ISC2 · ISSEP
An advanced ISC2 security-engineering credential covering engineering foundations, risk, security planning, implementation and verification, and secure lifecycle operations.
Practice Questions
850
≈ 6 practice exams
Duration
180 minutes
Passing Score
700/1000
Difficulty
SpecialtyLast Updated
Oct 2026
ISSEP treats security as an engineering discipline carried across the full system lifecycle. The August 2025 outline begins with Systems Security Engineering Foundations (24%) and Security Planning and Engineering (22%), then tests risk, implementation and verification, and secure operations through disposal. Together the two largest domains account for 46%.
The exam has 125 items, allows three hours, and requires 700 out of 1,000 points. CISSP is one eligibility route, not an absolute prerequisite: a CISSP holder needs two years of focused experience, while the standalone route requires seven years across at least two ISSEP domains, with a possible one-year waiver.
This 850-question ISSEP practice bank is built for repeated work across all five domains. Start with 30 free questions and practice tracing a security need into requirements, architecture, implementation, verification evidence, operational change, and eventual disposal rather than memorizing controls without their engineering context.
Information Systems Security Engineering Professional (ISSEP) is an advanced ISC2 certification for practitioners who treat cybersecurity as an engineering discipline across the system lifecycle. Developed with the U.S. National Security Agency, it covers requirements, architecture, implementation decisions, verification evidence, authorization support, operational change, and secure disposal.
The current outline took effect August 1, 2025. Systems Security Engineering Foundations is the largest domain at 24%, followed by Security Planning and Engineering at 22%. ISSEP is available through both a CISSP-based pathway and a standalone experience pathway.
ISSEP is designed for experienced security engineers, architects, systems engineers, and other practitioners responsible for integrating security into complex systems from concept through disposal. Its current objectives span Zero Trust, supply-chain risk, DevSecOps, model-based systems engineering, verification, and lifecycle operations.
It is not exclusively a CISSP concentration. Experienced security engineers can pursue ISSEP through ISC2's standalone seven-year route even when they do not hold CISSP.
A CISSP in good standing can qualify with two years of cumulative full-time experience in one or more current ISSEP domains. The standalone route requires seven years of cumulative full-time experience across at least two current domains.
For the standalone route, a relevant bachelor's or master's degree or an approved additional credential can waive one year, and only one year can be waived. Qualifying part-time work and internships may count. Candidates who pass without the required experience may apply for Associate of ISC2 status and have up to eight years to earn the experience.
The ISSEP exam has 125 items, allows three hours, and includes multiple-choice and advanced item types. It is offered in English at Pearson Testing Centers and requires 700 out of 1,000 points to pass.
ISC2 currently lists regional standard prices of $599 in the Americas and many other regions, €575.04 in EMEA, and £485.19 in the United Kingdom. Taxes and currency depend on the examination location.
ISSEP verifies advanced security-engineering knowledge and qualifying experience through either the CISSP-based or standalone route. ISC2 states that the credential is ANAB-accredited under ISO/IEC 17024 and recognized in the U.S. Department of Defense 8140 framework, although suitability for a particular role still depends on that role's requirements.
Maintenance differs by pathway: an ISSEP holder with CISSP needs 60 ISSEP-related Group A CPE credits per three-year cycle, counted within the CISSP total; a holder without CISSP needs 140 Group A credits. ISC2 currently charges one $135 annual member maintenance fee regardless of the number of qualifying certifications held.
5 sample questions with answers and explanations. The full bank has 850 questions, enough for 6 full-length practice exams.
Preview — answers shown1. A reliability engineer calculates availability metrics for a critical authentication server. The server has experienced four failures over 8760 hours of operation with a total downtime of 12 hours. What is the Mean Time Between Failures for this server? (Select one!)
Explanation
MTBF is calculated as total operational time divided by number of failures. Total operational time is 8760 hours minus 12 hours downtime equals 8748 hours. MTBF equals 8748 hours divided by 4 failures equals 2187 hours, which rounds to 2190 hours. The 730-hour option incorrectly divides calendar hours by failures without subtracting downtime. The 2920-hour option appears to use incorrect calculation methodology. The 8748-hour option represents total uptime but does not account for the four failure events.
2. A reliability engineer calculates availability metrics for a critical authentication service. The service experiences three failures over 8,760 operational hours with repair times of 2, 3, and 4 hours respectively. What is the Mean Time Between Failures? (Select one!)
Explanation
Mean Time Between Failures is calculated as Total Operational Time divided by Number of Failures. Total operational time equals 8,760 hours. Number of failures equals 3. MTBF equals 8,760 divided by 3, which equals 2,920 hours. The value 2,917 hours incorrectly subtracts total repair time before calculating. The value 8,751 hours incorrectly subtracts repair time from operational hours. The value 3 hours confuses MTBF with repair duration.
3. A systems engineer develops Technical Performance Measures for a secure communications system. The reliability analysis shows Mean Time Between Failures of 8760 hours and Mean Time To Repair of 4 hours. What is the system availability percentage? (Select one!)
Explanation
Availability = MTBF / (MTBF + MTTR) = 8760 / (8760 + 4) = 8760 / 8764 = 0.9995 or 99.95 percent. This calculation is fundamental to resource analysis under Domain 1.6. MTBF represents operational time between failures (8760 hours = 1 year). MTTR represents time to restore after failure (4 hours). The other percentages result from incorrect formulas or arithmetic errors.
4. A reliability engineer is calculating availability metrics for a critical security monitoring system. The system has experienced three failures over 8,760 operational hours with total repair time of 12 hours. What is the Mean Time Between Failures for this system? (Select one!)
Explanation
Mean Time Between Failures is calculated as total operational time divided by number of failures. Total operational time is 8,760 hours minus 12 hours of repair time, yielding 8,748 hours of actual operation. MTBF equals 8,748 hours divided by 3 failures, which equals 2,916 hours. This represents the average operational time between successive failures. The calculation of 730 hours incorrectly divides 8,760 by 12 instead of using the proper MTBF formula. The calculation of 2,920 hours incorrectly divides total hours by failures without subtracting repair time. Four hours would be Mean Time To Repair, calculated as 12 hours total repair time divided by 3 failures, which is a different metric measuring restoration time rather than operational reliability.
5. A maintainability engineer calculates reliability metrics for a radar system. The system operates 8,760 hours per year and experiences three failures during the year. Each failure requires an average of 6 hours to repair. What is the Mean Time Between Failures (MTBF) for this system? (Select one!)
Explanation
Mean Time Between Failures (MTBF) equals Total operational time divided by Number of failures. Total operational time is 8,760 hours and there were 3 failures, so MTBF equals 8,760 divided by 3 equals 2,920 hours. The 6-hour repair time is Mean Time To Repair (MTTR), which is a different metric. MTBF measures reliability (how long between failures), while MTTR measures maintainability (how quickly failures are repaired). Domain 1.6 Resource Analysis added quantitative reliability metrics including MTBF, MTTF, MTTR, and MTD to the August 2025 exam.
No. A CISSP in good standing can qualify with two years of ISSEP-domain experience, but ISC2 also offers a standalone route requiring seven years across at least two domains.
The standalone route requires seven years of cumulative full-time experience across at least two current ISSEP domains. A relevant degree or approved credential can waive one year.
Yes. A candidate who passes without the experience may apply for Associate of ISC2 status and has up to eight years to obtain the required experience.
The exam has 125 items, allows three hours, and uses multiple-choice and advanced item types. It is offered in English at Pearson Testing Centers and requires 700 out of 1,000.
Engineering Foundations is 24%, Risk Management 20%, Security Planning and Engineering 22%, Implementation, Verification and Validation 20%, and Secure Operations, Change Management and Disposal 14%.
A holder with CISSP needs 60 ISSEP-related Group A CPEs per three-year cycle within the CISSP total; a holder without CISSP needs 140 Group A CPEs. The current annual ISC2 member fee is $135.
Certified Information Systems Security Professional (CISSP)
CISSP · 850 questions
Information Systems Security Architecture Professional (ISSAP)
ISSAP · 850 questions
Information Systems Security Management Professional (ISSMP)
ISSMP · 833 questions
Systems Security Certified Practitioner (SSCP)
SSCP · 849 questions
Certified Cloud Security Professional (CCSP)
CCSP · 850 questions
Certified in Cybersecurity (CC)
CC · 838 questions
$17.99
One-time access to this exam