CertGrid
Security Study Guide

(ISC)² CISSP Study Guide

The (ISC)² CISSP validates the broad knowledge and managerial judgment needed to design, engineer, and lead an enterprise security program across eight domains defined by the Common Body of Knowledge (CBK). It is aimed at experienced practitioners (the cert requires five years of cumulative paid work in two or more domains) such as security managers, architects, analysts, and CISOs. The exam is delivered as a Computerized Adaptive Test (CAT) and rewards the 'manager's-eye' answer (risk-based, big-picture) over the most technical one.

Domain 1: Security and Risk Management

Key concepts you must know · 84 practice questions

Domain 2: Asset Security

Key concepts you must know · 60 practice questions

Domain 3: Security Architecture and Engineering

Key concepts you must know · 77 practice questions

Domain 4: Communication and Network Security

Key concepts you must know · 70 practice questions

Domain 5: Identity and Access Management

Key concepts you must know · 72 practice questions

Domain 6: Security Assessment and Testing

Key concepts you must know · 83 practice questions

Domain 7: Security Operations

Key concepts you must know · 130 practice questions

Domain 8: Software Development Security

Key concepts you must know · 113 practice questions

(ISC)² CISSP exam tips

Study guide FAQ

How is the CISSP exam structured and scored?

The English exam is a Computerized Adaptive Test (CAT) of 100-150 questions over a maximum of 4 hours (240 minutes). You need a scaled score of 700 out of 1000 to pass. Questions are weighted by the eight domains, with Security Operations and Security and Risk Management carrying the most weight, and you cannot return to previous questions.

What experience is required to become certified?

You need at least five years of cumulative paid work experience in two or more of the eight CISSP domains. A four-year college degree or an approved credential can waive one year. If you pass the exam but lack the experience, you become an Associate of (ISC)² and have up to six years to earn the required experience, after which a current CISSP must endorse you.

How should I focus my study time across the domains?

Weight your study toward the largest domains: Security Operations (Domain 7) and Software Development Security (Domain 8) carry the most questions in this bank, followed by Security and Risk Management (Domain 1) and Security Assessment and Testing (Domain 6). Master the foundational managerial and risk concepts first, because they underpin scenario questions in every other domain.

Is CISSP a technical or managerial exam?

It is primarily managerial and conceptual, testing breadth across the CBK rather than deep configuration skill on any one product. You must understand technologies (cryptography, networking, IAM, secure development) well enough to reason about them, but the questions reward governance, risk-based judgment, and the manager's perspective over hands-on command-line expertise.