What to Study for the ISC2 CISSP Exam
The Certified Information Systems Security Professional (CISSP®) certification validates the technical and managerial knowledge needed to design, engineer, implement, and manage an organization’s information security program.
The current CISSP Certification Exam Outline took effect on April 15, 2024. It includes eight domains covering governance, risk, assets, architecture, networks, identity, testing, operations, and secure software development.
CISSP Experience Requirements
To earn the CISSP certification, you must have at least five years of cumulative professional experience in two or more of the eight CISSP domains.
You may satisfy up to one year of the experience requirement through an eligible postsecondary degree or an approved credential. Only one year can be waived. Qualifying part-time employment and internships may also count.
If you pass the exam without the required experience, you may become an Associate of ISC2. You then have six years to earn the experience required for CISSP certification.
CISSP Exam Format
- Testing format: Computerized Adaptive Testing
- Number of items: 100 to 150
- Testing time: Three hours
- Item formats: Multiple-choice and advanced item types
- Passing score: 700 out of 1,000
The CAT format adjusts question selection based on your responses. The exam may end after the minimum number of items, once the system determines, with sufficient confidence, whether your ability is above or below the passing standard.
What Is on the CISSP Exam?
| Domain | Average Weight |
|---|---|
| Security and Risk Management | 16% |
| Asset Security | 10% |
| Security Architecture and Engineering | 13% |
| Communication and Network Security | 13% |
| Identity and Access Management | 13% |
| Security Assessment and Testing | 12% |
| Security Operations | 13% |
| Software Development Security | 10% |
Domain 1: Security and Risk Management
Average exam weight: 16%
This is the largest CISSP domain. It covers the governance, ethical, legal, and risk foundations of an information security program.
Review:
- ISC2 and organizational codes of ethics
- Confidentiality, integrity, availability, authenticity, and nonrepudiation
- Security governance and alignment with business strategy
- Due care and due diligence
- Legal, regulatory, contractual, and privacy requirements
- Investigation types
- Policies, standards, procedures, and guidelines
- Business continuity requirements and business impact analysis
- Personnel security
- Risk identification, analysis, treatment, and monitoring
- Threat modeling
- Supply-chain risk
- Security awareness, education, and training
Approach risk questions from the organization’s perspective. The best answer often supports business objectives, follows governance, and addresses risk at the appropriate level before selecting a technical control.
Domain 2: Asset Security
Average exam weight: 10%
Asset Security covers how organizations identify, classify, handle, retain, and destroy information and other assets.
Study:
- Data and asset classification
- Handling requirements
- Asset ownership and inventory
- Data owners, controllers, custodians, processors, users, and subjects
- Data collection, location, maintenance, retention, and destruction
- Data remanence
- End-of-life and end-of-support requirements
- Data in use, in transit, and at rest
- Data loss prevention, digital rights management, and cloud access security brokers
Controls should reflect the asset’s classification, value, sensitivity, location, legal requirements, and position in the data life cycle.
Domain 3: Security Architecture and Engineering
Average exam weight: 13%
This domain covers secure design principles, security models, cryptography, system architecture, facilities, and the information system life cycle.
Review:
- Least privilege and defense in depth
- Secure defaults and fail-secure design
- Separation of duties
- Zero Trust
- Privacy by design
- Shared-responsibility models
- Security models such as Bell-LaPadula and Biba
- Hardware-based security capabilities
- Cloud, virtualized, containerized, serverless, IoT, embedded, edge, and industrial systems
- Symmetric and asymmetric cryptography
- Hashing, digital signatures, certificates, and public key infrastructure
- Cryptanalytic attacks
- Physical and environmental security
- The complete information system life cycle
Understand what security property a model or control protects rather than memorizing names alone.
Domain 4: Communication and Network Security
Average exam weight: 13%
This domain measures your ability to design and protect network architectures, components, and communication channels.
Study:
- OSI and TCP/IP models
- IPv4 and IPv6
- Secure communication protocols
- Network topologies and traffic flows
- Physical, logical, and microsegmentation
- VLANs, VPNs, and virtual routing
- Zero Trust network concepts
- Wireless, mobile, satellite, and content-delivery networks
- Software-defined networking
- Virtual private clouds
- Network observability and capacity management
- Network access control and endpoint security
- Remote and third-party connectivity
Connect network controls to threats, trust boundaries, business requirements, and data flows.
Domain 5: Identity and Access Management
Average exam weight: 13%
Identity and Access Management addresses physical and logical access for people, devices, systems, and services.
Review:
- Identification, authentication, authorization, and accounting
- Multifactor and passwordless authentication
- Identity proofing and registration
- Credential management
- Single sign-on
- Federated identity
- Just-in-time access
- Role, rule, attribute, risk, mandatory, and discretionary access controls
- Provisioning and deprovisioning
- Access reviews
- Privilege escalation and privileged-account management
- Service accounts
Access should be based on business need, least privilege, and approved identity life-cycle processes.
Domain 6: Security Assessment and Testing
Average exam weight: 12%
This domain covers the design, execution, analysis, and reporting of security tests, assessments, and audits.
Study:
- Internal, external, and third-party assessments
- On-premises, cloud, and hybrid testing
- Vulnerability assessments
- Penetration testing
- Red, blue, and purple team exercises
- Log and code reviews
- Interface and misuse-case testing
- Breach and attack simulations
- Compliance checks
- Security metrics and indicators
- Test-output analysis
- Remediation and exception handling
- Ethical disclosure
Know the purpose, authorization requirements, limitations, and expected output of each assessment method.
Domain 7: Security Operations
Average exam weight: 13%
Security Operations covers investigations, monitoring, incident response, change management, recovery, continuity, physical security, and personnel safety.
Review:
- Evidence collection and handling
- Digital forensics
- Logging, SIEM, threat intelligence, threat hunting, and UEBA
- Configuration management and baselines
- Privileged operations and separation of duties
- Media protection
- Incident detection, response, recovery, and lessons learned
- Firewalls, IDS, IPS, sandboxing, honeypots, and antimalware
- Patch and vulnerability management
- Change management
- Backup and recovery strategies
- Disaster recovery procedures and tests
- Business continuity exercises
- Physical security
- Personnel safety and emergency management
During an incident, protect people first, follow the approved response process, preserve evidence when required, contain damage, restore operations, and document lessons learned.
Domain 8: Software Development Security
Average exam weight: 10%
This domain addresses security throughout software development and acquisition.
Study:
- Agile, Waterfall, DevOps, and DevSecOps
- Software maturity models
- Security requirements throughout the SDLC
- Programming languages, libraries, runtimes, and development tools
- CI/CD pipelines
- Code repositories and configuration management
- Static, dynamic, interactive, and composition analysis
- Change auditing and risk analysis
- Commercial, open-source, third-party, managed, and cloud software
- Source-code vulnerabilities
- API security
- Secure coding standards
Security should be integrated throughout development rather than treated as a final test before release.
How to Study for the CISSP Exam
Think Like a Security Leader
The CISSP exam combines technical and managerial judgment. When answering a scenario, ask:
- What business objective or asset must be protected?
- What is the greatest risk?
- Which policy, process, or requirement applies?
- Who owns the risk or decision?
- Does the organization need more information before acting?
- Which option addresses the root cause?
- What should occur before implementing a technical solution?
- Which answer best supports people, business operations, and governance?
Study Relationships Across Domains
CISSP scenarios often combine several domains. A cloud migration may involve governance, asset classification, architecture, networks, access, testing, operations, and software security.
Prepare for CAT
You cannot judge your performance from the number or apparent difficulty of the questions. Read carefully, answer the current item, and maintain a steady pace throughout the three-hour examination.
Start Preparing for the CISSP Exam
Pocket Prep’s CISSP practice questions help you review all eight domains and apply security knowledge to realistic technical and managerial scenarios. Each question includes detailed explanations of the correct and incorrect answers.