Certification guide
Certified Information Systems Security Professional (CISSP) is ISC2’s flagship credential and the closest thing security leadership has to a universal standard. It validates that you can design, build, and run an information security program end to end (governance and risk, cryptography and architecture, networks, identity, assessment, operations, and secure software) and it is the certification hiring managers reach for when staffing CISOs, security architects, security managers, and senior engineers. Like CGRC, it holds a place on the U.S. DoD 8140 approved list, making it a fixture in federal, defense-contractor, and regulated-industry roles.
What separates the CISSP from technical certifications is the vantage point. The exam relentlessly tests judgment: two answers will often be technically true, and passing means recognizing which one a security professional advising the business should choose first. The current outline took effect April 15, 2024, Security and Risk Management grew to 16% and Software Development Security trimmed to 10%, and ISC2 has woven cloud, zero trust, and supply chain thinking throughout all eight domains. Delivery is Computerized Adaptive Testing in every language: the engine serves you 100 to 150 questions over three hours, adapting difficulty as you answer.
Security and Risk Management
Domain 1 · 16%The exam’s center of gravity: governance, risk assessment and treatment, legal and regulatory compliance, privacy, professional ethics, business continuity foundations, security policy, awareness, and supply chain risk management.
Asset Security
Domain 2 · 10%Information and asset handling across the full lifecycle, data roles and ownership, classification and labeling, retention and minimization, media sanitization and remanence, and protecting data at rest, in transit, and in use.
Security Architecture and Engineering
Domain 3 · 13%Secure design principles, formal security models, cryptography and cryptanalytic attacks, hardware and virtualization security, cloud shared responsibility, and the physical and environmental design of facilities and data centers.
Communication and Network Security
Domain 4 · 13%Secure network architecture and protocols: segmentation and screened subnets, IPsec and TLS, wireless security, 802.1X port-based access control, VoIP and converged networks, SDN, and the attacks that target each layer.
Identity and Access Management (IAM)
Domain 5 · 13%The identity lifecycle end to end, authentication factors and biometrics, federation with SAML, OAuth, and OIDC, Kerberos, access control models, privileged access management, just-in-time access, and zero trust.
Security Assessment and Testing
Domain 6 · 12%Proving controls actually work: vulnerability assessments versus penetration tests, SAST, DAST, and fuzzing, audit strategies and SOC reports, security metrics, and validating disaster recovery without breaking production.
Security Operations
Domain 7 · 13%Security day to day, incident response, digital forensics and evidence handling, logging with SIEM and UEBA, backups and recovery sites, patch and change management, and catching exfiltration before it succeeds.
Software Development Security
Domain 8 · 10%Security built into software rather than bolted on: secure SDLC and DevSecOps, threat modeling, injection and XSS, software supply chain and SBOMs, secrets management, and secure design principles like complete mediation.
Each Certifym CISSP practice exam is a full-length, 100-question timed simulation stratified to the official 2024 weights: 16 questions from Security and Risk Management down to 10 from Software Development Security, mirroring exactly what the live exam emphasizes. Questions are written the way ISC2 writes them: scenario-driven, best-answer format, from the perspective of a security professional advising the business, with a detailed explanation on every question covering why the right answer wins and why the tempting distractors lose. ISC2 scores the live exam on a 700-out-of-1000 scale; we set the pass mark at 70% as the honest raw-score equivalent, so a passing run here means genuine coverage across all eight domains, not luck in the heavy ones.
ISC2 CISSP - Practice Exam
Full-length ISC2 CISSP practice exam aligned to the current (April 2024) exam outline. 100 questions weighted across all eight domains: Security and Risk Management (16%), Asset…
Subscribe to startFrequently asked questions about CISSP
What is the CISSP certification?
CISSP is ISC2’s flagship credential and the closest thing security leadership has to a universal standard. It validates that you can design, build, and run an information security program end to end, governance and risk, cryptography and architecture, networks, identity, assessment, operations, and secure software. It also holds a place on the U.S. DoD 8140 approved list, which makes it a fixture in federal, defense-contractor, and regulated-industry roles.
How many questions are on the CISSP exam and how long is it?
The engine serves you 100 to 150 questions over three hours. Because delivery is adaptive, the number you actually see depends on how you answer. The exam ends once the engine has enough evidence to score you.
Is the CISSP a computer adaptive test?
Yes. Delivery is Computerized Adaptive Testing in every language, and the engine adapts question difficulty as you answer. The exam is delivered at Pearson VUE.
What is the passing score for the CISSP?
ISC2 scores the live exam on a 700-out-of-1000 scale. Certifym sets the pass mark on its CISSP practice exams at 70% as the honest raw-score equivalent, so a passing run means genuine coverage across all eight domains rather than luck in the heavy ones.
What experience do I need for the CISSP?
The CISSP carries a five-year experience requirement. That expectation shows up in the exam itself: questions are written from the perspective of a security professional advising the business, not from the perspective of someone administering a single system.
What are the eight CISSP domains and how are they weighted?
Security and Risk Management (16%), Asset Security (10%), Security Architecture and Engineering (13%), Communication and Network Security (13%), Identity and Access Management (13%), Security Assessment and Testing (12%), Security Operations (13%), and Software Development Security (10%). Security and Risk Management is the exam’s center of gravity and deserves the most study time.
What changed in the April 2024 CISSP outline?
The current outline took effect April 15, 2024. Security and Risk Management grew to 16% and Software Development Security trimmed to 10%, and ISC2 wove cloud, zero trust, and supply chain thinking throughout all eight domains rather than isolating them in one.
How hard is the CISSP exam?
What makes it hard is the vantage point rather than the technical depth. The exam relentlessly tests judgment: two answers will often be technically true, and passing means recognizing which one a security professional advising the business should choose first. Combine that with adaptive delivery across eight domains and there is nowhere to hide a weak area.
How should I prepare for the CISSP?
Drill scenarios at the official weights rather than reading domain by domain. Each Certifym CISSP practice exam is a full-length, 100-question timed simulation stratified to the 2024 weights, 16 questions from Security and Risk Management down to 10 from Software Development Security, written in ISC2’s scenario-driven, best-answer style, with a detailed explanation on every question covering why the right answer wins and why the tempting distractors lose.
How does the CISSP compare with CGRC?
Both sit on the U.S. DoD 8140 approved list, so either one satisfies the same category of federal and defense-contractor requirements. The difference is scope: CISSP spans eight domains end to end, from cryptography and network security through operations and secure software, while CGRC concentrates on the governance, risk, and compliance side that CISSP covers in Domain 1.
Trademark notice & independence. Certifym.net is operated by Certifym Exam Services, LLC and is not affiliated with, endorsed by, or sponsored by ISC2, Inc. ISC2®, CISSP®, CGRC®, and CBK® are registered marks of ISC2, Inc. Certification names and marks are used solely to identify the certifications for which our independent practice materials are designed. The CISSP exam outline and its domain structure are the property of ISC2, Inc.; candidates should download the official, current exam outline directly from isc2.org.
All questions, answers, and explanations on Certifym are original content created for practice purposes. They are not actual ISC2 examination questions and are not represented as such. Practicing with these materials does not guarantee a passing result on any live certification exam.
