⭐ Trusted by 700+ Buyers  ·  4.7★ Star Seller on Etsy  ·  $9.99/exam  ·  Grab it now →
Home › ISC2 › CISSP study guide

ISC2 CISSP (Certified Information Systems Security Professional) Practice Test & Study Guide

Everything you need to plan your CISSP prep: the exam format, what each domain covers, a week-by-week study plan, original practice questions, and what thousands of study-group comments reveal about where candidates slip up.

Last updated · By the NotJustExam team

About the ISC2 CISSP (Certified Information Systems Security Professional) exam

The CISSP is ISC2's flagship credential for experienced security practitioners who design, build, and manage an organization's overall security posture rather than operating a single tool. It is deliberately broad: passing demonstrates that you can reason across risk management, architecture, networking, identity, operations, and software security and connect technical controls to business and legal objectives.

It is aimed at people already several years into a security career — security managers, architects, analysts, consultants, and engineers moving toward leadership. The exam rewards a "manager's mindset": choosing the most defensible, risk-based answer rather than the most technically clever one.

CISSP matters because it is one of the most widely recognized security certifications worldwide, is frequently named in job descriptions and government frameworks, and satisfies common baseline requirements for senior security roles. For many practitioners it functions as a career gate into management-track positions.

ISC2 CISSP (Certified Information Systems Security Professional) exam format at a glance

AttributeDetail (as of 2026, verify on the official page)
Exam name / codeCISSP
Number of questions100-150 items (English adaptive format)
Question typesMultiple choice plus advanced innovative items
FormatComputerized Adaptive Testing (CAT) in English; linear fixed-form (~125 items) in other languages
DurationUp to 4 hours (since the April 2024 update, for both English CAT and linear versions)
Passing score700 out of 1000
CostAbout USD $749 (US); verify regional pricing
LanguagesEnglish and several additional languages
DeliveryPearson VUE test centers and ISC2-authorized online proctoring
Validity / recert3-year cycle: 120 CPEs total (40/year minimum) plus an Annual Maintenance Fee

ISC2 CISSP (Certified Information Systems Security Professional) domains & what they cover

  • Security and Risk Management (~16%): The largest domain — governance, compliance, ethics, risk assessment, and security policy. It frames how every other domain ties back to business risk.
  • Asset Security (~10%): Classifying, handling, and protecting data and assets across their lifecycle, including ownership, retention, and privacy considerations.
  • Security Architecture and Engineering (~13%): Secure design principles, cryptography, and the models and physical controls used to build trustworthy systems.
  • Communication and Network Security (~13%): Secure network architecture, protocols, segmentation, and the controls that protect data in transit.
  • Identity and Access Management (~13%): Authentication, authorization, federation, and the lifecycle of identities and entitlements across systems.
  • Security Assessment and Testing (~12%): Designing and running audits, vulnerability assessments, and control tests, and interpreting the results.
  • Security Operations (~13%): Day-to-day defense — monitoring, incident response, forensics, disaster recovery, and business continuity.
  • Software Development Security (~10%): Embedding security into the development lifecycle, secure coding, and assessing the security of acquired software.

How hard is ISC2 CISSP (Certified Information Systems Security Professional)?

CISSP is widely considered hard, but the difficulty is conceptual rather than memorization-heavy. The exam tests judgment: questions often present several technically correct options and ask for the best one given a business and risk context. Candidates from a hands-on technical background frequently stumble here because the "right" answer favors policy, people, and risk over the deepest technical fix.

Common sticking points include risk management terminology, the breadth of domains far outside your day job, and the adaptive format, which can feel relentless because it keeps targeting your weak areas. A realistic preparation window is roughly 8 to 16 weeks of consistent study for someone already working in security.

How to prepare for ISC2 CISSP (Certified Information Systems Security Professional): a study plan

  1. Weeks 1-2: Read a reputable CISSP study guide cover to cover for a first pass. Don't aim for mastery — build a mental map of all eight domains.
  2. Weeks 3-8: Study one domain at a time. After each, do a focused set of practice questions and, crucially, read the explanation for every item — right or wrong — to internalize the reasoning pattern.
  3. Weeks 9-12: Switch to mixed, full-length timed question sets to simulate the adaptive experience. Track scores per domain and revisit your two or three weakest areas.
  4. Final week: Stop cramming new material. Review your notes, mnemonics, and missed-question log, and practice pacing.

Use practice questions to train judgment, not recall: when two answers seem correct, articulate why one is better. That habit is the single biggest predictor of passing.

ISC2 CISSP (Certified Information Systems Security Professional) FAQ

How much does the CISSP exam cost?

The exam fee is approximately USD $749 in the United States as of 2026, though pricing can differ by region and occasionally by promotional bundles. Confirm the current fee on the official ISC2 page before scheduling, since ISC2 periodically adjusts pricing.

How do I keep the certification valid after I pass?

CISSP runs on a three-year certification cycle. To maintain it, you need to earn a minimum of 40 Continuing Professional Education (CPE) credits per year, 120 total across the cycle, and pay an Annual Maintenance Fee (AMF). Falling short of the CPE or AMF requirements can put the certification at risk of lapsing, so tracking CPEs continuously is safer than trying to catch up near the deadline. Confirm the current CPE and AMF figures on the official ISC2 page, as they can change.

What experience do I need to qualify, and is there a path if I don't have it yet?

ISC2 requires a minimum of five years of cumulative, paid full-time work experience in at least two of the eight CISSP domains, with one year waivable for a qualifying four-year degree or an approved credential. If you pass the exam without meeting this requirement, you can become an Associate of ISC2 and are given a multi-year window to accumulate the required experience and convert to full CISSP status. Confirm the current waiver list and Associate timeline on the official ISC2 page.

What happens if I fail the exam — can I retake it?

Yes, but ISC2 enforces a waiting period before you can retake it, and that waiting period generally lengthens after each successive failed attempt, along with a cap on how many attempts are allowed within a rolling 12-month window. You also pay the exam fee again for each attempt. Verify the exact current waiting periods and attempt limits on the official ISC2 page, since these policies have been revised before.

How is the exam delivered, and what format should I expect?

In English, CISSP is delivered as a Computerized Adaptive Test (CAT) through Pearson VUE, at a physical test center or via online proctoring in many regions, drawing from a pool of roughly 100 to 150 items and adjusting difficulty to your responses as you answer. Non-English sittings instead use a longer, linear fixed-form exam of about 125 items. Either format allows up to four hours to complete the test, plus the usual photo ID and security checks at check-in.

Is the CISSP actually worth it?

For most practitioners aiming at senior, architect, or management-track security roles, generally yes: it is one of the most widely recognized credentials in the field, shows up frequently as an explicit hiring requirement, and can support a meaningful salary premium. The payoff is smaller for people early in their careers or working in purely hands-on technical roles, where a narrower technical certification may be a better immediate fit before circling back to CISSP once the experience requirement is met.

Free CISSP practice questions

5 original questions written for NotJustExam from the public CISSP exam objectives and independently answer-checked. Try answering before you open the explanation.

Question 1

A risk analyst determines that a threat has an annualized rate of occurrence (ARO) of 0.5 and a single loss expectancy (SLE) of $200,000. What is the annualized loss expectancy (ALE)?

  1. $100,000
  2. $50,000
  3. $200,000
  4. $400,000
Show answer & explanation

Answer: A. ALE is calculated as SLE multiplied by ARO, so $200,000 x 0.5 = $100,000. A common error is dividing SLE by ARO or treating ARO as if it doubles the loss, which produces the incorrect $400,000 figure.

Source: official documentation

Question 2

Which cryptographic mechanism allows a recipient to verify both the integrity of a message and the identity of its sender, without by itself providing confidentiality?

  1. Symmetric encryption
  2. A one-time pad
  3. Steganography
  4. A digital signature
Show answer & explanation

Answer: D. A digital signature is created by signing a hash of the message with the sender's private key, which proves integrity and authenticity (and non-repudiation) without encrypting the message content. Symmetric encryption is often mistaken for providing authentication, but on its own it only provides confidentiality.

Source: official documentation

Question 3

In an access control model, a central authority assigns sensitivity labels to data (such as Confidential or Secret) and clearances to users, and individual users cannot change the permissions on objects they access. Which model is being described?

  1. Discretionary Access Control (DAC)
  2. Mandatory Access Control (MAC)
  3. Role-Based Access Control (RBAC)
  4. Attribute-Based Access Control (ABAC)
Show answer & explanation

Answer: B. MAC uses centrally assigned sensitivity labels and clearances, and users cannot alter access permissions on objects, unlike DAC, where the object's owner controls access at their discretion. RBAC and ABAC instead grant access based on roles or attributes rather than mandated classification labels.

Source: official documentation

Question 4

A penetration tester is given full advance knowledge of the target's internal network architecture, source code, and credentials before testing begins. What type of testing approach is this?

  1. White-box testing
  2. Black-box testing
  3. Gray-box testing
  4. Zero-knowledge testing
Show answer & explanation

Answer: A. White-box, or full-knowledge, testing gives the tester complete internal information such as architecture, source code, and credentials, enabling deeper and more targeted testing. Black-box testing is the opposite extreme, where the tester starts with no prior knowledge and must discover everything externally.

Source: official documentation

Question 5

During an incident investigation, which principle requires a documented record of everyone who handled a piece of digital evidence, along with when and why, from collection through presentation?

  1. Least privilege
  2. Separation of duties
  3. Defense in depth
  4. Chain of custody
Show answer & explanation

Answer: D. Chain of custody documents the handling, transfer, and storage of evidence to preserve its integrity and admissibility, recording who accessed it and why at every step. Least privilege and separation of duties are access-control principles, not evidence-handling requirements.

Source: official documentation

What 6,658 study-group comments reveal about CISSP

We summarised the public study-group discussion behind every question in our CISSP bank and compared it with an independent AI review. Where they disagree, a posted answer key alone is not enough to trust — which is why every question in the full bank shows the community vote, a discussion summary and a reasoned explanation side by side.

484practice questions reviewed
6,658study-group comments summarised from Q2 2021 – Q2 2025
8%of questions where the answer commonly posted online is disputed
40%of single-answer questions where the community vote is split

The CISSP traps that come up most

  • Rule-Based and Role-Based controls share an acronym, not a meaning — Both are abbreviated RBAC, but rule-based access control applies system-wide conditions like time or location, while role-based access control grants permissions according to a user's job role. Read the scenario carefully to tell them apart.
  • Mirroring beats parity for pure redundancy — RAID 1 (mirroring) gives the strongest fault tolerance for a given pair of disks because it keeps a full duplicate copy, while RAID 5's parity-based approach favors cost-efficiency and read performance over maximum redundancy.
  • Data Owner decides; Data Custodian implements — The data owner is accountable for classifying data and deciding how it should be protected, while the data custodian carries out the day-to-day technical safeguarding under the owner's direction. The two roles are often swapped by mistake.
  • ACLs filter statelessly; firewalls track connection state — A standard access control list filters traffic per packet based on static criteria like source/destination address and port, without awareness of connection state. A stateful firewall instead tracks the ongoing session to make context-aware decisions.
  • Match the assumed knowledge level to the test type — White-box testing assumes full internal knowledge, black-box testing assumes none, and gray-box testing assumes partial knowledge such as a former insider's residual familiarity. Misjudging which level a scenario describes is a frequent scoring trap.

Inside the full CISSP practice bank

  • 484 practice questions in an interactive web app, plus a printable PDF
  • The community-voted answer and a summary of the study-group discussion for each question
  • A step-by-step AI explanation of why the right answer is right — and why the others are not
  • One-time $9.99, lifetime access, no subscription

More certification study guides

Independent study material. NotJustExam is not affiliated with, endorsed by, or sponsored by any certification body; all certification names, trademarks and exam codes belong to their owners and are used for descriptive purposes only. The sample questions on this page are original items written for NotJustExam from the publicly available exam objectives. Exam facts change — always confirm details on the official exam page before you register.