125 to 150 items, three hours, eight domains: the CISSP exam in plain English
CISSP is computerised adaptive testing in every language: 125 to 150 items, a maximum of three hours, and 700 out of 1,000 to pass. Items are multiple choice or advanced innovative items such as drag and drop and hotspot. There are eight domains and 62 objectives, led by Security and Risk Management at 16 per cent. Answer as an adviser to the business: protect people, follow policy and law, and fix risk at its source.
Strong technical specialists treat CISSP as a harder technical exam, and meet questions about balancing risk, cost and business goals. The exam rewards a manager's first move, not an engineer's best fix.
How does the format work?
| Item | Detail |
|---|---|
| Delivery | Computerised adaptive testing in all languages |
| Items | 125 to 150 |
| Time | A maximum of three hours |
| Pass mark | 700 out of 1,000 |
| Languages | Chinese, English, German, Japanese and Spanish |
| Item types | Multiple choice and advanced innovative items |
Each answer shapes the next question. The exam ends once the system has enough evidence, after at most 150 items and three hours, and that can come before the maximum. Finishing early says nothing about whether you passed.
Items are multiple choice, with four options, or advanced innovative items, such as drag and drop or hotspot questions. Scenarios appear in both. A short situation is described, and you choose the best, first or most important action.
How should you read a question?
Read each question for its key word: best, first, most or least. Then think as an adviser to senior management. Protect people first, follow policy and law, and choose the answer that addresses risk at its source rather than a technical quick fix.
Faisal, in the book, had led firewall projects for eight years. When he started studying he answered practice questions as an engineer and scored poorly. Once he asked "what would the business need first?", his scores rose and he passed four months later.
A few habits help:
- If two answers are both correct actions, ask which comes first in the incident or project lifecycle.
- If an answer is purely technical and ignores policy, ownership or approval, it is rarely the best.
- The most extreme option, such as wiping, firing or ignoring, is rarely the best.
- When in doubt, ask who is accountable and who should decide.
What are the eight domains?
| Domain | Weight | Objectives | What it asks of you |
|---|---|---|---|
| 1 Security and Risk Management | 16% | 12 | Ethics, governance, law, investigations, policy, continuity, personnel, risk, threat modelling, supply chain, awareness |
| 2 Asset Security | 10% | 6 | Classification, handling, ownership, lifecycle, retention, data controls |
| 3 Security Architecture and Engineering | 13% | 10 | Design principles, models, cryptography, facilities |
| 4 Communication and Network Security | 13% | 3 | Secure network architecture, components and channels |
| 5 Identity and Access Management | 13% | 6 | Access, authentication, federation, authorisation, provisioning |
| 6 Security Assessment and Testing | 12% | 5 | Test strategies, scans, reporting, audits |
| 7 Security Operations | 13% | 15 | Investigations, monitoring, incidents, recovery, physical and personnel safety |
| 8 Software Development Security | 10% | 5 | Development lifecycle, tools, acquired software, coding standards |
Total objectives: 62. Domain 7 has the longest list, and Domain 4 has the shortest, but each of its three objectives covers many topics.
Where do candidates lose marks?
Weak areas, mostly. Technical specialists neglect legal and regulatory issues (1.4), recovery testing (7.12) and the data lifecycle. Managers neglect cryptography and network detail. Everyone neglects the topics that feel like paperwork, which is where the exam asks you to show judgement.
Hani, in the book, rated himself on all 62 objectives. He gave himself 2 out of 5 on 1.4 (legal and regulatory issues) and 7.12 (testing recovery plans), so he gave them extra time. Several scenario questions on his exam turned on both.
What should you do with this map?
Split your hours in proportion to the weights, then move hours towards your lowest-rated objectives. Download the current exam outline from isc2.org and check its effective date, 15 April 2024, and the weights before you buy study material.
The study hours guide shows a worked split for 200 hours. Ten scenario questions let you practise the manager's mindset. Chapter 5 of CredenTrek For CISSP lists every objective with what it means in practice.
- Download the current exam outline from isc2.org and note its effective date.
- Rate yourself from 1 to 5 on each of the 62 objectives.
- Read five practice questions and underline the key word in each: best, first, most or least.
- Choose your three lowest-rated objectives as the first targets in your plan.
Questions readers ask
How many questions are on the CISSP exam?
What score do I need to pass CISSP?
Can I go back and change answers?
Which languages are available?
- ISC2 CISSP certification page
- ISC2 CISSP exam outline, effective 15 April 2024
- ISC2 Candidate Information Bulletin
This guide is independent and is not endorsed by ISC2. Facts change: confirm them on the official page before you act.