ISC2 CISSP: the honest guide
Everything ISC2 publishes about CISSP, in one place: what the exam asks, how the domains are weighted, and what it takes to be ready.
This guide page is built from the registry, not written yet.
Everything below comes from CISSP’s published exam data, and every figure links to the vendor page it came from. The researched version, with study plans and the parts nobody publishes, is still being written. This page is not submitted to search engines until it is.
Practise CISSP questions in the meantimeWhat the exam actually asks you to do
Multiple choice plus advanced innovative items: drag-and-drop and hotspot questions where you place items or click a point on a diagram.
- Multiple choice
- Drag and drop
- Hotspot
The highlighted formats are the ones you cannot answer from memory alone. ISC2, CISSP exam outline ↗
Domain breakdown and official weightings
From the official ISC2 exam outlines. Security and Risk Management is the heaviest domain at 16 percent, followed by Security Architecture and Engineering at 13 percent.
- Security and Risk Management16%
- Asset Security10%
- Security Architecture and Engineering13%
- Communication and Network Security13%
- Identity and Access Management (IAM)13%
- Security Assessment and Testing12%
- Security Operations13%
- Software Development Security10%
What comes after passing
CISSP runs on a three-year cycle needing 120 CPE credits, at least 40 per year, plus the annual maintenance fee each year.
Costs across the full renewal cycle are on the CISSP cost page.
Frequently asked questions
How does CISSP CAT scoring work?
The adaptive engine serves 100-150 questions over 3 hours and continuously estimates your ability per domain; the exam ends early once it's statistically confident you're above (or below) the passing standard of 700/1000.
What experience do I need for CISSP?
Five years of cumulative paid work in at least two of the eight domains (one year waivable with a degree or approved cert). Pass without the experience and you become an Associate of ISC2 until you accrue it.
Why do people say 'think like a manager' for CISSP?
CISSP rewards risk-based, business-aligned answers over hands-on technical fixes. When two answers are both technically true, the one addressing process, policy, or human safety first usually wins. Our explanations flag this pattern explicitly.
Keep reading
CISSP practice questions
Free sample questions with the full explanation on every answer.
CISSP vs Security+
Side by side on cost, difficulty, and which one to take first.
Practise CISSP for free while you decide
Original questions written from the published objectives, with the concept, the reasoning, and a note on every wrong option. No account needed to start.
Start free CISSP questions