ISC2 · free study guide
CISSP study guide
Certified Information Systems Security Professional
Free CISSP study guide and exam blueprint. 125 questions in 180 minutes. Written from ISC2's Exam Outline 2024, last checked 20 July 2026. Domain weightings, glossary, and practice questions with worked explanations.
Written from ISC2's Exam Outline 2024. Last checked against that document on 20 July 2026.
125 questions
180 minutes
8 domains
Orientation
Think like a manager.
CISSP fails more technically brilliant people than any other security exam, and the reason is almost never a knowledge gap. It is a mindset gap. The exam does not want the answer an engineer would give. It wants the answer a security manager accountable to the board would give. Internalize that and everything else is study; miss it and no amount of technical depth saves you.
Is this the current version?
Yes. ISC2 refreshed the CISSP exam outline effective April 15, 2024, and those weights remain current for 2026: Domain 1 rose to 16%, Domain 8 fell to 10%, and the rest held. ISC2 runs a triennial Job Task Analysis, so a further update is possible, but as of now the 2024 outline is the one you sit. The 2024 refresh also wove AI and machine-learning security tasks across all eight domains rather than as a separate topic.
What you are walking into
The English CISSP is a computerized adaptive test (CAT). It delivers between 100 and 150 questions over three hours, and it adapts: answer well and it gives you harder questions and may end early; struggle and it probes further. There is no fixed length and no published passing percentage. The algorithm decides when it has enough evidence of your ability, which is why two people sitting the same exam may see different numbers of questions.
You cannot go back. In CAT format, once you answer a question and move on, it is locked. There is no reviewing or changing earlier answers. Commit to each question as you go.
What this practice tool reproduces, and what it cannot
No static practice tool can reproduce true adaptive testing, because CAT changes the questions based on your live performance. This mock is a fixed-length linear approximation: it draws a full, blueprint-weighted set so you practice breadth, timing, and the managerial mindset. Treat a strong, consistent score here as readiness for the real adaptive exam, not as a simulation of the CAT algorithm itself.
Getting certified
- Five years of cumulative, full-time paid experience in two or more of the eight domains.
- A relevant degree or an approved credential can waive one year (only one).
- No experience yet? You can still sit and pass the exam, then become an Associate of ISC2 and have up to six years to earn the experience. This is why studying for CISSP before you have five years is common and worthwhile.
- Endorsement by an existing ISC2 certified professional, and agreement to the ISC2 Code of Ethics, complete the process.
The mindset, concretely
When a question offers several answers that all look defensible, the right one usually reflects these principles:
- People first, always. Human life and safety outrank every asset. If an option protects people, it wins.
- Management drives security. Governance, policy, and management support come before technical controls. The answer is often "get management approval" or "consult the policy," not "configure the firewall."
- Address the root cause, not the symptom. The best answer fixes why the problem happened, not just its visible effect.
- Preserve first, investigate second. In an incident, protect evidence and contain harm before analyzing.
- Risk, not fear. Decisions follow from risk assessment and business value, not from what is technically coolest or most thorough.
The order that works
- Blueprint first. Eight domains. Domain 1 (Security and Risk Management) is the biggest at 16% and underpins the rest, so it is where you start.
- Domain 3 is the technical wall. Security models and cryptography are the most concentrated study; do not rush them.
- Five domains tie at 13%. Architecture, Network, IAM, and Operations, plus Assessment at 12%, together are most of the exam.
- Practice the mindset, not just the facts. On every practice question, ask which answer a CISO would defend to the board.
Your study plan
Exam Outline
What the exam is made of.
Eight domains, published weights. Domain 1 leads at 16%, and five domains cluster at 13%. There is no small domain you can safely skip, but the weights tell you where to spend disproportionate time.
16%Security & Risk10%Asset Security13%Architecture13%Network Security13%IAM12%Assessment13%Operations10%Software Dev
Eight domains (CBK)
100-150 adaptive questions
Domain 1 (Security and Risk Management) is 16%, the largest and most foundational, and its risk and governance vocabulary reappears throughout the other seven. The first seven domains together cover 90% of the exam; Domains 2 and 8 split the remaining 20%. A candidate who studies all eight equally is working against the weights.
The eight domains
| Domain | Weight | What it covers |
| 1. Security and Risk Management | 16% | Governance, compliance and law, risk management, the ISC2 Code of Ethics, BCP, personnel security, awareness. The managerial core. |
| 2. Asset Security | 10% | Classification, ownership roles, the data lifecycle, data remanence and sanitization, privacy (PII, PHI). |
| 3. Security Architecture and Engineering | 13% | Security models (Bell-LaPadula, Biba), cryptography, secure design principles, trusted computing, physical security. The technical wall. |
| 4. Communication and Network Security | 13% | OSI and TCP/IP, secure protocols, network attacks and defenses, segmentation, wireless, zero-trust networking. |
| 5. Identity and Access Management | 13% | Authentication factors, access control models (DAC/MAC/RBAC/ABAC), federation, the identity lifecycle, biometrics. |
| 6. Security Assessment and Testing | 12% | Vulnerability assessment, penetration testing, audits, log review, code testing (SAST/DAST), DR testing types. |
| 7. Security Operations | 13% | Incident response, digital forensics and evidence, change and configuration management, detective vs corrective controls, physical operations. |
| 8. Software Development Security | 10% | The SDLC and security in it, secure coding, OWASP Top 10, DevSecOps, code review methods, supply chain. |
The format
| Delivery | Computerized adaptive testing (CAT) for the English exam. |
| Questions | Between 100 and 150; the algorithm decides when it has enough evidence. |
| Time | 3 hours. |
| Navigation | No going back. Once answered, a question is locked. |
| Pass mark | Not published as a percentage; scored against a required competency level. |
| Experience | 5 years in two or more domains, or pass and become an Associate of ISC2. |
| Validity | Three years; maintain with continuing professional education (CPE) credits and an annual maintenance fee. |
Why this mock is fixed-length
The real exam is adaptive and cannot be reproduced by a static bank. This mock draws a full, blueprint-weighted set at a representative length so you can practice breadth, pacing, and, above all, the managerial mindset. A consistently strong score here signals readiness; it is not a simulation of the CAT algorithm.
Domain 1 16% · largest
Security and risk management.
The largest domain and the foundation of the whole exam. It is the least technical and the most managerial, and its concepts, risk, governance, law, ethics, resurface in every other domain. This is where the CISSP mindset is forged.
Governance and its documents
- Security governance aligns security with business objectives, driven from the top down. Security supports the mission; it does not exist for its own sake.
- The document hierarchy: policies (high-level intent, mandatory), standards (mandatory specifics), procedures (step-by-step), baselines (minimum levels), and guidelines (recommended, not mandatory).
- Frameworks solve different problems: ISO 27001 for a certifiable information security management system, NIST RMF for US federal risk management, COBIT for IT governance. The exam asks which framework fits a scenario, not to recite them.
Risk management
ISC2 loves quantitative risk. Know these cold.
| Term | Meaning |
| Asset Value (AV) | What the asset is worth. |
| Exposure Factor (EF) | Percentage of the asset lost in one event. |
| SLE | Single Loss Expectancy = AV x EF. |
| ARO | Annualized Rate of Occurrence (times per year). |
| ALE | Annualized Loss Expectancy = SLE x ARO. |
- Risk treatment: mitigate (reduce), transfer (insure/outsource), avoid (stop the activity), accept (bear it). A control is only worth deploying if its cost is less than the risk reduction it buys.
- Residual risk remains after controls; management formally accepts it. Total risk minus controls leaves residual risk.
- The data owner and management own risk decisions, not the security team alone.
Law, compliance, and ethics
- Regulations: GDPR (EU privacy), HIPAA (US health), PCI-DSS (payment cards). Know the domain each governs.
- Intellectual property: patents, trademarks, copyrights, trade secrets, and their differences.
- The ISC2 Code of Ethics has four canons, and their order matters: (1) protect society and the common good; (2) act honorably and legally; (3) provide diligent, competent service to principals; (4) advance and protect the profession. When canons conflict, the earlier one wins, society before employer.
Continuity and personnel
- BCP vs DRP: Business Continuity Planning keeps the whole business running; Disaster Recovery Planning restores IT systems specifically. BCP is the broader umbrella.
- A Business Impact Analysis (BIA) identifies critical functions and sets RTO (recovery time) and RPO (data loss) targets.
- Personnel security: separation of duties, least privilege, mandatory vacations, job rotation, and onboarding/offboarding, all reduce insider risk. People are both the greatest asset and the greatest risk.
Domain 2 10%
Asset security.
How an organization classifies, handles, and ultimately destroys its data across the whole lifecycle. The recurring theme: the data owner sets the classification and accepts the risk; the custodian implements the controls.
Classification and ownership
- Classification assigns sensitivity levels (for example public, internal, confidential, restricted, or the government's unclassified through top secret) so protection is proportional to value.
- The roles, and who does what: the data owner (senior, accountable, sets classification), the data custodian (IT, implements and maintains controls), the steward (data quality and context), the processor (acts on the owner's behalf), and the user. The owner decides; the custodian executes.
The data lifecycle and states
- States: data at rest, in transit, and in use, each needing different protection (encryption at rest and in transit, careful handling in use).
- Scoping and tailoring: selecting which controls from a baseline apply (scoping) and adjusting them to the organization (tailoring).
Data remanence and sanitization
A favorite exam trap. Given a scenario, pick the right method for the sensitivity and the reuse plan.
| Method | What it does |
| Clearing | Overwrites data so it cannot be recovered by normal means; media can be reused within the organization. |
| Purging | Removes data so it cannot be recovered even with laboratory tools; may allow release outside. |
| Destruction | Physically destroys the media (shredding, incineration). The most thorough, for the most sensitive data. |
Data remanence is the residual data left behind after deletion. Simply deleting a file or formatting a disk does not remove it; that is why clearing, purging, or destruction is required.
Privacy
- PII (personally identifiable information) and PHI (protected health information) get special legal protection.
- Data minimization: collect and keep only what is needed. Data you never hold cannot be breached.
- Retention policies define how long data is kept and when it is securely disposed of.
Domain 3 13% · the technical wall
Security architecture and engineering.
The most technically broad domain, and the one candidates most often underestimate. It spans formal security models from the 1970s to modern cloud, with cryptography deep enough to feel like its own certification. Do not rush it.
Security models
The exam gives a scenario and asks which model applies. The confidentiality-versus-integrity distinction is the key.
| Model | Protects | Rule of thumb |
| Bell-LaPadula | Confidentiality | No read up, no write down. Keeps secrets from leaking down. |
| Biba | Integrity | No read down, no write up. Keeps bad data from flowing up. |
| Clark-Wilson | Integrity | Well-formed transactions and separation of duties. |
| Brewer-Nash | Conflict of interest | The "Chinese Wall": access changes to prevent conflicts. |
Cryptography
- Symmetric (AES, 3DES): one shared key, fast, great for bulk encryption; key exchange is the hard part.
- Asymmetric (RSA, ECC): a public/private key pair, slower, great for key exchange and digital signatures.
- Hashing (SHA-256): one-way, for integrity. Digital signatures combine hashing and asymmetric keys for integrity, authentication, and non-repudiation.
- PKI: certificate authorities, public/private keys, and revocation (CRL, OCSP) that make asymmetric trust work at scale.
- Expect several crypto questions; know not just what each does but when to use it and why.
Secure design and trusted computing
- Principles: least privilege, defense in depth, fail-secure (fail closed), separation of duties, keeping designs simple, secure defaults.
- Trusted computing: the TPM (chip on one device), the HSM (dedicated key hardware at scale), secure enclaves, the trusted computing base (TCB), and the reference monitor concept.
- Cloud and virtualization: the shared responsibility model, isolation, containerization risks, and the "inability to patch" problem for embedded and ICS systems.
Physical security
- Layered site design, CPTED (crime prevention through environmental design), mantraps and turnstiles, fire suppression, power (UPS and generators), and environmental controls.
- Physical access defeats most logical controls, so it is treated as first-order, not an afterthought.
Domain 4 13%
Communication and network security.
Where networking knowledge matters most, but tested at the design level. The CISSP does not ask you to configure a switch; it asks why a given architecture or protocol is chosen, what it is vulnerable to, and how controls mitigate that.
Models and where attacks live
- The OSI model (7 layers) and TCP/IP. Know what each layer does and where attacks occur: ARP poisoning at Layer 2, IP spoofing at Layer 3, and so on. Mapping an attack or control to its layer is a common question.
- Secure protocols: TLS/SSL for web, IPSec for VPN tunnels, SSH for remote access, and the insecure protocols they replace (Telnet, FTP, HTTP).
Network defenses
- Firewalls: packet-filtering (Layer 4, stateless), stateful, and next-generation (application-aware). Match the type to the need.
- Segmentation: DMZ for public-facing services, VLANs, and microsegmentation to limit lateral movement.
- IDS vs IPS (a favorite trap): an IDS detects and alerts (passive, out of band); an IPS detects and blocks (active, inline). If availability is paramount, lean IDS; if stopping the attack is paramount, IPS.
- Modern models: SD-WAN, SASE, and zero-trust network access, never trust, always verify, applied to the network.
Network attacks
- DoS and DDoS (including amplified/reflected), ARP poisoning, DNS spoofing/poisoning, on-path (formerly man-in-the-middle), and session hijacking.
- The pattern: recognize the attack from its description and pick the control that most directly counters it.
Wireless
- WPA3 is the current standard; WEP and WPA are broken or outdated. 802.1X with EAP provides port-based authentication.
- Wireless extends the attack surface beyond the physical walls, so it is secured with strong authentication and encryption, not just a hidden SSID.
Domain 5 13%
Identity and access management.
Identity is the new perimeter. As security shifts from defending a network boundary to verifying identity at every access point, this domain has become central. The access control models are non-negotiable knowledge.
Authentication
- Factors: something you know (password), have (token), are (biometric), do (behavior), and somewhere you are (location). True multifactor combines different factor types.
- Biometrics: the false acceptance rate (FAR, wrongly admits an impostor, a security failure), the false rejection rate (FRR, wrongly rejects a valid user, a usability failure), and the crossover error rate (CER), where the two meet. A lower CER means a more accurate system.
- Passwordless and adaptive authentication reduce reliance on shared secrets.
Access control models
Know the use case for each; the exam gives a scenario and asks which fits.
| Model | Who decides access |
| DAC (Discretionary) | The data owner, flexible but riskier. |
| MAC (Mandatory) | The system, via classification labels and clearances. Most rigid; government use. |
| RBAC (Role-Based) | By job role. Most common in enterprises. |
| ABAC (Attribute-Based) | By evaluated attributes (user, resource, environment). Most fine-grained. |
Federation and directories
- Federation: SAML (enterprise SSO, authentication), OAuth 2.0 (authorization/delegated access), OpenID Connect (authentication on top of OAuth). Know which does authentication and which does authorization.
- Directory and protocols: LDAP, Active Directory, and Kerberos (tickets, the KDC, mutual authentication).
- Privileged Access Management (PAM): vaulting, just-in-time access, and session monitoring for high-power accounts.
The identity lifecycle
- Provisioning (grant at onboarding, least privilege), periodic access review and recertification, and prompt deprovisioning when someone leaves. Orphaned accounts are a classic finding.
- Zero trust: never trust, always verify, decisions made per request rather than once at a perimeter.
Domain 6 12%
Security assessment and testing.
How an organization verifies its controls actually work. Not just running a scan, but choosing the right method, interpreting results, and reporting to the right audience. The managerial framing matters here too.
Assessment vs testing
- Vulnerability assessment: scanning to identify potential weaknesses, without exploiting them. Broad and automated.
- Penetration testing: actively exploiting weaknesses to demonstrate real impact. Phases run reconnaissance, scanning, exploitation, and reporting.
- Test knowledge levels: black box (no information), gray box (partial), white box (full information).
Audits
- Internal audits (own staff) versus external/third-party audits (independent, objective, often for compliance).
- Attestation standards: SOC 1 (financial controls), SOC 2 (security, availability, confidentiality, and more), and SSAE 18. SOC 2 is the one you cite for a service provider's security posture.
- The right assessor and scope depend on whether the driver is compliance or risk.
Code and log testing
- SAST (static): analyzes source code without running it, finding flaws early. DAST (dynamic): tests the running application from the outside. IAST combines both. Know which finds which category of bug.
- Log review and SIEM analysis: aggregation, correlation, and interpretation, tied back to the monitoring in Operations.
- Synthetic transactions and misuse case testing validate behavior beyond normal use.
Disaster recovery testing
Ordered by realism and risk; the exam asks which fits a constraint.
| Type | What happens |
| Tabletop / checklist | Discussion only; no systems touched. Lowest risk. |
| Walkthrough / structured | Step through the plan in detail. |
| Simulation | Act out a scenario without affecting production. |
| Parallel | Run the recovery site alongside production. |
| Full interruption (cutover) | Switch fully to recovery. Most realistic, highest risk. |
Domain 7 13%
Security operations.
Where security concepts meet the day to day. The largest practical domain, covering how teams respond to incidents, handle evidence, and maintain controls. Candidates from technical roles must remember to answer from the managerial perspective.
Incident response
Know the order, and know that containment comes before eradication. The exam asks what you do first or next.
| Phase | Focus |
| 1. Preparation | Plans, tools, and training before anything happens. |
| 2. Detection & Analysis | Identify and understand the incident. |
| 3. Containment | Stop the spread; limit damage. |
| 4. Eradication | Remove the cause. |
| 5. Recovery | Restore to normal operation. |
| 6. Post-incident (lessons learned) | Improve for next time. |
Digital forensics and evidence
The forensics trap
When a question describes an incident and asks what to do immediately, the answer is almost never "start analyzing the logs." The first priority is to preserve the evidence: secure the scene, document the chain of custody, and make forensic copies before touching anything. Investigate the copy, never the original.
- Chain of custody documents every handling of evidence so it is admissible and shown untampered.
- Order of volatility: collect the most volatile evidence first (memory, running processes) before the least (disk, backups).
- Types of evidence and the best evidence rule: originals are preferred over copies where possible.
Operational controls
- Change and configuration management: controlled change, baselines, and asset inventory. Unmanaged change is a leading source of incidents.
- Control types by function: preventive (stops it), detective (finds it), corrective (fixes it), plus deterrent, recovery, and compensating.
- Patch management, backups (and the 3-2-1 rule), and least-privilege operations.
- Physical operations: guards, lighting, CCTV, and locks, the visible layer of defense in depth.
Domain 8 10%
Software development security.
The smallest domain at 10%, trimmed slightly in 2024, but do not skip it. It covers building security into software from the start rather than bolting it on, and the OWASP Top 10 and code-testing distinctions are reliably tested.
The SDLC and shifting left
- Security is integrated at every phase of the software development lifecycle, requirements, design, development, testing, deployment, maintenance, not added at the end.
- DevSecOps shifts security left, embedding it early and continuously rather than as a final gate.
- SDLC models: waterfall (sequential), agile (iterative), and spiral (risk-driven). Know their trade-offs.
Secure coding and common flaws
- Secure practices: input validation, parameterized queries (against injection), proper error handling, and least privilege in code.
- The OWASP Top 10: injection, broken authentication, and the rest, the canonical list of web application risks.
- Buffer overflows, race conditions (TOC/TOU), and insecure deserialization as recurring flaw classes.
Code review and testing
- SAST (static): analyzes source without running it. DAST (dynamic): tests the running app from outside. IAST combines both. The static-versus-dynamic distinction is heavily tested.
- Manual code review and pair programming as complementary human checks.
Supply chain and third-party risk
- Software supply chain security: third-party libraries, dependencies, and APIs are attack surface. A single poisoned dependency can compromise everyone downstream.
- Assess acquired and open-source software, and secure APIs with authentication, rate limiting, and validation.
Reference
Glossary.
High-yield terms as the CISSP CBK uses them, weighted toward the distinctions and models the exam turns on.
- ALE
- Annualized Loss Expectancy = SLE x ARO. Expected yearly cost of a risk; drives whether a control is worth its cost.
- Associate of ISC2
- Status for someone who passes the CISSP exam but lacks the five years of experience; they have up to six years to earn it.
- Bell-LaPadula
- Confidentiality model: no read up, no write down. Prevents secrets leaking to lower levels.
- Biba
- Integrity model: no read down, no write up. Prevents low-integrity data corrupting higher levels.
- BCP vs DRP
- Business Continuity Planning keeps the whole business running; Disaster Recovery Planning restores IT systems. BCP is the broader umbrella.
- Chain of custody
- Documented handling of evidence proving it was not tampered with, so it is admissible.
- Clearing / purging / destruction
- Sanitization by increasing thoroughness: clearing (reuse inside), purging (unrecoverable even in a lab), destruction (physical elimination).
- CER
- Crossover Error Rate: where a biometric's FAR and FRR meet. Lower CER means a more accurate system.
- Data owner vs custodian
- The owner (senior) sets classification and accepts risk; the custodian (IT) implements and maintains the controls.
- Data remanence
- Residual data left after deletion. Why clearing, purging, or destruction is needed rather than a simple delete.
- DAC / MAC / RBAC / ABAC
- Access models: owner-decides / system-labels / by-role / by-attributes. Match to the scenario.
- ISC2 Code of Ethics
- Four canons in priority order: protect society; act honorably; serve principals diligently; advance the profession. Earlier canons win conflicts.
- IDS vs IPS
- IDS detects and alerts (passive, out of band); IPS detects and blocks (active, inline).
- Order of volatility
- Collect the most volatile evidence first (memory, processes) before the least (disk, backups).
- Residual risk
- Risk remaining after controls are applied; management formally accepts it.
- SABSA / RMF / ISO 27001 / COBIT
- Frameworks for different problems: risk-driven architecture / US federal risk / certifiable ISMS / IT governance.
- SAST vs DAST
- Static analyzes source without running it; dynamic tests the running application from outside.
- SLE
- Single Loss Expectancy = Asset Value x Exposure Factor. Cost of one occurrence.
- SOC 2
- An attestation report on a service provider's security, availability, and confidentiality controls; cite it for a vendor's posture.
- Separation of duties
- Splitting a critical task so no one person can complete it alone; reduces fraud.
- The CISSP mindset
- People first; management-driven; root cause over symptom; preserve before investigate; risk over fear. The tiebreaker among defensible answers.
- Zero trust
- Never trust, always verify; access decided per request rather than once at a perimeter.
Common questions
CISSP exam questions, answered
How many questions are on the CISSP exam?
The CISSP exam has 125 questions and lasts 180 minutes. ISC2 uses a scaled score rather than a published percentage, so there is no fixed pass mark to quote.
What is on the CISSP exam?
The exam covers 8 domains: Security & Risk (16%), Asset Security (10%), Architecture (13%), Network Security (13%), IAM (13%), Assessment (12%), Operations (13%), Software Dev (10%). These weightings come from ISC2's Exam Outline 2024.
Is this CISSP material current?
Yes. This guide was written from ISC2's own published outline, Exam Outline 2024, and last checked against that document on 20 July 2026. That date is shown on every page so you can judge for yourself rather than take our word for it.
Are there free CISSP practice questions?
Yes. Sample questions with full worked explanations are free and need no account. The complete question bank and the full-length 125-question timed mock are paid.
Practise it
The guide above is free. The question bank and the full-length timed mock are the paid part.
Open CISSP →