CHEAT SHEET · CISSP

CISSP Cheat Sheet.
The night-before summary, built like the exam.

Weighted to the current exam outline·15-minute scan
By Vincent Ruan, EA, CFP®Published July 21, 2026
Drill weak spots →

CISSP Cheat Sheet

A condensed reference for the Certified Information Systems Security Professional (CISSP) exam, covering logistics, domains, key concepts, and last-minute review points.

Exam Logistics At-a-Glance

ItemDetail
FormatComputerized Adaptive Testing (CAT), English exam
Question count100 to 150 questions
Passing score700 out of 1000 points
Registration feeU.S. $749 (standard)
Rescheduling feeU.S. $50
Cancellation feeU.S. $100
DeliveryPearson VUE test centers
Domains covered8 domains

Eligibility Requirements

  • A minimum of 5 years cumulative, full-time paid work experience is required.
  • That experience must span two or more of the eight domains in the current CISSP Exam Outline.
  • A relevant degree or approved credential can satisfy 1 year of the required experience.
  • Without full experience, candidates can become an Associate of ISC2 and have 6 years to earn the five years required.
  • Registration and appointment scheduling happen through the Pearson VUE website after signing up with ISC2.

The 8 Official Domains (Quick List)

  1. Security and Risk Management — 16%
  2. Asset Security — 10%
  3. Security Architecture and Engineering — 13%
  4. Communication and Network Security — 13%
  5. Identity and Access Management (IAM) — 13%
  6. Security Assessment and Testing — 12%
  7. Security Operations — 13%
  8. Software Development Security — 10%

Notice the weighting: Domain 1 (Security and Risk Management) carries the heaviest single share, and four domains tie at 13% each — Architecture, Network Security, IAM, and Operations. Under-studying Domain 1 is one of the most common scoring mistakes.

Key Terms and Concepts to Memorize

  • CIA Triad — Confidentiality, Integrity, Availability; the foundational model behind nearly every domain.
  • Due care vs. due diligence — due care is taking reasonable action; due diligence is the research/investigation behind that action.
  • Defense in depth — layered, overlapping controls rather than reliance on a single safeguard.
  • Least privilege vs. need-to-know — least privilege limits access rights; need-to-know limits access to specific data required for a task.
  • Administrative, technical (logical), and physical controls — the three control categories tested across risk and operations questions.
  • Qualitative vs. quantitative risk analysis — quantitative uses numeric values (e.g., ALE, SLE, ARO); qualitative uses relative ratings.
  • Symmetric vs. asymmetric cryptography — shared-key speed versus public/private-key key-exchange and non-repudiation.
  • Authentication factors — something you know, have, and are; multi-factor combines at least two categories.
  • Business Continuity Planning (BCP) vs. Disaster Recovery Planning (DRP) — BCP keeps the business running; DRP restores IT systems after disruption.
  • Change management vs. configuration management — controlling what changes versus tracking system state and baselines.

Common Gotchas and Traps

  • CISSP is a management/governance-oriented exam, not a hands-on technical exam — when two answers seem technically correct, pick the one reflecting policy, process, or risk-based thinking.
  • Computerized Adaptive Testing means question difficulty adjusts based on your answers, and you cannot skip back to review or change earlier answers.
  • "Best" or "most appropriate" answer questions often have multiple technically valid options — always default to the answer that best protects the organization's risk posture.
  • Don't confuse the domain names with their weightings; several domains sound similar (Security Architecture vs. Security Operations) but test very different content.
  • Experience requirements must map to the current Exam Outline domains — unrelated IT experience alone does not qualify.
  • Missing the Pearson VUE cancellation or rescheduling window triggers a fee, so lock in a realistic test date rather than scheduling too early.

Night-Before Checklist

  • Confirm Pearson VUE appointment time, test center address, and required photo ID.
  • Review the 8 domain weightings once more, focusing extra attention on Domain 1 given its 16% share.
  • Skim key term flashcards: CIA triad, due care/diligence, control types, risk formulas, authentication factors.
  • Get full sleep — CAT exams reward careful reading and focus, not last-minute cramming.
  • Pack ID, confirmation details, and arrive early to avoid day-of stress.
  • Do a final mental review of test-taking strategy: choose the most risk-averse, management-aligned answer when in doubt.

Frequently asked questions

What are the CISSP exam domains and how are they weighted?

The CISSP exam is organized into 8 domains. Their exam weightings are: Domain 1 Security and Risk Management (16%), Domain 2 Asset Security (10%), Domain 3 Security Architecture and Engineering (13%), Domain 4 Communication and Network Security (13%), Domain 5 Identity and Access Management (IAM) (13%), Domain 6 Security Assessment and Testing (12%), Domain 7 Security Operations (13%), and Domain 8 Software Development Security (10%). Because Domain 1 carries the heaviest weight at 16%, it is worth prioritizing in your study plan, while Domains 2 and 8 (each 10%) contribute the least to your score.

What is the CISSP exam format, length, and passing score?

The English CISSP exam uses Computerized Adaptive Testing (CAT) and contains 100 to 150 questions. The passing score is 700 out of 1000 points. Because CAT adapts to your responses, the exact number of questions you receive within the 100–150 range depends on your performance, and there is no fixed percentage of correct answers required — you simply need to reach the 700-point scaled threshold.

How much does the CISSP exam cost, and what are the change fees?

The standard CISSP examination registration fee is U.S. $749. If you need to change your appointment after registering, a rescheduling fee of U.S. $50 applies, and a cancellation fee of U.S. $100 applies if you cancel. The exam is administered at Pearson VUE test centers, and after registering with ISC2 candidates are redirected to the Pearson VUE website to finalize the exam appointment. Because rescheduling ($50) costs less than cancelling ($100), moving an appointment is generally cheaper than cancelling outright if you can still commit to a later date.

What work experience do I need to become CISSP-certified, and what if I don't have it yet?

To earn the CISSP, a candidate must have a minimum of 5 years of cumulative, full-time paid work experience in two or more of the eight domains of the current CISSP Exam Outline. A relevant degree or approved credential may satisfy 1 year of the required experience, reducing the requirement to four years in that case. If you pass the exam but don't yet have the experience, you can become an Associate of ISC2, which gives you 6 years to earn the five years of required experience. In practice, this means you can sit for and pass the exam first and still have a multi-year window to accumulate the qualifying experience before full certification.

Sources

  1. 1.CISSP Certification Exam OutlineISC2 (accessed Jul 18, 2026)
  2. 2.CISSP Experience RequirementsISC2 (accessed Jul 18, 2026)
  3. 3.ISC2 Exam PricingISC2 (accessed Jul 18, 2026)
  4. 4.Register for an ISC2 ExamISC2 (accessed Jul 18, 2026)
  5. 5.CISSP Certification OverviewISC2 (accessed Jul 18, 2026)