ISC2 · CISSP
Validates technical and managerial security knowledge across eight domains, from risk and architecture through identity, assessment, operations, and software development security.
Practice Questions
850
≈ 6 practice exams
Duration
180 minutes
Passing Score
700/1000
Difficulty
ProfessionalLast Updated
Oct 2026
CISSP tests whether an experienced security practitioner can make sound technical and managerial decisions across an entire security program. The current eight-domain outline gives Security and Risk Management the largest weight at 16%; Security Operations is 13%, not the 15% figure found in some older summaries. The other six domains range from 10% to 13%.
All CISSP language versions now use computerized adaptive testing. Candidates receive 100-150 multiple-choice and advanced items in up to three hours and need 700 out of 1,000 points. Full certification also requires five years of paid experience in at least two domains, subject to a maximum one-year waiver; candidates without the experience can pursue Associate of ISC2 status after passing.
Use this 850-question bank to practice switching between governance, architecture, networking, identity, assessment, operations, and software-security decisions. Start with 30 free questions, then keep every domain in rotation because the adaptive exam does not reward a strategy built around one predictable question sequence.
The Certified Information Systems Security Professional (CISSP) validates the ability to design, engineer, and manage an organization's security posture across eight domains. The current ISC2 outline took effect April 15, 2024 and balances governance and risk decisions with architecture, networking, identity, assessment, operations, and secure software development.
CISSP uses computerized adaptive testing for all available languages. Candidates receive 100-150 items and up to three hours; the adaptive exam may finish once the scoring algorithm has enough evidence to determine the result.
CISSP is aimed at experienced security practitioners whose responsibilities cross technical implementation and organizational security leadership. ISC2 highlights roles such as security managers, architects, consultants, directors, and senior engineers.
Candidates who pass before meeting the experience requirement can become an Associate of ISC2 and work toward the required experience before applying for the full credential.
Full CISSP certification requires five years of cumulative paid work experience in at least two of the eight current CISSP domains. A four-year degree or an approved credential can waive one year, but the waiver cannot reduce the requirement below four years.
After passing, candidates must complete ISC2's endorsement process, agree to the Code of Ethics, and pay the applicable annual maintenance fee. Passing the exam alone does not immediately confer full CISSP status when the experience requirement is unmet.
The CISSP CAT exam contains 100-150 multiple-choice and advanced item types, allows up to 180 minutes, and requires 700 out of 1,000 points. It is offered in Chinese, English, German, Japanese, and Spanish at authorized Pearson testing centers; Chinese appointments are available in specified windows.
ISC2 currently lists the CISSP exam at $749 in the United States. Regional prices and taxes vary, so candidates should confirm the amount shown for their examination location.
CISSP demonstrates broad security leadership knowledge plus verified professional experience across at least two security domains. ISC2 describes it as a credential for professionals who design, engineer, and manage an organization's security program.
To remain in good standing, holders must earn 120 continuing professional education credits over each three-year cycle and pay the annual ISC2 maintenance fee, currently $135. ISC2 charges one member maintenance fee even when a member holds multiple qualifying ISC2 certifications.
5 sample questions with answers and explanations. The full bank has 850 questions, enough for 6 full-length practice exams.
Preview — answers shown1. An organization implements NIST Cybersecurity Framework 2.0. Which core function was newly added in version 2.0 and emphasizes executive accountability for cybersecurity strategy aligned with business objectives? (Select one!)
Explanation
GOVERN is the sixth core function newly added in NIST CSF 2.0, released in February 2024. It emphasizes executive accountability and strategic alignment of cybersecurity with business objectives, establishing organizational context, risk management strategy, and oversight. The original five functions from CSF 1.0 were Identify, Protect, Detect, Respond, and Recover. GOVERN now precedes all other functions, reflecting that governance decisions must drive all cybersecurity activities.
2. An organization evaluating governance frameworks needs one that aligns IT strategy with business objectives and is most commonly used for Sarbanes-Oxley compliance. Which framework should they select? (Select one!)
Explanation
COBIT (Control Objectives for Information and Related Technology) is specifically designed to align IT and business strategies and is the most commonly used framework for SOX compliance. COBIT provides comprehensive governance covering 40 objectives across five domains including risk management, information security, and compliance. NIST CSF 2.0 focuses on cybersecurity risk management rather than IT governance. ISO 27001 is an ISMS certification standard focused on information security controls. SABSA is a business-driven security architecture framework rather than an IT governance framework.
3. A global enterprise needs to ensure employees cannot accumulate excessive privileges as they change roles over time within the organization. Which identity and access management concept specifically addresses this risk? (Select one!)
Explanation
Privilege creep is the accumulation of access rights and permissions as users move between roles without previous permissions being revoked. This occurs when the Joiner-Mover-Leaver lifecycle is not properly managed, specifically during the Mover phase when access should be reviewed and adjusted. Separation of duties prevents users from holding conflicting roles simultaneously. Least privilege means granting only the minimum necessary permissions for current job functions. Need to know is a principle limiting access to specific information required for job duties.
4. During a security assessment, you discover that database administrators can both create user accounts and grant those accounts elevated privileges without oversight. Which two security principles are being violated? (Select two!)
Multiple correct answersExplanation
Separation of duties is violated because a single person controls the entire critical process of account creation and privilege assignment. Least privilege is violated because the administrator has more permissions than necessary to perform their job effectively. Dual control requires two people simultaneously present, which is not specifically violated here. Job rotation involves periodic role changes for fraud detection. Need to know limits information access but is less directly applicable to this permission scenario.
5. An organization implements RAID for critical database servers to ensure continuous operation during hardware failures. The solution must survive two simultaneous disk failures while maximizing usable storage capacity. Which RAID level meets these requirements most effectively? (Select one!)
Explanation
RAID 6 uses double parity and can tolerate two simultaneous disk failures while maintaining data availability. It requires a minimum of four disks and provides (n-2)/n usable capacity. RAID 0 provides no fault tolerance and loses all data if any single disk fails. RAID 1 (mirroring) tolerates only one disk failure per mirror pair. RAID 5 uses single parity and tolerates only one disk failure, failing catastrophically if a second disk fails before the first is rebuilt. RAID 6 is the only option that satisfies the two-disk failure requirement.
CISSP uses computerized adaptive testing and presents 100-150 multiple-choice and advanced items. The maximum testing time is three hours.
ISC2 requires 700 out of 1,000 points. Because the test is adaptive, candidates can receive different item counts and difficulty paths.
Full certification requires five years of cumulative paid work experience in at least two current CISSP domains. A four-year degree or approved credential can waive one year.
Yes. If you pass before meeting the experience requirement, you can apply for Associate of ISC2 status while you build the experience needed for full certification.
Security and Risk Management is 16%. Security Architecture and Engineering, Communication and Network Security, Identity and Access Management, and Security Operations are each 13%.
Earn 120 CPE credits during each three-year cycle and pay the annual ISC2 maintenance fee, currently $135. ISC2 charges one member fee even if you hold multiple qualifying certifications.
Certified in Cybersecurity (CC)
CC · 838 questions
Certified Secure Software Lifecycle Professional (CSSLP)
CSSLP · 841 questions
Certified in Governance, Risk and Compliance (CGRC)
CGRC · 850 questions
Information Systems Security Architecture Professional (ISSAP)
ISSAP · 850 questions
Information Systems Security Management Professional (ISSMP)
ISSMP · 833 questions
Information Systems Security Engineering Professional (ISSEP)
ISSEP · 850 questions
$17.99
One-time access to this exam