Every Exam PrepFREE EXAM PREP
Ask AI
STUDY GUIDE · CISSP

Certified Information Systems Security Professional (CISSP) Study Guide

Verified against the ISC2 exam outline 6 sections
Written by Every Exam Prep Editorial TeamSource and review policyPublished July 18, 2026
Time limit
3h
Passing score
700/1000
Exam fee
$749
Governing body
ISC2

The Certified Information Systems Security Professional (CISSP) is one of the most recognized credentials in the cybersecurity industry, administered by ISC2. It validates a professional's ability to design, implement, and manage a best-practice cybersecurity program across an entire organization, rather than focusing on a single technical niche.

The CISSP is aimed at experienced practitioners, not entry-level candidates. It suits security analysts, security managers, IT directors, security consultants, and auditors who already work in the field and want formal recognition of that experience. Because the exam blends managerial and technical content, it is often pursued by people moving from hands-on security roles into leadership positions such as security architect, CISO, or director of information security.

Career Impact

  • Signals to employers that a candidate can operate across the full breadth of information security, from risk management to software development security.
  • Frequently listed as a preferred or required qualification for senior security roles and government or defense-adjacent positions.
  • Provides a common credential recognized across industries and countries, which helps professionals move between sectors.

Because the certification demands real-world experience, not just exam knowledge, earning it typically reflects genuine seniority rather than a starting point in a career.

Understanding the mechanics of the CISSP exam helps candidates plan their preparation timeline and budget realistically.

Format and Scoring

  • The English-language CISSP exam uses Computerized Adaptive Testing (CAT), which adjusts question difficulty based on a candidate's responses.
  • The exam contains 100 to 150 questions.
  • A passing result requires a score of 700 out of 1000 points.

Cost

  • The standard CISSP examination registration fee is U.S. $749.
  • Candidates who need to reschedule their appointment are charged a rescheduling fee of U.S. $50.
  • Canceling an exam appointment carries a cancellation fee of U.S. $100.

Delivery

The CISSP exam is administered at Pearson VUE test centers. After registering with ISC2, candidates are redirected to the Pearson VUE website to finalize the exam appointment, choosing a testing location and time slot that works with their schedule.

Because the exam uses adaptive testing, the number of questions a given candidate sees can vary within the stated range, and the test ends once the system has gathered enough evidence to determine a pass or fail result with statistical confidence.

Domains

The CISSP exam is organized into 8 domains, collectively known as the Common Body of Knowledge (CBK). Each domain carries a different weight on the exam, reflecting its relative importance to real-world security practice.

  • Domain 1: Security and Risk Management (16%) — the largest domain, covering governance, compliance, legal and regulatory issues, professional ethics, and risk management frameworks.
  • Domain 2: Asset Security (10%) — classifying, handling, and protecting information and physical assets throughout their lifecycle, including data retention and privacy.
  • Domain 3: Security Architecture and Engineering (13%) — secure design principles, cryptography, and engineering processes that build security into systems from the ground up.
  • Domain 4: Communication and Network Security (13%) — securing network architecture, components, and communication channels against interception and attack.
  • Domain 5: Identity and Access Management, IAM (13%) — controlling how identities are provisioned, authenticated, and authorized across systems.
  • Domain 6: Security Assessment and Testing (12%) — designing and executing assessment strategies, audits, and test processes to validate security controls.
  • Domain 7: Security Operations (13%) — day-to-day operational practices such as incident response, disaster recovery, and investigations.
  • Domain 8: Software Development Security (10%) — integrating security into the software development lifecycle, including secure coding practices.

Together these domains span Security and Risk Management, Asset Security, Security Architecture and Engineering, Communication and Network Security, Identity and Access Management, Security Assessment and Testing, Security Operations, and Software Development Security. Because Domain 1 carries the heaviest weight, candidates should treat governance and risk concepts as a foundation that connects to material in every other domain, rather than as an isolated topic to study once and move past.

Because the CISSP tests breadth across 8 domains rather than depth in one, a structured, multi-week study plan tends to work better than cramming. Most candidates benefit from a plan built around domain rotation followed by integration and practice.

Weeks 1-2: Foundation

Start with Domain 1, Security and Risk Management, since its concepts around governance, risk, and compliance recur throughout the rest of the material. Build a glossary of key terms as you go, since CISSP vocabulary is dense and precise.

Weeks 3-6: Domain Rotation

Work through Domains 2 through 8 in turn, spending roughly one week per domain, with extra time on the heavier-weighted domains such as Security Architecture and Engineering, Network Security, IAM, and Security Operations. For each domain, alternate between reading core concepts and answering topic-specific practice questions to reinforce recall.

Weeks 7-8: Integration and Review

Shift from single-domain study to mixed practice tests that draw questions from all 8 domains at once, which mirrors how the actual exam blends topics. Review flashcards for terminology you consistently miss, and revisit weaker domains identified through practice test scoring.

Final Week: Light Review

Avoid learning new material in the final days. Instead, do timed practice sessions, review your notes on frequently confused terms, and rest before exam day. Because the exam uses adaptive testing, being comfortable and confident with core concepts across all domains matters more than memorizing edge cases.

Small logistical and strategic mistakes can undermine months of preparation. The following guidance addresses the most common pitfalls candidates report.

Before Exam Day

  • Confirm your appointment details on the Pearson VUE website well in advance, since scheduling is finalized there rather than directly with ISC2.
  • Arrive with acceptable identification and arrive early, since test centers typically will not admit candidates who arrive late.
  • If you must change your appointment, do so as early as possible. Rescheduling and cancellation both carry separate fees, so last-minute changes are costly on top of being stressful.

During the Exam

  • Because the exam is adaptive, do not try to game question difficulty by answering carelessly. Read each question fully before answering, since CISSP questions are often scenario-based and reward careful reading over speed.
  • Think like a manager, not just a technician. CISSP consistently rewards the answer that reflects best-practice governance and risk management, even when a more technical answer seems plausible.
  • Do not panic if questions feel unfamiliar or difficult. Adaptive testing is designed to probe the edges of a candidate's knowledge, so a string of hard questions is not necessarily a sign of failure.

Common Mistakes to Avoid

  • Treating the exam as a technical certification only, and neglecting governance, legal, and risk-management content.
  • Under-preparing for the lower-weighted domains, since every domain still contributes questions.
  • Skipping practice questions in favor of passive reading, which does not build the scenario-analysis skills the exam actually tests.

Because the CISSP spans 8 broad domains and rewards precise, scenario-based reasoning, a mix of study formats tends to work better than relying on a single method. Free resources on this site are organized to support each stage of preparation.

Practice Questions

Scenario-style practice questions mirror the way the real exam presents situations rather than simple recall prompts. Working through practice questions organized by domain helps identify which of the 8 domains need more attention before moving to mixed, full-length practice sets.

Flashcards

The CISSP vocabulary is dense, with many terms that sound similar but carry distinct meanings in a security context. Flashcards are useful for quick, repeated review of terminology, especially during the integration and final-review phases of a study plan, when reinforcing recall matters more than reading new material.

Glossary

A glossary of CISSP-specific terms gives candidates a fast reference point while working through practice questions or reviewing domain content, reducing the time spent searching for definitions elsewhere and helping build the precise vocabulary the exam expects.

Used together, these formats let candidates read for understanding, drill for recall, and test for application, which matches the way the CISSP blends conceptual knowledge with judgment-based questions.

CISSP flashcards

30 cards on the highest-yield terms and rules. Grading uses spaced repetition and saves in this browser.

Card 1 of 300 mastered
Say the answer out loud before flipping.
Browse all 30 cards
  1. What are the 8 CISSP CBK domains?

    Security and Risk Management; Asset Security; Security Architecture and Engineering; Communication and Network Security; Identity and Access Management (IAM); Security Assessment and Testing; Security Operations; and Software Development Security.

  2. What does the CIA triad stand for in information security?

    Confidentiality, Integrity, and Availability — the three core properties that security controls are designed to protect.

  3. What is the difference between qualitative and quantitative risk analysis?

    Quantitative analysis assigns numeric/monetary values (e.g., ALE, SLE, ARO) to risk, while qualitative analysis uses subjective ratings like high/medium/low based on judgment and scenarios.

  4. Define Single Loss Expectancy (SLE).

    The monetary loss expected from a single occurrence of a risk event, calculated as Asset Value (AV) multiplied by Exposure Factor (EF).

  5. Define Annualized Loss Expectancy (ALE).

    The expected yearly monetary loss from a risk, calculated as SLE multiplied by the Annualized Rate of Occurrence (ARO).

  6. What is the principle of least privilege?

    Users and processes should be granted only the minimum access rights needed to perform their job functions, nothing more.

  7. What is separation of duties?

    A control that divides critical tasks among multiple people so no single individual can complete a sensitive process alone, reducing fraud and error risk.

  8. What is defense in depth?

    A layered security strategy using multiple, overlapping controls (physical, technical, administrative) so that if one layer fails, others still provide protection.

  9. Distinguish authentication from authorization.

    Authentication verifies who a subject is (identity proof), while authorization determines what an authenticated subject is permitted to do.

  10. What are the three factors of authentication?

    Something you know (password/PIN), something you have (token/smart card), and something you are (biometric).

  11. What is Discretionary Access Control (DAC)?

    An access model where the resource owner decides who can access the resource and what permissions they receive.

  12. What is Mandatory Access Control (MAC)?

    An access model where access decisions are enforced by the system based on fixed security labels/classifications, not by resource owners.

  13. What is Role-Based Access Control (RBAC)?

    An access model that grants permissions based on a subject's assigned role within an organization rather than individual identity.

  14. What is the difference between symmetric and asymmetric encryption?

    Symmetric encryption uses one shared secret key for both encryption and decryption; asymmetric encryption uses a mathematically linked public/private key pair.

  15. What does a digital signature provide?

    Integrity, authentication, and non-repudiation by hashing a message and encrypting the hash with the sender's private key.

  16. What is the purpose of a hashing algorithm in security?

    To produce a fixed-length, unique digest of data used to verify integrity — any change to the input produces a different hash.

  17. What is the difference between a Type I and Type II error in biometric systems?

    A Type I error (False Rejection Rate) wrongly denies a legitimate user; a Type II error (False Acceptance Rate) wrongly admits an impostor.

  18. What is the Crossover Error Rate (CER) in biometrics?

    The point at which the False Rejection Rate and False Acceptance Rate are equal; a lower CER indicates a more accurate biometric system.

  19. What is a Security Information and Event Management (SIEM) system used for?

    To aggregate, correlate, and analyze log data from across an environment in real time to detect and alert on security incidents.

  20. What is the difference between a vulnerability assessment and a penetration test?

    A vulnerability assessment identifies and catalogs weaknesses without exploiting them, while a penetration test actively exploits vulnerabilities to demonstrate real-world impact.

  21. What is the primary goal of business continuity planning (BCP)?

    To ensure critical business functions can continue operating during and after a disruptive event.

  22. What is a disaster recovery plan (DRP) focused on?

    Restoring IT systems, data, and infrastructure after a disruptive event, as a subset of the broader business continuity plan.

  23. Define Recovery Time Objective (RTO).

    The maximum acceptable amount of time a system or process can be down before it must be restored after a disruption.

  24. Define Recovery Point Objective (RPO).

    The maximum acceptable amount of data loss, measured in time, between the last backup and the point of disruption.

  25. What is the OSI model and how many layers does it have?

    A conceptual 7-layer framework (Physical, Data Link, Network, Transport, Session, Presentation, Application) describing how network communication functions.

  26. What is the purpose of change management in security operations?

    To ensure that changes to systems are formally reviewed, approved, tested, and documented to minimize disruption and unintended security risk.

  27. What is the Software Development Life Cycle (SDLC) and why does it matter for security?

    A structured process for building software through phases (planning, design, development, testing, deployment, maintenance); embedding security at each phase reduces vulnerabilities before release.

  28. What is threat modeling?

    A structured process of identifying potential threats, vulnerabilities, and attack vectors against a system early in design to prioritize mitigations.

  29. What is the difference between data at rest, in transit, and in use?

    Data at rest is stored on media, data in transit is moving across a network, and data in use is actively being processed in memory — each requires different protective controls.

  30. What is data remanence?

    Residual data that remains on storage media after attempts to erase or delete it, posing a risk of unauthorized disclosure if not properly sanitized.

CISSP glossary

25 terms the CISSP tests, defined in plain English.

ALE (Annualized Loss Expectancy)
The expected yearly financial loss from a given risk, calculated as SLE multiplied by the annualized rate of occurrence.
ARO (Annualized Rate of Occurrence)
An estimate of how many times a specific risk event is expected to occur in a given year.
Associate of ISC2
A designation for candidates who pass the CISSP exam but have not yet met the full required work experience.
Availability
The security property ensuring that systems and data are accessible to authorized users when needed.
CAT (Computerized Adaptive Testing)
An exam delivery method where question difficulty adjusts in real time based on the test-taker's prior answers.
CBK (Common Body of Knowledge)
The comprehensive framework of topics and domains that define the scope of knowledge covered by the CISSP exam.
CIA Triad
The foundational security model of Confidentiality, Integrity, and Availability that guides control selection and risk assessment.
Confidentiality
The security property ensuring that information is accessible only to authorized individuals or systems.
DAC (Discretionary Access Control)
An access control model in which the data owner determines and assigns permissions to other users.
Data Remanence
Residual traces of data left on storage media after deletion attempts, which can potentially be recovered by unauthorized parties.
Defense in Depth
A security strategy that layers multiple independent controls so no single point of failure compromises the entire system.
Integrity
The security property ensuring that data remains accurate and unaltered except by authorized action.
ISC2
The nonprofit organization that develops and administers the CISSP certification and other information security credentials.
Least Privilege
The security principle of granting subjects only the minimum access rights necessary to perform their duties.
MAC (Mandatory Access Control)
An access control model where the operating system enforces access based on predefined security classifications and clearances.
Non-repudiation
A security property ensuring that a party cannot deny having performed an action, typically enforced through digital signatures and logging.
Pearson VUE
The third-party testing vendor that administers the CISSP exam at authorized test centers.
Penetration Testing
An authorized, simulated attack against a system used to identify and exploit vulnerabilities to assess real-world security risk.
RBAC (Role-Based Access Control)
An access control model that assigns permissions to users based on their organizational role rather than individual identity.
RPO (Recovery Point Objective)
The maximum tolerable amount of data loss measured in time, dictating how frequently backups must occur.
RTO (Recovery Time Objective)
The target maximum duration allowed to restore a system or process after a disruption.
Separation of Duties
A control that splits a sensitive task among multiple people to prevent any one person from committing fraud or error undetected.
SIEM (Security Information and Event Management)
A platform that collects, correlates, and analyzes security event data across an organization to enable detection and response.
SLE (Single Loss Expectancy)
The projected monetary loss from a single instance of a risk event, calculated as asset value multiplied by exposure factor.
Threat Modeling
A proactive process of identifying, categorizing, and prioritizing potential threats and attack vectors against a system during design.

Sources

  1. 1.CISSP Certification Exam OutlineISC2 (accessed Jul 18, 2026)
  2. 2.ISC2 Exam PricingISC2 (accessed Jul 18, 2026)
  3. 3.Register for an ISC2 ExamISC2 (accessed Jul 18, 2026)
  4. 4.CISSP Certification OverviewISC2 (accessed Jul 18, 2026)

Official sources

Primary documents used to verify the exam details shown on this page.

Last verified against the ISC2 exam outline: