Free Practice Questions for ISC2 CISSP Certification

    🔄 Last checked for updates June 14th, 2026

    Study with 239 exam-style practice questions designed to help you prepare for the ISC2 CISSP. All questions are aligned with the latest exam guide and include detailed explanations to help you master the material.

    Start Practicing

    All Domains

    Practice with randomly mixed questions from all topics

    Question MixAll Topics
    FormatRandom Order

    Domain Mode

    Practice questions from a specific topic area

    Quiz History

    Exam Details

    Key information about ISC2 CISSP

    Official study guide

    View

    Question formats CertSafari offers
    • Multiple choice
    • Ordering
    • Matching
    exam format:

    Multiple choice and advanced innovative items

    exam language:

    Chinese, English, German, Japanese, Spanish

    passing score:

    700 out of 1000 points

    prerequisites:

    Minimum of five years cumulative, full-time experience in two or more of the eight domains of the current CISSP Exam Outline. A post-secondary degree (bachelors or masters) in computer science, information technology (IT) or related fields, or an additional credential from the ISC2 approved list, may satisfy up to one year of the required experience. Part-time work and internships may also count towards the experience requirement. Candidates without the required experience may become an Associate of ISC2 by successfully passing the examination, then have six years to earn the five years required experience.

    delivery method:

    ISC2 Authorized PPC and PVTC Select Pearson VUE Testing Centers

    time limit minutes:

    180 minutes

    number of questions:

    100 - 150

    Exam Topics & Skills Assessed

    Skills measured (from the official study guide)

    Domain 1: Security and Risk Management

    Subdomain 1.1: Understand, adhere to, and promote professional ethics

    - ISC2 Code of Professional Ethics - Organizational code of ethics

    Subdomain 1.2: Understand and apply security concepts

    - Confidentiality, integrity, and availability, authenticity, and nonrepudiation (5 Pillars of Information Security)

    Subdomain 1.3: Evaluate and apply security governance principles

    Evaluate and apply security governance principles

    Subdomain 1.4: Understand legal, regulatory, and compliance issues that pertain to information security in a holistic context

    Understand legal, regulatory, and compliance issues that pertain to information security in a holistic context

    Subdomain 1.5: Understand requirements for investigation types (i.e., administrative, criminal, civil, regulatory, industry standards)

    Understand requirements for investigation types (i.e., administrative, criminal, civil, regulatory, industry standards)

    Subdomain 1.6: Develop, document, and implement security policy, standards, procedures, and guidelines

    Develop, document, and implement security policy, standards, procedures, and guidelines

    Subdomain 1.7: Identify, analyze, assess, prioritize, and implement Business Continuity (BC) requirements

    - Alignment of the security function to business strategy, goals, mission, and objectives - Organizational processes (e.g., acquisitions, divestitures, governance committees) - Organizational roles and responsibilities - Security control frameworks (e.g., International Organization for Standardization (ISO), National Institute of Standards and Technology (NIST), Control Objectives for Information and Related Technology (COBIT), Sherwood Applied Business Security Architecture (SABSA), Payment Card Industry (PCI), Federal Risk and Authorization Management Program (FedRAMP)) - Due care/due diligence - Cybercrimes and data breaches - Licensing and Intellectual Property requirements - Import/export controls - Transborder data flow - Issues related to privacy (e.g., General Data Protection Regulation (GDPR), California Consumer Privacy Act, Personal Information Protection Law, Protection of Personal Information Act) - Contractual, legal, industry standards, and regulatory requirements - Business impact analysis (BIA) - External dependencies

    Subdomain 1.8: Contribute to and enforce personnel security policies and procedures

    - Candidate screening and hiring - Employment agreements and policy driven requirements - Onboarding, transfers, and termination processes - Vendor, consultant, and contractor agreements and controls

    Subdomain 1.9: Understand and apply risk management concepts

    - Threat and vulnerability identification - Risk analysis, assessment, and scope - Risk response and treatment (e.g., cybersecurity insurance) - Applicable types of controls (e.g., preventive, detection, corrective) - Control assessments (e.g., security and privacy) - Continuous monitoring and measurement - Reporting (e.g., internal, external) - Continuous improvement (e.g., risk maturity modeling) - Risk frameworks (e.g., International Organization for Standardization (ISO), National Institute of Standards and Technology (NIST), Control Objectives for Information and Related Technology (COBIT), Sherwood Applied Business Security Architecture (SABSA), Payment Card Industry (PCI))

    Subdomain 1.10: Understand and apply threat modeling concepts and methodologies

    Understand and apply threat modeling concepts and methodologies

    Subdomain 1.11: Apply supply chain risk management (SCRM) concepts

    - Risks associated with the acquisition of products and services from suppliers and providers (e.g., product tampering, counterfeits, implants) - Risk mitigations (e.g., third-party assessment and monitoring, minimum security requirements, service level requirements, silicon root of trust, physically unclonable function, software bill of materials)

    Subdomain 1.12: Establish and maintain a security awareness, education, and training program

    - Methods and techniques to increase awareness and training (e.g., social engineering, phishing, security champions, gamification) - Periodic content reviews to include emerging technologies and trends (e.g., cryptocurrency, artificial intelligence (AI), blockchain) - Program effectiveness evaluation

    Domain 2: Asset Security

    Subdomain 2.1: Identify and classify information and assets

    - Information and asset ownership - Asset inventory (e.g., tangible, intangible) - Asset management - Data classification - Asset Classification

    Subdomain 2.2: Establish information and asset handling requirements

    - Data roles (i.e., owners, controllers, custodians, processors, users/subjects) - Data collection - Data location - Data maintenance - Data retention - Data remanence - Data destruction - Data states (e.g., in use, in transit, at rest)

    Subdomain 2.3: Provision information and assets securely

    Provision information and assets securely

    Subdomain 2.4: Manage data lifecycle

    Manage data lifecycle

    Subdomain 2.5: Ensure appropriate asset retention (e.g., End of Life (EOL), End of Support)

    Ensure appropriate asset retention (e.g., End of Life (EOL), End of Support)

    Subdomain 2.6: Determine data security controls and compliance requirements

    - Scoping and tailoring - Standards selection - Data protection methods (e.g., Digital Rights Management (DRM), data loss prevention (DLP), cloud access security broker (CASB))

    Domain 3: Security Architecture and Engineering

    Subdomain 3.1: Research, implement and manage engineering processes using secure design principles

    - Threat modeling - Least privilege - Defense in depth - Secure defaults - Fail securely - Segregation of Duties (SoD) - Keep it simple and small - Zero trust or trust but verify - Privacy by design - Shared responsibility - Secure access service edge

    Subdomain 3.2: Understand the fundamental concepts of security models (e.g., Biba, Star Model, Bell-LaPadula)

    Understand the fundamental concepts of security models (e.g., Biba, Star Model, Bell-LaPadula)

    Subdomain 3.3: Select controls based upon systems security requirements

    Select controls based upon systems security requirements

    Subdomain 3.4: Understand security capabilities of Information Systems (IS) (e.g., memory protection, Trusted Platform Module (TPM), encryption/decryption)

    Understand security capabilities of Information Systems (IS) (e.g., memory protection, Trusted Platform Module (TPM), encryption/decryption)

    Subdomain 3.5: Assess and mitigate the vulnerabilities of security architectures, designs, and solution elements

    - Client-based systems - Server-based systems - Database systems - Cryptographic systems - Industrial Control Systems (ICS) - Cloud-based systems (e.g., Software as a Service (SaaS), Infrastructure as a Service (IaaS), Platform as a Service (PaaS)) - Distributed systems - Internet of Things (IoT) - Microservices (e.g., application programming interface (API)) - Containerization - Serverless - Embedded systems - High-Performance Computing systems - Edge computing systems - Virtualized systems

    Subdomain 3.6: Select and determine cryptographic solutions

    - Cryptographic life cycle (e.g., keys, algorithm selection) - Cryptographic methods (e.g., symmetric, asymmetric, elliptic curves, quantum) - Public key infrastructure (PKI) (e.g., quantum key distribution) - Key management practices (e.g., rotation) - Digital signatures and digital certificates (e.g., non-repudiation, integrity)

    Subdomain 3.7: Understand methods of cryptanalytic attacks

    - Brute force - Ciphertext only - Known plaintext - Frequency analysis - Chosen ciphertext - Implementation attacks - Side-channel - Fault injection - Timing - Man-in-the-Middle (MITM) - Pass the hash - Kerberos exploitation - Ransomware

    Subdomain 3.8: Apply security principles to site and facility design

    Apply security principles to site and facility design

    Subdomain 3.9: Design site and facility security controls

    - Wiring closets/intermediate distribution facilities - Server rooms/data centers - Media storage facilities - Evidence storage - Restricted and work area security - Utilities and heating, ventilation, and air conditioning (HVAC) - Environmental issues (e.g., natural disasters, man-made) - Fire prevention, detection, and suppression - Power (e.g., redundant, backup)

    Subdomain 3.10: Manage the information system lifecycle

    - Stakeholders needs and requirements - Requirements analysis - Architectural design - Development /implementation - Integration - Verification and validation - Transition/deployment - Operations and maintenance/sustainment - Retirement/disposal

    Domain 4: Communication and Network Security

    Subdomain 4.1: Apply secure design principles in network architectures

    - Open System Interconnection (OSI) and Transmission Control Protocol/Internet Protocol (TCP/IP) models - Internet Protocol (IP) version 4 and 6 (IPv6) (e.g., unicast, broadcast, multicast, anycast) - Secure protocols (e.g., Internet Protocol Security (IPSec), Secure Shell (SSH), Secure Sockets Layer (SSL)/Transport Layer Security (TLS)) - Implications of multilayer protocols - Converged protocols (e.g., Internet Small Computer Systems Interface (iSCSI), Voice over Internet Protocol (VoIP), InfiniBand over Ethernet, Compute Express Link) - Transport architecture (e.g., topology, data/control/management plane, cut-through/store-and-forward) - Performance metrics (e.g., bandwidth, latency, jitter, throughput, signal-to-noise ratio) - Traffic flows (e.g., north-south, east-west) - Physical segmentation (e.g., in-band, out-of-band, air-gapped) - Logical segmentation (e.g., virtual local area networks (VLANs), virtual private networks (VPNs), virtual routing and forwarding, virtual domain) - Micro-segmentation (e.g., network overlays/encapsulation; distributed firewalls, routers, intrusion detection system (IDS)/intrusion prevention system (IPS), zero trust) - Edge networks (e.g., ingress/egress, peering) - Wireless networks (e.g., Bluetooth, Wi-Fi, Zigbee, satellite) - Cellular/mobile networks (e.g., 4G, 5G) - Content distribution networks (CDN) - Software defined networks (SDN), (e.g., application programming interface (API), Software-Defined Wide-Area Network, network functions virtualization) - Virtual Private Cloud (VPC) - Monitoring and management (e.g., network observability, traffic flow/shaping, capacity management, fault detection and handling)

    Subdomain 4.2: Secure network components

    - Operation of infrastructure (e.g., redundant power, warranty, support) - Transmission media (e.g., physical security of media, signal propagation quality) - Network Access Control (NAC) systems (e.g., physical, and virtual solutions) - Endpoint security (e.g., host-based)

    Subdomain 4.3: Implement secure communication channels according to design

    - Voice, video, and collaboration (e.g., conferencing, Zoom rooms) - Remote access (e.g., network administrative functions) - Data communications (e.g., backhaul networks, satellite) - Third-party connectivity (e.g., telecom providers, hardware support)

    Domain 5: Identity and Access Management (IAM)

    Subdomain 5.1: Control physical and logical access to assets

    - Information - Systems - Devices - Facilities - Applications - Services

    Subdomain 5.2: Design identification and authentication strategy (e.g., people, devices, and services)

    - Groups and Roles - Authentication, Authorization and Accounting (AAA) (e.g., multi-factor authentication (MFA), password-less authentication) - Session management - Registration, proofing, and establishment of identity - Credential management systems (e.g., Password vault) - Single sign-on (SSO) - Just-In-Time

    Subdomain 5.3: Federated identity with a third-party service

    - Federated Identity Management (FIM)

    Subdomain 5.4: Implement and manage authorization mechanisms

    - Role-based access control (RBAC) - Rule-based access control - Mandatory access control (MAC) - Discretionary access control (DAC) - Attribute-based access control (ABAC) - Risk-based access control - Access policy enforcement (e.g., policy decision point, policy enforcement point)

    Subdomain 5.5: Manage the identity and access provisioning lifecycle

    - Account access review (e.g., user, system, service) - Provisioning and deprovisioning (e.g., on /off boarding and transfers) - Service accounts management - Role definition and transition (e.g., people assigned to new roles) - Privilege escalation (e.g., use of sudo, auditing its use)

    Subdomain 5.6: Implement authentication systems

    - On-premises - Cloud - Hybrid

    Domain 6: Security Assessment and Testing

    Subdomain 6.1: Design and validate assessment, test, and audit strategies

    Design and validate assessment, test, and audit strategies

    Subdomain 6.2: Conduct security control testing

    - Vulnerability assessment - Penetration testing (e.g., red, blue

    Techniques & products

    ISC2 Code of Professional Ethics
    Organizational code of ethics
    Confidentiality, integrity, and availability (CIA)
    Authenticity
    Nonrepudiation
    Security governance principles
    Legal, regulatory, and compliance issues
    Cybercrimes
    Data breaches
    Licensing and Intellectual Property
    Import/export controls
    Transborder data flow
    GDPR
    CCPA
    PIPL
    POPIA
    Administrative investigations
    Criminal investigations
    Civil investigations
    Regulatory investigations
    Industry standards investigations
    Security policy
    Security standards
    Security procedures
    Security guidelines
    Business Continuity (BC)
    Business impact analysis (BIA)
    External dependencies
    ISO
    NIST
    COBIT
    SABSA
    PCI
    FedRAMP
    Due care/due diligence
    Personnel security policies
    Candidate screening
    Hiring processes
    Employment agreements
    Onboarding
    Transfers
    Termination processes
    Vendor agreements
    Consultant agreements
    Contractor agreements
    Risk management concepts
    Threat identification
    Vulnerability identification
    Risk analysis
    Risk assessment
    Risk scope
    Risk response
    Risk treatment
    Cybersecurity insurance
    Preventive controls
    Detection controls
    Corrective controls
    Control assessments
    Security assessments
    Privacy assessments
    Continuous monitoring
    Continuous measurement
    Risk maturity modeling
    Threat modeling concepts
    Threat modeling methodologies
    Supply Chain Risk Management (SCRM)
    Product tampering
    Counterfeits
    Implants
    Third-party assessment
    Third-party monitoring
    Minimum security requirements
    Service Level Agreements (SLA)
    Silicon root of trust
    Physically unclonable function
    Software bill of materials
    Security awareness programs
    Security education programs
    Security training programs
    Social engineering
    Phishing
    Security champions
    Gamification
    Cryptocurrency
    Artificial Intelligence (AI)
    Blockchain
    Information ownership
    Asset ownership
    Asset inventory
    Asset management
    Data classification
    Asset Classification
    Data roles (owners, controllers, custodians, processors, users/subjects)
    Data collection
    Data location
    Data maintenance
    Data retention
    Data remanence
    Data destruction
    Data states (in use, in transit, at rest)
    Secure provisioning
    Data lifecycle management
    Asset retention (EOL, End of Support)
    Scoping and tailoring
    Standards selection
    Digital Rights Management (DRM)
    Data Loss Prevention (DLP)
    Cloud Access Security Broker (CASB)
    Secure design principles
    Least privilege
    Defense in depth
    Secure defaults
    Fail securely
    Segregation of Duties (SoD)
    Keep it simple and small
    Zero trust
    Trust but verify
    Privacy by design
    Shared responsibility
    Secure access service edge
    Biba security model
    Star Model
    Bell-LaPadula security model
    System security requirements
    Memory protection
    Trusted Platform Module (TPM)
    Encryption/decryption
    Client-based systems
    Server-based systems
    Database systems
    Cryptographic systems
    Industrial Control Systems (ICS)
    Cloud-based systems (SaaS, IaaS, PaaS)
    Distributed systems
    Internet of Things (IoT)
    Microservices (API)
    Containerization
    Serverless
    Embedded systems
    High-Performance Computing systems
    Edge computing systems
    Virtualized systems
    Cryptographic life cycle
    Key management
    Algorithm selection
    Symmetric cryptography
    Asymmetric cryptography
    Elliptic curves cryptography
    Quantum cryptography
    Public Key Infrastructure (PKI)
    Quantum key distribution
    Key rotation
    Digital signatures
    Digital certificates
    Non-repudiation
    Integrity
    Brute force attack
    Ciphertext only attack
    Known plaintext attack
    Frequency analysis attack
    Chosen ciphertext attack
    Implementation attacks
    Side-channel attacks
    Fault injection attacks
    Timing attacks
    Man-in-the-Middle (MITM) attack
    Pass the hash attack
    Kerberos exploitation
    Ransomware
    Site security principles
    Facility design security
    Wiring closets security
    Intermediate distribution facilities security
    Server rooms security
    Data centers security
    Media storage facilities security
    Evidence storage security
    Restricted area security
    Work area security
    Utilities security
    HVAC security
    Environmental issues management
    Fire prevention
    Fire detection
    Fire suppression
    Redundant power
    Backup power
    Information system lifecycle
    Requirements analysis
    Architectural design
    Development /implementation
    Integration
    Verification and validation
    Transition/deployment
    Operations and maintenance/sustainment
    Retirement/disposal
    OSI model
    TCP/IP model
    IPv4
    IPv6
    IPSec
    SSH
    SSL/TLS
    Multilayer protocols
    Converged protocols (iSCSI, VoIP, InfiniBand over Ethernet, CXL)
    Transport architecture
    Network topology
    Data plane
    Control plane
    Management plane
    Cut-through switching
    Store-and-forward switching
    Bandwidth
    Latency
    Jitter
    Throughput
    Signal-to-noise ratio (SNR)
    North-south traffic flow
    East-west traffic flow
    Physical segmentation
    In-band management
    Out-of-band management
    Air-gapped networks
    Logical segmentation
    Virtual Local Area Networks (VLANs)
    Virtual Private Networks (VPNs)
    Virtual routing and forwarding
    Virtual domain
    Micro-segmentation
    Network overlays
    Encapsulation
    Distributed firewalls
    Distributed routers
    Intrusion Detection System (IDS)
    Intrusion Prevention System (IPS)
    Edge networks
    Ingress/egress points
    Network peering
    Wireless networks (Bluetooth, Wi-Fi, Zigbee, satellite)
    Cellular/mobile networks (4G, 5G)
    Content Distribution Networks (CDN)
    Software Defined Networks (SDN)
    Software-Defined Wide-Area Network (SD-WAN)
    Network Functions Virtualization (NFV)
    Virtual Private Cloud (VPC)
    Network observability
    Traffic flow management
    Traffic shaping
    Capacity management
    Fault detection
    Fault handling
    Redundant power (network)
    Transmission media physical security
    Signal propagation quality
    Network Access Control (NAC) systems
    Endpoint security
    Host-based security
    Voice security
    Video security
    Collaboration security
    Remote access security
    Data communications security
    Backhaul networks
    Satellite communications security
    Third-party connectivity security
    Physical access control
    Logical access control
    Identification strategy
    Authentication strategy
    Groups and Roles
    Authentication, Authorization and Accounting (AAA)
    Multi-factor authentication (MFA)
    Password-less authentication
    Session management
    Identity registration
    Identity proofing
    Identity establishment
    Federated Identity Management (FIM)
    Credential management systems
    Password vault
    Single Sign-On (SSO)
    Just-In-Time access
    Authorization mechanisms
    Role-based access control (RBAC)
    Rule-based access control
    Mandatory access control (MAC)
    Discretionary access control (DAC)
    Attribute-based access control (ABAC)
    Risk-based access control
    Access policy enforcement
    Policy decision point
    Policy enforcement point
    Identity and access provisioning lifecycle
    Account access review
    Provisioning
    Deprovisioning
    Onboarding
    Offboarding
    Service accounts management
    Role definition
    Role transition
    Privilege escalation
    Sudo auditing
    On-premises authentication systems
    Cloud authentication systems
    Hybrid authentication systems
    Assessment strategies
    Test strategies
    Audit strategies
    Security control testing
    Vulnerability assessment
    Penetration testing (red team, blue team, purple team)
    Log reviews
    Synthetic transactions
    Benchmarks
    Code review
    Code testing
    Misuse case testing
    Coverage analysis
    Interface testing (UI, network, API)
    Breach attack simulations
    Compliance checks
    Internal audits
    External audits
    Third-party audits
    Security process data collection
    Technical data collection
    Administrative data collection
    Test output analysis
    Report generation
    Remediation
    Exception handling
    Ethical disclosure
    Account management (audits)
    Management review and approval (audits)
    Key performance indicators (KPI)
    Key risk indicators (KRI)
    Backup verification data
    Training and awareness (audits)
    Disaster Recovery (DR) audits
    Business Continuity (BC) audits
    Investigations
    Evidence collection
    Evidence handling
    Reporting (investigations)
    Documentation (investigations)
    Investigative techniques
    Digital forensics tools
    Digital forensics tactics
    Digital forensics procedures
    Artifacts (data, computer, network, mobile device)
    Logging activities
    Monitoring activities
    Media management
    Media protection techniques
    Data at rest monitoring
    Data in transit monitoring
    Intrusion Detection and Prevention Systems (IDPS)
    Security Information and Event Management (SIEM)
    Continuous monitoring and tuning
    Egress monitoring
    Log management
    Threat intelligence
    Threat feeds
    Threat hunting
    User and Entity Behavior Analytics (UEBA)
    Configuration Management (CM)
    Configuration provisioning
    Configuration baselining
    Configuration automation
    Need-to-know principle
    Least privilege principle
    Segregation of Duties (SoD)
    Privileged account management
    Job rotation
    Service-level agreements (SLA)
    Resource protection
    Incident management
    Incident detection
    Incident response
    Incident mitigation
    Incident reporting
    Incident recovery
    Incident remediation
    Lessons learned (incident management)
    Firewalls (next generation, web application, network)
    Intrusion detection systems (IDS)
    Intrusion prevention systems (IPS)
    Whitelisting
    Blacklisting
    Third-party security services
    Sandboxing
    Honeypots
    Honeynets
    Anti-malware
    Machine learning-based tools
    AI-based tools
    Patch management
    Vulnerability management
    Change management processes
    Recovery strategies
    Backup storage strategies (cloud, onsite, offsite)
    Recovery site strategies (cold vs. hot)
    Resource capacity agreements
    Multiple processing sites
    System resilience
    High Availability (HA)
    Quality of Service (QoS)
    Fault tolerance
    Disaster Recovery (DR) processes
    DR response
    DR personnel
    DR communications
    DR assessment
    DR restoration
    DR training and awareness
    DR lessons learned
    DRP read-through
    DRP tabletop exercise
    DRP walkthrough
    DRP simulation
    DRP parallel test
    DRP full interruption test
    DRP communications
    Business Continuity (BC) planning
    BC exercises
    Physical security
    Perimeter security controls
    Internal security controls
    Travel security
    Security training and awareness (personnel)
    Insider threat awareness
    Social media impacts awareness
    Two-factor authentication (2FA) fatigue awareness
    Emergency management
    Duress procedures
    Software Development Life Cycle (SDLC) security
    Agile methodology
    Waterfall methodology
    DevOps
    DevSecOps
    Scaled Agile Framework (SAFe)
    Capability Maturity Model (CMM)
    Software Assurance Maturity Model (SAMM)
    SDLC operation and maintenance
    SDLC change management
    Integrated Product Team
    Software development ecosystem security controls
    Source-code security weaknesses
    Source-code vulnerabilities
    API security
    Secure coding practices
    Software-defined security
    Programming languages security
    Libraries security
    Tool sets security
    Integrated Development Environment (IDE) security
    Runtime security
    Continuous Integration (CI)
    Continuous Delivery (CD)
    Software Configuration Management (CM)
    Code repositories security
    Software security effectiveness assessment
    Application security testing (SAST, DAST, SCA, IAST)
    Auditing of changes (software)
    Logging of changes (software)
    Risk analysis (software)
    Risk mitigation (software)
    Acquired software security impact
    Commercial-off-the-shelf (COTS) software
    Open source software
    Third-party software
    Managed services (enterprise applications)
    Cloud services (SaaS, IaaS, PaaS)
    Secure coding guidelines
    Secure coding standards

    CertSafari is not affiliated with, endorsed by, or officially connected to Isc2. Full disclaimer