CertGrid
Security Study Guide

(ISC)² CISSP Study Guide

The (ISC)² CISSP validates the broad knowledge and managerial judgment needed to design, engineer, and lead an enterprise security program across eight domains defined by the Common Body of Knowledge (CBK). It is aimed at experienced practitioners (the cert requires five years of cumulative paid work in two or more domains) such as security managers, architects, analysts, and CISOs. The exam is delivered as a Computerized Adaptive Test (CAT) and rewards the 'manager's-eye' answer (risk-based, big-picture) over the most technical one.

Objective-mapped study guide, aligned to current exam objectives · Reviewed Aug 2026 · Independent practice platform.

Real exam: 100-150 qs · 180 min · CAT adaptive exam.

Domain 1: Security and Risk Management

Key concepts you must know · 167 practice questions

Domain 2: Asset Security

Key concepts you must know · 106 practice questions

Domain 3: Security Architecture and Engineering

Key concepts you must know · 137 practice questions

Domain 4: Communication and Network Security

Key concepts you must know · 135 practice questions

Domain 5: Identity and Access Management

Key concepts you must know · 134 practice questions

Domain 6: Security Assessment and Testing

Key concepts you must know · 127 practice questions

Domain 7: Security Operations

Key concepts you must know · 154 practice questions

Domain 8: Software Development Security

Key concepts you must know · 129 practice questions

(ISC)² CISSP exam tips

Study guide FAQ

How is the CISSP exam structured and scored?

The English exam is a Computerized Adaptive Test (CAT) of 100-150 questions over a maximum of 3 hours (180 minutes). You need a scaled score of 700 out of 1000 to pass. Questions are weighted across the eight domains per the official outline - Security and Risk Management is the largest at 16%, with the remaining domains ranging from 10% to 13% - and you cannot return to previous questions.

What experience is required to become certified?

You need at least five years of cumulative paid work experience in two or more of the eight CISSP domains. A four-year college degree or an approved credential can waive one year. If you pass the exam but lack the experience, you become an Associate of (ISC)² and have up to six years to earn the required experience, after which a current CISSP must endorse you.

How should I focus my study time across the domains?

Weight your study toward the highest-weighted domains on the official outline: Security and Risk Management (Domain 1) is the largest at 16%, followed by the four 13% domains - Security Architecture and Engineering (D3), Communication and Network Security (D4), Identity and Access Management (D5), and Security Operations (D7). Asset Security (D2) and Software Development Security (D8) are the smallest at 10%. Master the foundational managerial and risk concepts first, because they underpin scenario questions in every other domain.

Is CISSP a technical or managerial exam?

It is primarily managerial and conceptual, testing breadth across the CBK rather than deep configuration skill on any one product. You must understand technologies (cryptography, networking, IAM, secure development) well enough to reason about them, but the questions reward governance, risk-based judgment, and the manager's perspective over hands-on command-line expertise.

Related Security resources

What CertGrid is (and is not)

CertGrid is an independent IT certification practice platform for Azure, AWS, Google, Cisco, Security, Linux, Kubernetes, Terraform, and other certification tracks. It provides objective-mapped practice questions, readiness scoring, weak-domain drills, and explanations to help learners understand what to study next.

Independent & original. CertGrid is an independent practice platform and is not affiliated with or endorsed by Security. Questions are original practice items designed to mirror certification concepts and exam style. CertGrid does not provide official exam questions or braindumps.