Practice tests
Choose a randomized 10-, 20-, 30-, or 50-question session from the approved CISSP 2024 Exam Outline bank and review detailed explanations.
Certification overview
Use CISSP-specific study guidance to connect the eight exam domains to risk, governance, architecture, operations, and organizational decision-making.
Practice and study
Start with a randomized practice session or the full study roadmap, use quick reviews for distinctions that are easy to blur, then use the eight domain guides for complete coverage.
Choose a randomized 10-, 20-, 30-, or 50-question session from the approved CISSP 2024 Exam Outline bank and review detailed explanations.
Use the full CISSP roadmap to organize the eight domains, then open a detailed domain guide for deeper review.
Review governance and risk, security models and design principles, and assessment, incident, and recovery decisions with focused comparisons.
Use CISSP references for fast lookup, or revisit Security+ and Network+ foundations when a topic needs a more basic refresher first.
Use focused Explore articles to revisit governance, vulnerability context, certificates, and cryptography from outside the exam-outline structure.
How to use this hub
Use randomized practice to identify weak areas, then use the CISSP study guide and domain guides to connect those gaps to governance, risk, architecture, operations, and software security decisions.
At a glance
CISSP covers security across an entire organization. Technical knowledge still matters, but candidates also need to connect controls to business objectives, legal duties, architecture, risk, operations, and program leadership.
The certification is aimed at experienced security practitioners, managers, architects, consultants, and senior technical professionals who need to reason across several security disciplines rather than stay inside one product or job function.
Candidate fit
CISSP is designed for experienced professionals who design, manage, assess, or lead security work. That can include security managers and executives, but it also includes architects, engineers, consultants, auditors, and senior practitioners whose decisions affect more than one system.
The breadth is part of the challenge. A candidate may be deeply experienced in operations, networking, governance, or architecture and still need deliberate study in the other domains.
Building on a foundation
Security+ provides a strong foundation for many CISSP topics. CISSP asks you to widen the frame around those topics.
Security+ foundation: Recognize the control or tool that best addresses a stated problem.
CISSP perspective: Evaluate whether the control fits business requirements, risk tolerance, architecture, policy, law, cost, and lifecycle obligations.
Security+ foundation: Choose the correct response action, evidence source, or containment step.
CISSP perspective: Balance response priorities with governance, communications, legal considerations, business continuity, and lessons learned.
Security+ foundation: Identify secure design patterns and implementation choices.
CISSP perspective: Select and defend architecture based on requirements, trust boundaries, system models, resilience, and organizational constraints.
Security+ foundation: Understand risk concepts, treatment options, and common frameworks.
CISSP perspective: Apply risk decisions across programs, suppliers, assets, data, compliance duties, and executive accountability.
Official scope
Weights are averages from the current ISC2 exam outline.
Ethics, governance, law, policy, risk, supply chains, awareness, and business continuity foundations.
Information and asset classification, ownership, handling, retention, privacy, and secure lifecycle decisions.
Security models, engineering principles, cryptography, physical design, and architecture weaknesses across modern systems.
Secure network architecture, communications technologies, transmission methods, and protected network operations.
Identity lifecycles, authentication, authorization, federation, access models, and access-control governance.
Assessment strategies, testing, audits, control validation, reporting, and analysis of security results.
Investigations, incident management, monitoring, resilience, recovery, change, patching, and operational security.
Secure development lifecycles, software controls, acquisition, testing, supply chains, and application risk.
Beyond the exam
To earn the CISSP certification, a candidate generally needs five years of cumulative full-time work experience in at least two of the eight domains. A qualifying degree or an approved credential can waive up to one year, but the waivers do not stack.
Security+ is currently on ISC2's approved credential list for the one-year experience waiver. Passing the exam without the required experience can lead to Associate of ISC2 status while the candidate earns the remaining experience. ISC2 currently allows up to six years to complete that requirement.
Passing the exam is followed by the certification application and endorsement process. Certified members must also support the ISC2 Code of Ethics, pay the annual maintenance fee, and meet continuing professional education requirements.
Study approach
Use the eight domains and their weights to identify weak areas before choosing books, courses, or question banks.
Map what you already do at work to the outline, then identify domains where your experience is indirect or mostly theoretical.
Practice connecting security choices to business objectives, policy, risk, architecture, legal duties, and operational consequences.
A useful practice question should explain why a plausible option is not the best fit under the stated constraints.
Understand endorsement, experience documentation, CPE reporting, and the annual maintenance obligation before scheduling the exam.
Exam policies, fees, and certification requirements can change. Check the official sources before making registration or maintenance decisions.
CertHappens is an independent study resource and is not affiliated with or endorsed by ISC2.