Information security leadership study guide
Aligned to ISC2 CISSP exam outline effective April 15, 2024
601 practice questions
160 flashcards
Completely free

ISC2 CISSP Exam Prep

Practice governance, asset security, architecture, networks, IAM, assessment, operations, and software security with 601 original CISSP questions.

601 original questions
ISC2 weighted
Risk-first drills

Most popular

Start with free practice questions

Jump into a mixed set drawn from 601 free practice questions.

Free Practice Questions

Exam structure

Know the split before you start drilling

Security and Risk Management

16%

16 scored + 0 pretest

Asset Security

10%

10 scored + 0 pretest

Security Architecture and Engineering

13%

13 scored + 0 pretest

Communication and Network Security

13%

13 scored + 0 pretest

Identity and Access Management

13%

13 scored + 0 pretest

Security Assessment and Testing

12%

12 scored + 0 pretest

Security Operations

13%

13 scored + 0 pretest

Software Development Security

10%

10 scored + 0 pretest

Outline version

2024-04-15

ISC2 lists the current CISSP outline as effective April 15, 2024.

Exam length

3 hours

ISC2 lists a 3-hour English CAT exam.

Items

100-150

The official exam uses multiple choice and advanced innovative items.

Passing score

700/1000

ISC2 lists 700 out of 1000 points as the passing score.

Domains

8

The eight CISSP domains range from 10% to 16% of the exam.

Practice bank

601 questions

Original questions aligned to the public ISC2 CISSP outline.

Start here

How to study for CISSP

Use this sequence for the cleanest CISSP study pass.

1

1. Lead with governance and risk

CISSP answers usually begin with ownership, policy, risk treatment, ethics, business impact, and documented process.

2

2. Connect controls to lifecycle

Map asset handling, architecture, network, identity, and software controls to the data, system, or service lifecycle in the scenario.

3

3. Validate operations and assurance

Finish with assessment evidence, incident response, logging, backup, resilience, and lessons learned.

About the exam

CISSP Exam structure

CISSP prep with 601 original practice questions, ISC2 domain-weighted mocks, security leadership drills, flashcards, and topic recovery.

Issuer and path

ISC2 CISSP Exam Prep is administered through ISC2. Check official resources before booking, retesting, or relying on a stale requirement.

Security and Risk Management

16%

16 scored + 0 pretest

Ethics, security governance, risk management, legal and compliance issues, investigations, policy, business continuity, personnel security, supply chain risk, and awareness training.

Asset Security

10%

10 scored + 0 pretest

Information and asset classification, ownership, handling, secure provisioning, data lifecycle, retention, destruction, data states, and data protection controls.

Security Architecture and Engineering

13%

13 scored + 0 pretest

Secure design principles, security models, system capabilities, architecture vulnerabilities, cryptography, facilities, physical security, and system lifecycle management.

Communication and Network Security

13%

13 scored + 0 pretest

Secure network design, OSI and TCP/IP models, secure protocols, segmentation, network components, wireless, remote access, edge security, and network attacks.

Identity and Access Management

13%

13 scored + 0 pretest

Physical and logical access, identification, authentication, authorization, federation, credential management, provisioning, access reviews, and identity lifecycle controls.

Security Assessment and Testing

12%

12 scored + 0 pretest

Assessment strategy, audit programs, control testing, vulnerability assessment, penetration testing, evidence, reporting, remediation, and continuous monitoring.

Security Operations

13%

13 scored + 0 pretest

Operational security, logging, investigations, incident response, disaster recovery, backup, change management, resilience, resource protection, and personnel safety.

Software Development Security

10%

10 scored + 0 pretest

Secure SDLC, development methods, security testing, DevSecOps, software assurance, supply chain risk, secure coding, API security, and vulnerability management.

Before you schedule

Confirm the current ISC2 CISSP outline, language, testing format, ID requirements, accommodations, endorsement requirements, and ISC2 exam policies.

Official Outline Coverage Map

Coverage is mapped to official outline item counts so content depth can be checked without hard-coding a single exam.

Official outline
TopicOfficial outline itemsYour questionsYour flashcardsConfidence
Ethics, Governance and Risk Decisions84910
Priority
Business Continuity, Personnel, Supply Chain and Awareness84810
Priority
Asset Classification, Ownership and Handling53010
Strong
Data Lifecycle, Retention and Protection Controls53010
Strong
Secure Design, Security Models and Cryptography73910
Priority
Architecture Vulnerabilities, Facilities and Lifecycle63910
Strong
Network Architecture, Segmentation and Traffic Control73910
Priority
Secure Protocols, Wireless, Edge and Network Attacks63910
Strong
Identity, Authentication and Access Models73910
Priority
Federation, Provisioning and Identity Lifecycle63910
Strong
Assessment Strategy, Audit and Control Testing63610
Strong
Vulnerability Testing, Penetration Testing and Reporting63610
Strong
Operations, Investigations and Incident Response73910
Priority
Logging, Backup, Disaster Recovery and Resilience63910
Strong
Secure SDLC, DevSecOps and Software Testing53010
Strong
Secure Coding, Software Supply Chain and API Security53010
Strong

How to use this guide

How to study for CISSP

Treat each CISSP question as a risk decision: identify the owner, objective, control type, lifecycle phase, and business consequence before choosing.

1. Identify ownership

Find the business owner, data owner, risk owner, custodian, user, or third party accountable for the decision.

2. Define the objective

Clarify whether the scenario tests confidentiality, integrity, availability, privacy, safety, compliance, or resilience.

3. Select the control path

Choose policy, process, administrative, technical, physical, preventive, detective, corrective, or compensating control.

4. Verify assurance

Look for evidence, monitoring, testing, auditability, review, lessons learned, and residual risk acceptance.

Ethics, Governance and Risk Decisions
Risk Management

Ethics, Governance and Risk Decisions

This topic covers the ISC2 ethics mindset, security governance, business alignment, risk ownership, due care, due diligence, control frameworks, and risk response.

Key rules

Rule 1

Ethics, Governance and Risk Decisions questions test whether a security leader can choose a defensible control, process, or governance response for a business risk.

Exam cue: Identify the domain objective: govern risk, protect assets, engineer securely, secure networks, control identity, test, operate, or secure software.

Rule 2

The best CISSP answer usually protects people, policy, data, and mission before jumping to a narrow technical fix.

Exam cue: Match the response to the risk owner, data owner, control objective, lifecycle phase, and assurance evidence in the scenario.

Rule 3

Eliminate answers that skip authorization, ignore legal or contractual duties, weaken least privilege, or confuse preventive, detective, and corrective controls.

Exam cue: Prefer documented policy, due care, defense in depth, least privilege, validated recovery, and continuous improvement.

Common traps

Choosing a tool before confirming business requirements, ownership, and risk treatment.

Prevention: Avoid answers that jump to a tool, ignore the risk owner, weaken least privilege, skip evidence, or treat one security objective as the only concern.

Treating confidentiality as the only goal when integrity, availability, authenticity, accountability, and safety also matter.

Prevention: Avoid answers that jump to a tool, ignore the risk owner, weaken least privilege, skip evidence, or treat one security objective as the only concern.

Ignoring legal, regulatory, contractual, audit, and evidence-handling obligations.

Prevention: Avoid answers that jump to a tool, ignore the risk owner, weaken least privilege, skip evidence, or treat one security objective as the only concern.

Memory anchors

ISC2 Ethics

ISC2 ethics questions favor protecting society, acting honorably, providing competent service, and advancing the profession.

Due Care

Due care is the reasonable action a prudent organization takes to protect assets and people.

Due Diligence

Due diligence is the investigation and ongoing effort used to understand and manage risk.

Risk Owner

A risk owner is accountable for deciding whether to avoid, transfer, mitigate, or accept risk.

Control Framework

A control framework organizes security objectives, control families, and assurance expectations.

Risk Treatment

Risk treatment selects avoid, transfer, mitigate, or accept based on business risk appetite.

Security Governance

Security governance aligns security strategy, roles, policies, and measurement with organizational objectives.

Policy Hierarchy

Policies set intent, standards define mandatory requirements, procedures give steps, and guidelines offer advice.

Threat Modeling

Threat modeling identifies likely threats, attack paths, controls, and residual risk before or during design.

Compliance Duty

Compliance duties come from laws, regulations, contracts, standards, and internal policy obligations.

Next best moves

Quick check-up

Use a short quiz to confirm the rule pattern is actually sticking.

Check-up Questions

1-2 question checkpoint

A security consultant discovers that a client's product can expose patients to physical harm. The client asks the consultant to remain silent until the next release. What should the consultant do FIRST?

A payroll manager accidentally receives access to employee medical records. No evidence shows that the records were viewed or changed. Which security objective has already been violated?

Answer all questions to submit.

Next step personalized recommendations

Open another topic next

Official resources

Verify the details with the official sources

Use these links for eligibility, scheduling, handbook rules, and issuer updates. Our guide helps you study; official sources tell you what the testing partner currently requires.

FAQ

Common CISSP questions

Is this the official CISSP exam?

No. These are original practice questions aligned to ISC2's public CISSP exam outline. They are not copied from secure exam material.

Which CISSP outline is this aligned to?

This content is aligned to the ISC2 CISSP outline effective April 15, 2024.

What domains are covered?

The bank covers all eight CISSP domains: security and risk management, asset security, architecture and engineering, communication and network security, IAM, assessment and testing, operations, and software development security.

How should I answer CISSP scenario questions?

Start with governance and risk ownership, then choose the control or process that best protects the organization while respecting policy, law, ethics, and business objectives.

How should I use the 601 questions?

Use topic drills for weak domains, section drills for each ISC2 domain, then 100-question weighted mocks that mirror the published domain percentages.

What is Pass Harbor?

Completely free exam prep for 317 U.S. exams.

  • Practice questions
  • Flashcards
  • Study guides
  • Mock exams
  • No registration
  • No paywall
  • Start instantly
No more expensive exam prep. Quality study tools should be accessible to everyone.