ISC2

ISC2 Certified Information Systems Security Professional (CISSP) (CISSP)
exam objectives

ISC2's advanced, experience-required cybersecurity leadership credential validating expertise across security and risk management, asset security, security architecture and engineering, network security, identity and access management, security assessment and testing, security operations, and software development security.

Questions
45
Duration
60 min
Passing score
700
Domains
8

209 practice questions available for CISSP on CertPilot AI, mapped to the domains below.

CISSP exam domains and weightings

The CISSP exam is split into 8 domains. The percentage next to each is the share of the exam it accounts for — study time is best spent proportionally.

1.0Security and Risk Management

16%

37 practice questions in this domain

  • 1.1Security concepts and governance (CIA triad, authenticity, non-repudiation, security governance, alignment with business strategy, due care vs. due diligence)
  • 1.2Professional ethics and legal/regulatory compliance ((ISC)² Code of Ethics, cybercrime laws, data breach laws, IP protections, import/export controls, privacy regulations)
  • 1.3Investigation types and policy development (administrative, criminal, civil, and regulatory investigations; security policies, standards, procedures, and guidelines)
  • 1.4Business continuity planning (BIA, prioritizing BC requirements, external dependencies)
  • 1.5Personnel security and risk management (candidate screening, employment agreements, onboarding/termination, risk identification/analysis/treatment, risk frameworks)
  • 1.6Threat modeling, supply chain risk management, and security awareness training

2.0Asset Security

10%

22 practice questions in this domain

  • 2.1Identify and classify information and assets
  • 2.2Establish information and asset handling requirements
  • 2.3Provision resources securely (asset inventory, ownership)
  • 2.4Manage the data lifecycle (data roles, collection, retention, disposal, data remanence)
  • 2.5Ensure appropriate asset retention and determine data security controls (baselines, scoping/tailoring, standards selection, encryption at rest/in transit)

3.0Security Architecture and Engineering

13%

31 practice questions in this domain

  • 3.1Secure design principles and security models (threat modeling, defense in depth, zero trust, Bell-LaPadula, Biba, Clark-Wilson)
  • 3.2Security capabilities and controls selection (evaluation criteria like Common Criteria, certification/accreditation, memory protection, TPM)
  • 3.3Vulnerability assessment across system types (client/server, database, cryptographic, industrial control systems, cloud, distributed, IoT)
  • 3.4Cryptographic solutions and PKI (symmetric/asymmetric encryption, elliptic curve, key management, digital signatures/certificates, hashing/salting)
  • 3.5Cryptanalytic attacks (brute force, known-plaintext, chosen-plaintext, side-channel, man-in-the-middle, pass-the-hash)
  • 3.6Physical and facility security design (site/facility security controls, wiring closets, server rooms, HVAC, fire suppression, power, restricted areas)

4.0Communication and Network Security

13%

27 practice questions in this domain

  • 4.1Network models and secure architecture (OSI and TCP/IP models, IP addressing/routing, segmentation, converged protocols)
  • 4.2Wireless and cellular network security
  • 4.3Network security devices and components (firewalls, IDS/IPS, routers/switches, NAC)
  • 4.4Secure communication channels (VoIP, remote access/VPN, virtualized networks, third-party connectivity)
  • 4.5Network attacks and countermeasures (DDoS, on-path/MITM, eavesdropping)

5.0Identity and Access Management (IAM)

13%

26 practice questions in this domain

  • 5.1Control physical and logical access to assets
  • 5.2Manage identification and authentication of people, devices, and services (SSO, MFA, credential management, session management, FIDO)
  • 5.3Federated identity with third-party services (on-premise, cloud, hybrid)
  • 5.4Implement and manage authorization mechanisms (RBAC, rule-based, MAC, DAC, ABAC, risk-based access control)
  • 5.5Manage the identity and access provisioning lifecycle (account access review, provisioning/deprovisioning)
  • 5.6Implement authentication systems (OpenID Connect/OAuth, SAML, Kerberos, RADIUS/TACACS+)

6.0Security Assessment and Testing

12%

20 practice questions in this domain

  • 6.1Design and validate assessment, test, and audit strategies (internal, external, third-party)
  • 6.2Conduct security control testing (vulnerability assessment, penetration testing, log reviews, code review/testing, breach and attack simulations)
  • 6.3Collect security process data (account management, KPIs, backup verification, training/awareness metrics)
  • 6.4Analyze test output and generate reports (remediation, exception handling, ethical disclosure)
  • 6.5Conduct or facilitate security audits (internal, external, third-party)

7.0Security Operations

13%

28 practice questions in this domain

  • 7.1Investigations, evidence handling, and digital forensics
  • 7.2Logging, monitoring, and threat intelligence (SIEM, IDS/IPS, UEBA, continuous monitoring)
  • 7.3Incident management (detection through lessons learned)
  • 7.4Detective/preventative measures and vulnerability/patch management (firewalls, sandboxing, honeypots, allowlisting/blocklisting)
  • 7.5Recovery strategies and disaster recovery (backup, recovery sites, DRP testing, BC exercises)
  • 7.6Configuration/change management and resource protection (media management, asset management)
  • 7.7Physical security and personnel safety operations (duress, travel security, emergency management)

8.0Software Development Security

10%

18 practice questions in this domain

  • 8.1Security in the Software Development Life Cycle (SDLC) (Agile, Waterfall, DevOps/DevSecOps, maturity models)
  • 8.2Security controls in development ecosystems (CI/CD, code repositories, software configuration management)
  • 8.3Assess the effectiveness of software security (auditing/logging, risk analysis)
  • 8.4Assess security impact of acquired software (COTS, open source, third-party, cloud services)
  • 8.5Secure coding guidelines and standards (source-code-level vulnerabilities, secure API practices)

How to prepare for ISC2 Certified Information Systems Security Professional (CISSP)

Most candidates fail CISSP not because they didn't know the material, but because they couldn't tell which material they were weakest on. Reading the objectives end to end treats every domain as equally important — the exam doesn't. On CISSP, Security and Risk Management alone is 16% of your score.

CertPilot AI works the other way around. It tracks your accuracy per domain, weights each domain by its real exam share, and pulls most of each practice session from wherever you're currently weakest. The result is a single readiness score — at 90% you're in the range where candidates typically pass, so you book the exam on evidence instead of a hunch.

Every question comes with an AI explanation of why the right answer is right and why each distractor is wrong. The Exam Decoder goes further and breaks down how to read a question — the qualifiers, the scenario framing, and the trap options — which is the skill that separates a 740 from a 700.

ISC2 Certified Information Systems Security Professional (CISSP) (CISSP) FAQ

How many questions are on the ISC2 Certified Information Systems Security Professional (CISSP) (CISSP) exam?

The CISSP exam has up to 45 questions and you get 60 minutes to complete it.

What score do you need to pass ISC2 Certified Information Systems Security Professional (CISSP)?

ISC2 Certified Information Systems Security Professional (CISSP) requires a scaled score of 700. Scaled scoring means the raw number of correct answers is adjusted for the difficulty of the specific question set you were served, so there is no fixed percentage that guarantees a pass.

What domains does the CISSP exam cover?

ISC2 Certified Information Systems Security Professional (CISSP) is divided into 8 domains: Security and Risk Management (16%), Asset Security (10%), Security Architecture and Engineering (13%), Communication and Network Security (13%), Identity and Access Management (IAM) (13%), Security Assessment and Testing (12%), Security Operations (13%), Software Development Security (10%). The heaviest weighted domain is Security and Risk Management at 16% of the exam.

How do I know when I'm ready to book the CISSP exam?

CertPilot AI calculates a readiness score by weighting your accuracy in each domain by that domain's share of the real exam, then scaling it by how many questions you've actually answered — so a domain you've barely touched can't inflate the number. At 90% you're in the range where candidates typically pass.

How much does the CISSP exam cost?

The ISC2 Certified Information Systems Security Professional (CISSP) exam voucher typically costs around $749 USD. Pricing varies by region and vendors periodically adjust it, so confirm on the official vendor site before booking.

Free to start

Start practising CISSP questions

Adaptive sessions weighted to the domains above, AI explanations on every question, and a readiness score that tells you when to book.

Start free

Other ISC2 certifications