Free Practice Questions for ISC2 Certified Information Systems Security Professional (CISSP) Certification
- Exam guide version:
- April 15, 2024
- Guide checked for updates:
- 10 Sep 2026
- Question bank created:
- 15 Jun 2026
- Question bank last updated:
- 11 Aug 2026
Study with 297 exam-style practice questions designed to help you prepare for the ISC2 Certified Information Systems Security Professional (CISSP). All questions are aligned with the latest exam guide and include detailed explanations to help you master the material.
Exam experiencesNew
Pass and fail outcomes from candidates who prepared here — advice, scores, and prep time.
Start Practicing
All Domains
Practice with randomly mixed questions from all topics
Domain Mode
Practice questions from a specific topic area
Quiz History
Exam Details
Key information about ISC2 Certified Information Systems Security Professional (CISSP)
- Multiple choice
- Ordering
- Matching
Chinese, English, German, Japanese, Spanish
Multiple choice and advanced innovative items, Computerized Adaptive Testing (CAT)
700 out of 1000 points
Minimum five years cumulative, full-time experience in two or more of the eight domains of the CISSP Exam Outline. A post-secondary degree or additional ISC2 credential may satisfy up to one year of experience. Part-time work and internships may also count. Candidates without full experience can become an Associate of ISC2 by passing the exam and have six years to earn the required experience.
180 minutes
100 - 150
Exam Topics & Skills Assessed
Skills measured (from the official study guide)
Domain 1: Security and Risk Management
Subdomain 1.1: Understand, adhere to, and promote professional ethics
Subdomain 1.2: Understand and apply security concepts
Subdomain 1.3: Evaluate and apply security governance principles
Subdomain 1.4: Understand legal, regulatory, and compliance issues that pertain to information security in a holistic context
Subdomain 1.5: Understand requirements for investigation types (i.e., administrative, criminal, civil, regulatory, industry standards)
Subdomain 1.6: Develop, document, and implement security policy, standards, procedures, and guidelines
Subdomain 1.7: Identify, analyze, assess, prioritize, and implement Business Continuity (BC) requirements
Subdomain 1.8: Contribute to and enforce personnel security policies and procedures
Subdomain 1.9: Understand and apply risk management concepts
Subdomain 1.10: Understand and apply threat modeling concepts and methodologies
Subdomain 1.11: Apply supply chain risk management (SCRM) concepts
Subdomain 1.12: Establish and maintain a security awareness, education, and training program
Domain 2: Asset Security
Subdomain 2.1: Identify and classify information and assets
Subdomain 2.2: Establish information and asset handling requirements
Subdomain 2.3: Provision information and assets securely
Subdomain 2.4: Manage data lifecycle
Subdomain 2.5: Ensure appropriate asset retention (e.g., End of Life (EOL), End of Support)
Subdomain 2.6: Determine data security controls and compliance requirements
Domain 3: Security Architecture and Engineering
Subdomain 3.1: Research, implement and manage engineering processes using secure design principles
Subdomain 3.2: Understand the fundamental concepts of security models (e.g., Biba, Star Model, Bell-LaPadula)
Subdomain 3.3: Select controls based upon systems security requirements
Subdomain 3.4: Understand security capabilities of Information Systems (IS) (e.g., memory protection, Trusted Platform Module (TPM), encryption/decryption)
Subdomain 3.5: Assess and mitigate the vulnerabilities of security architectures, designs, and solution elements
Subdomain 3.6: Select and determine cryptographic solutions
Subdomain 3.7: Understand methods of cryptanalytic attacks
Subdomain 3.8: Apply security principles to site and facility design
Subdomain 3.9: Design site and facility security controls
Subdomain 3.10: Manage the information system lifecycle
Domain 4: Communication and Network Security
Subdomain 4.1: Apply secure design principles in network architectures
Subdomain 4.2: Secure network components
Subdomain 4.3: Implement secure communication channels according to design
Domain 5: Identity and Access Management (IAM)
Subdomain 5.1: Control physical and logical access to assets
Subdomain 5.2: Design identification and authentication strategy (e.g., people, devices, and services)
Subdomain 5.3: Federated identity with a third-party service
Subdomain 5.4: Implement and manage authorization mechanisms
Subdomain 5.5: Manage the identity and access provisioning lifecycle
Subdomain 5.6: Implement authentication systems
Domain 6: Security Assessment and Testing
Subdomain 6.1: Design and validate assessment, test, and audit strategies
Subdomain 6.2: Conduct security control testing
Subdomain 6.3: Collect security process data (e.g., technical and administrative)
Subdomain 6.4: Analyze test output and generate report
Subdomain 6.5: Conduct or facilitate security audits
Domain 7: Security Operations
Subdomain 7.1: Understand and comply with investigations
Subdomain 7.2: Conduct logging and monitoring activities
Subdomain 7.3: Perform configuration management (CM) (e.g., provisioning, baselining, automation)
Subdomain 7.4: Apply foundational security operations concepts
Subdomain 7.5: Apply resource protection
Subdomain 7.6: Conduct incident management
Subdomain 7.7: Operate and maintain detection and preventative measures
Subdomain 7.8: Implement and support patch and vulnerability management
Subdomain 7.9: Understand and participate in change management processes
Subdomain 7.10: Implement recovery strategies
Subdomain 7.11: Implement disaster recovery (DR) processes
Subdomain 7.12: Test disaster recovery plans (DRP)
Subdomain 7.13: Participate in Business Continuity (BC) planning and exercises
Subdomain 7.14: Implement and manage physical security
Subdomain 7.15: Address personnel safety and security concerns
Domain 8: Software Development Security
Subdomain 8.1: Understand and integrate security in the Software Development Life Cycle (SDLC)
Subdomain 8.2: Identify and apply security controls in software development ecosystems
Subdomain 8.3: Assess the effectiveness of software security
Subdomain 8.4: Assess security impact of acquired software
Subdomain 8.5: Define and apply secure coding guidelines and standards
Techniques & products