GPT-5.6 Luna
Gemini: 3.6 Flash
Claude: Sonnet 5
Process
I ran the experiment in two rounds.
Round one was 100 standard questions across all 8 CISSP exam domains. Straight knowledge and application, the kind you see in most practice sets. This is where I expect the AI to be very strong.
Round two was 50 complex questions where you’re offered multiple technically correct answers and need to choose the BEST answer based on the context. Again, I covered all 8 domains of the CISSP exam.
This is where most people fail the exam, because it requires a specific skill set and experience. This is where I expect to dominate the AI model.
Then I gave all the models the same instruction: “Pick the single best answer and explain your reasoning in one sentence. Export the result as a .md file.
The result
The result was quite clear. All models scored 150/150.
ChatGPT: 150 out of 150.
Gemini: 150 out of 150.
Claude: 150 out of 150.
And the reasoning? Correct, every single time.
I couldn’t figure out the way to confuse the AI model into picking the wrong answer. No matter how much I tried. (without cheating, of course)
Be honest, did that surprise you as much as it surprised me? If you think you can write a question that breaks it, post it in the comments and I will actually run it.
Is the CISSP useless now?
You might jump to the “easy” conclusion that CISSP is useless now and AI will replace security professionals.
But in my opinion, that’s the wrong lesson to learn here.
Let’s focus on the exam first.
I know many people will disagree, but I don’t think that a value of an exam is lowered just because an AI model can pass it.
The process of learning for the exam teaches you to recognize patterns and think like a cybersecurity professional. It isn’t just about giving the right answer. It’s much more about the endless hours of studying and understanding concepts that will allow you to make the right decisions.
And trust me, they won’t allow you to take your own pen to the exam room, let alone an AI model.
Note: Let’s stop value things purely on the fact if AI can do it. Often, giving the right answer isn’t the whole story.
This is the part people argue about. Do you think an exam loses its value the moment AI can pass it? I say no. Let me know what you think!
And what does it mean for security professionals and their work?
I think the CISSP exam, like almost every certification exam, is a recognition test. It gives you a predefined set of answers and asks you to choose the best one.
And recognizing the best answer is clearly something that the AI models are very good at.
But that’s not how it works. If you’re about to start your first cybersecurity job, you will very quickly recognize that you have to make decisions with very limited knowledge of the situation.
There is no predefined set of correct answers, and you don’t even know if what you did was the right thing to do.
AI models might be better at taking exams, but that doesn’t make them suitable for creating a cybersecurity strategy for your company.
Last question: Which part of your work will you hand to AI, and which part will you never give up?
Conclusion
So here is what I think you should take from this little experiment. The demand for people in cybersecurity continues to increase as more and more companies are realizing they need to take this seriously.
I don’t think that’s going to change any time soon. However, we all need to leverage AI in our work and fully use the benefits it brings to the table.
Clearly, there are tasks at which AI models are much better than humans. Automate them, and focus on things where you’re a lot better than any AI model can ever be.
Stop competing with AI models and rather use them to your advantage.
Worried AI is closing the door on entry-level roles? It is not. But you need a plan, not more certs. That is exactly what the 90-Day Cybersecurity Job Blueprint gives you.
Let’s Connect
If you want to collaborate, discuss, or just geek out over networking and cybersecurity, reach out:
Email: erich.winkler@decodedsecurity.com
LinkedIn: Erich Winkler
Gumroad community: Decoded Security
Start Here: Decoded Security Roadmap
Enjoyed this article? Like it or drop a comment. I’d love to hear your thoughts and questions!
Let’s learn and grow together!





