CredenTrek
Library / CISSP / Guide 04 of 8
CISSP · Exam format and domains

125 to 150 items, three hours, eight domains: the CISSP exam in plain English

By Mustafa K. Al-Dori · Edition 2026.2, verified 9 October 2026 · 8 min read

The short answer

CISSP is computerised adaptive testing in every language: 125 to 150 items, a maximum of three hours, and 700 out of 1,000 to pass. Items are multiple choice or advanced innovative items such as drag and drop and hotspot. There are eight domains and 62 objectives, led by Security and Risk Management at 16 per cent. Answer as an adviser to the business: protect people, follow policy and law, and fix risk at its source.

Strong technical specialists treat CISSP as a harder technical exam, and meet questions about balancing risk, cost and business goals. The exam rewards a manager's first move, not an engineer's best fix.

How does the format work?

Item Detail
Delivery Computerised adaptive testing in all languages
Items 125 to 150
Time A maximum of three hours
Pass mark 700 out of 1,000
Languages Chinese, English, German, Japanese and Spanish
Item types Multiple choice and advanced innovative items

Each answer shapes the next question. The exam ends once the system has enough evidence, after at most 150 items and three hours, and that can come before the maximum. Finishing early says nothing about whether you passed.

Items are multiple choice, with four options, or advanced innovative items, such as drag and drop or hotspot questions. Scenarios appear in both. A short situation is described, and you choose the best, first or most important action.

How should you read a question?

Read each question for its key word: best, first, most or least. Then think as an adviser to senior management. Protect people first, follow policy and law, and choose the answer that addresses risk at its source rather than a technical quick fix.

Faisal, in the book, had led firewall projects for eight years. When he started studying he answered practice questions as an engineer and scored poorly. Once he asked "what would the business need first?", his scores rose and he passed four months later.

A few habits help:

  • If two answers are both correct actions, ask which comes first in the incident or project lifecycle.
  • If an answer is purely technical and ignores policy, ownership or approval, it is rarely the best.
  • The most extreme option, such as wiping, firing or ignoring, is rarely the best.
  • When in doubt, ask who is accountable and who should decide.

What are the eight domains?

Domain Weight Objectives What it asks of you
1 Security and Risk Management 16% 12 Ethics, governance, law, investigations, policy, continuity, personnel, risk, threat modelling, supply chain, awareness
2 Asset Security 10% 6 Classification, handling, ownership, lifecycle, retention, data controls
3 Security Architecture and Engineering 13% 10 Design principles, models, cryptography, facilities
4 Communication and Network Security 13% 3 Secure network architecture, components and channels
5 Identity and Access Management 13% 6 Access, authentication, federation, authorisation, provisioning
6 Security Assessment and Testing 12% 5 Test strategies, scans, reporting, audits
7 Security Operations 13% 15 Investigations, monitoring, incidents, recovery, physical and personnel safety
8 Software Development Security 10% 5 Development lifecycle, tools, acquired software, coding standards

Total objectives: 62. Domain 7 has the longest list, and Domain 4 has the shortest, but each of its three objectives covers many topics.

Where do candidates lose marks?

Weak areas, mostly. Technical specialists neglect legal and regulatory issues (1.4), recovery testing (7.12) and the data lifecycle. Managers neglect cryptography and network detail. Everyone neglects the topics that feel like paperwork, which is where the exam asks you to show judgement.

Hani, in the book, rated himself on all 62 objectives. He gave himself 2 out of 5 on 1.4 (legal and regulatory issues) and 7.12 (testing recovery plans), so he gave them extra time. Several scenario questions on his exam turned on both.

What should you do with this map?

Split your hours in proportion to the weights, then move hours towards your lowest-rated objectives. Download the current exam outline from isc2.org and check its effective date, 15 April 2024, and the weights before you buy study material.

The study hours guide shows a worked split for 200 hours. Ten scenario questions let you practise the manager's mindset. Chapter 5 of CredenTrek For CISSP lists every objective with what it means in practice.

Your next step
  1. Download the current exam outline from isc2.org and note its effective date.
  2. Rate yourself from 1 to 5 on each of the 62 objectives.
  3. Read five practice questions and underline the key word in each: best, first, most or least.
  4. Choose your three lowest-rated objectives as the first targets in your plan.

Questions readers ask

How many questions are on the CISSP exam?
The exam has 125 to 150 items, with a maximum of three hours. Because it is adaptive, it ends once the system is confident of your result, which can come before the maximum.
What score do I need to pass CISSP?
700 out of 1,000.
Can I go back and change answers?
Read the Candidate Information Bulletin for what the adaptive exam allows. Answer each question with care before you move on.
Which languages are available?
Chinese, English, German, Japanese and Spanish. Computerised adaptive testing now applies in all of them.
Sources

This guide is independent and is not endorsed by ISC2. Facts change: confirm them on the official page before you act.