Practice and study

Start practicing and studying CISSP

Start with a randomized practice session or the full study roadmap, use quick reviews for distinctions that are easy to blur, then use the eight domain guides for complete coverage.

Practice tests

Choose a randomized 10-, 20-, 30-, or 50-question session from the approved CISSP 2024 Exam Outline bank and review detailed explanations.

How to use this hub

Start with a practice set or the study guide, then map the scope to your experience

Use randomized practice to identify weak areas, then use the CISSP study guide and domain guides to connect those gaps to governance, risk, architecture, operations, and software security decisions.

At a glance

What CISSP covers

CISSP covers security across an entire organization. Technical knowledge still matters, but candidates also need to connect controls to business objectives, legal duties, architecture, risk, operations, and program leadership.

The certification is aimed at experienced security practitioners, managers, architects, consultants, and senior technical professionals who need to reason across several security disciplines rather than stay inside one product or job function.

Delivery

Computerized adaptive testing (CAT)

Exam time

3 hours

Items

100 to 150

Passing score

700 out of 1000

Item format

Multiple choice and advanced item types

Candidate fit

Who CISSP is built for

CISSP is designed for experienced professionals who design, manage, assess, or lead security work. That can include security managers and executives, but it also includes architects, engineers, consultants, auditors, and senior practitioners whose decisions affect more than one system.

The breadth is part of the challenge. A candidate may be deeply experienced in operations, networking, governance, or architecture and still need deliberate study in the other domains.

Signals that the scope may fit your work
  • You regularly connect technical findings to organizational risk.
  • You help choose, justify, or govern security controls.
  • You work across teams such as legal, privacy, software, networking, operations, and leadership.
  • You need to explain why a security decision is appropriate, not only how to configure it.

Building on a foundation

How the perspective changes after Security+

Security+ provides a strong foundation for many CISSP topics. CISSP asks you to widen the frame around those topics.

Controls and tools

Security+ foundation: Recognize the control or tool that best addresses a stated problem.

CISSP perspective: Evaluate whether the control fits business requirements, risk tolerance, architecture, policy, law, cost, and lifecycle obligations.

Incident response

Security+ foundation: Choose the correct response action, evidence source, or containment step.

CISSP perspective: Balance response priorities with governance, communications, legal considerations, business continuity, and lessons learned.

Architecture

Security+ foundation: Identify secure design patterns and implementation choices.

CISSP perspective: Select and defend architecture based on requirements, trust boundaries, system models, resilience, and organizational constraints.

Risk

Security+ foundation: Understand risk concepts, treatment options, and common frameworks.

CISSP perspective: Apply risk decisions across programs, suppliers, assets, data, compliance duties, and executive accountability.

Official scope

Eight CISSP domains

Weights are averages from the current ISC2 exam outline.

Domain 1 · 16%

Security and Risk Management

Ethics, governance, law, policy, risk, supply chains, awareness, and business continuity foundations.

Domain 2 · 10%

Asset Security

Information and asset classification, ownership, handling, retention, privacy, and secure lifecycle decisions.

Domain 5 · 13%

Identity and Access Management

Identity lifecycles, authentication, authorization, federation, access models, and access-control governance.

Domain 7 · 13%

Security Operations

Investigations, incident management, monitoring, resilience, recovery, change, patching, and operational security.

Domain 8 · 10%

Software Development Security

Secure development lifecycles, software controls, acquisition, testing, supply chains, and application risk.

Beyond the exam

Experience and certification path

To earn the CISSP certification, a candidate generally needs five years of cumulative full-time work experience in at least two of the eight domains. A qualifying degree or an approved credential can waive up to one year, but the waivers do not stack.

Security+ is currently on ISC2's approved credential list for the one-year experience waiver. Passing the exam without the required experience can lead to Associate of ISC2 status while the candidate earns the remaining experience. ISC2 currently allows up to six years to complete that requirement.

Passing the exam is followed by the certification application and endorsement process. Certified members must also support the ISC2 Code of Ethics, pay the annual maintenance fee, and meet continuing professional education requirements.

CPE requirement

120 credits during each three-year certification cycle

Annual maintenance fee

U.S. $135 for certified members

Multiple ISC2 certifications

One member AMF applies rather than a separate fee for every certification

Study approach

A practical preparation sequence

Step 1

Start with the official outline

Use the eight domains and their weights to identify weak areas before choosing books, courses, or question banks.

Step 2

Translate experience into the full scope

Map what you already do at work to the outline, then identify domains where your experience is indirect or mostly theoretical.

Step 3

Study decisions, not isolated facts

Practice connecting security choices to business objectives, policy, risk, architecture, legal duties, and operational consequences.

Step 4

Review why alternatives are weaker

A useful practice question should explain why a plausible option is not the best fit under the stated constraints.

Step 5

Plan beyond exam day

Understand endorsement, experience documentation, CPE reporting, and the annual maintenance obligation before scheduling the exam.

Confirm current requirements with ISC2

Exam policies, fees, and certification requirements can change. Check the official sources before making registration or maintenance decisions.

CertHappens is an independent study resource and is not affiliated with or endorsed by ISC2.