ISC2 CISSP practice questions
Original questions written from the published exam objectives, never recalled exam content, with an explanation that teaches the concept behind every answer. Why that matters.
- Exam code
- CISSP
- Cost
- $749 USD
- Questions
- 100-150 (computerized adaptive)
- Duration
- 180 minutes
- Passing score
- 700 (scale 1000)
- Format
- Computerized adaptive testing (CAT), multiple choice and advanced items
The CISSP exam costs $749. Fail it and the retake is another $749. Practicing until you are ready is the cheapest part of this.
Exam domains and official weightings
From the official ISC2 exam outlines. Put your study time where the weight is.
- Security and Risk Management16%
- Asset Security10%
- Security Architecture and Engineering13%
- Communication and Network Security13%
- Identity and Access Management (IAM)13%
- Security Assessment and Testing12%
- Security Operations13%
- Software Development Security10%
- Security and Risk Management16%
- Asset Security10%
- Security Architecture and Engineering13%
- Communication and Network Security13%
- Identity and Access Management (IAM)13%
- Security Assessment and Testing12%
- Security Operations13%
- Software Development Security10%
Try 5 free sample questions
No account needed. Every question includes our three-tier explanation: the concept, why the answer follows, and why each wrong option is wrong.
Sample question 1 of 5
A security manager finds that mitigating a low-likelihood risk would cost four times the expected annual loss. Leadership documents the decision to take no action and revisit annually. Which risk response has been chosen, and is it appropriate?
Sample question 2 of 5
An audit reveals database administrators can both approve and implement their own production changes. Which principle is violated, and what is the primary fix?
Sample question 3 of 5
A system needs to provide non-repudiation for signed contracts, the signer must be unable to plausibly deny signing. Which cryptographic approach delivers this?
Sample question 4 of 5
During a confirmed breach of a customer database, the incident commander's FIRST priority conflict arises: legal wants systems preserved for evidence, operations wants immediate rebuild. What should guide the decision?
Sample question 5 of 5
A company keeps finding exploitable flaws in production releases despite penetration testing before each launch. What is the most effective structural change?
Full CISSP question bank coming
We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.
An honest study plan
1. Read the official objectives first
Download the official objectives from ISC2 and skim every line. The exam can only test what’s listed there, it’s the contract.
2. Weight your study toward Security and Risk Management and Security Architecture and Engineering
Together the top two domains are 29% of the exam. Practice them until your accuracy is consistently above 80%.
3. Drill weak domains, then take a mock exam
Use Domain Drill on your weakest areas, then a full timed mock at real length (100-150 (computerized adaptive) questions, 180 minutes). Book the real exam when you’re consistently passing mocks, not before.
Official free resources
Study from the source. These are ISC2’s own materials:
Official CISSP exam page & objectives ↗Where CISSP fits
Related certifications
Frequently asked questions
How does CISSP CAT scoring work?
The adaptive engine serves 100-150 questions over 3 hours and continuously estimates your ability per domain; the exam ends early once it's statistically confident you're above (or below) the passing standard of 700/1000.
What experience do I need for CISSP?
Five years of cumulative paid work in at least two of the eight domains (one year waivable with a degree or approved cert). Pass without the experience and you become an Associate of ISC2 until you accrue it.
Why do people say 'think like a manager' for CISSP?
CISSP rewards risk-based, business-aligned answers over hands-on technical fixes. When two answers are both technically true, the one addressing process, policy, or human safety first usually wins. Our explanations flag this pattern explicitly.
Ready to practice for CISSP?
Play the free samples now. The full question bank is in progress, and you can join the waitlist on any sample question.