Doc CC-00Rev 2026-10Class study materialRead ~6 min
Free CISSP exam prep: practice questions, the 8 domains, and a study plan
Good CISSP exam prep is mostly scenario practice with the reasoning read in full, spread across all eight domains in proportion to their weight. This site does that for the ISC2 CISSP (Certified Information Systems Security Professional) exam: a 60-item practice test, a domain-by-domain study guide, and a study plan that assumes you also have a job.
Exam readout
- Format
- CAT, every language
- Items
- 100–150
- Time
- 3 hours
- Pass mark
- 700 / 1000 scaled
- Outline
- 8 domains · Apr 2024
What is on the board
Everything here is free to use in the browser. Four entry points, depending on how much you already know.
Practice test
60 items
Drill by domain, Weak-spot, or Timed 60 on a 72:00 clock. Open the test.
Domain guides
2 of 8
Domain 1 and Domain 3 are written; the rest are in preparation.
Rationales
Every option
Right or wrong, each answer choice carries a note on why.
Before you book
3 briefs
Eight questions, one per domain
One original practice item from each domain, untimed, with the reasoning for all four options once you answer. Treat it as a temperature check: the console does not reproduce CAT scoring and does not forecast a result.
Sampler
Item 01 / 08
One item per CISSP domain. Keys 1–4 pick, N goes next.
A Chief Information Security Officer is reviewing multiple attack paths identified during a recent threat modeling exercise. To optimize the security budget, which criteria should be the PRIMARY driver for prioritizing control implementation and detection engineering?
Rationale
Pick an answer. The reasoning for every option lands here — including why the wrong ones looked right.
Domain board · correct / seen
- D1–
- D2–
- D3–
- D4–
- D5–
- D6–
- D7–
- D8–
Field kit
Eight was the sampler
The CISSP prep app carries a much larger question bank than this site, on iPhone and Android. The 60-item test stays free here either way.
What CISSP is, in two paragraphs
CISSP is a vendor-neutral credential for people who design, run or answer for a security program: architects, security managers, senior engineers, consultants. Its eight domains run from risk and law to software development, so it rewards breadth over any one specialty, and it assumes you can talk to management as well as to servers.
It is a professional certification, not a license. It is accredited by ANAB to ISO/IEC 17024 and appears among the credentials approved under the U.S. DoD manual 8140.03, which is recognition rather than a mandate. Whether it fits your career is covered on CISSP certification; whether your work history counts, on CISSP requirements. Weighing it against ISACA’s governance-focused CISM? See CISSP vs CISM.
The 8 domains, weighted
Shares from the current outline, effective April 2024; only Domain 1 and Domain 8 moved, by one point each.
D1Security and Risk Management
16%
D2Asset Security
10%
D3Security Architecture and Engineering
13%
D4Communication and Network Security
13%
D5Identity and Access Management
13%
D6Security Assessment and Testing
12%
D7Security Operations
13%
D8Software Development Security
10%
Share of the CISSP exam by domain, ISC2 outline effective April 2024
Reading the weights
Security and Risk Management is the heaviest domain at 16%, and it sets the tone for the other seven: a question filed under operations or networking still tends to want a risk-and-governance answer. Asset Security and Software Development Security are the lightest at 10% each. The remaining five sit at 12–13%.
That spread is flatter than it first looks. No domain is small enough to skip, the exam draws items from all eight in line with these shares, and there is no going back to repair an earlier answer once you have moved on.
Domain depth lives on the study guide, which starts with Domain 1 and Domain 3, the domain of security models, cryptography and fire suppression, where Bell-LaPadula and Biba wait patiently to be confused with each other.
From exam seat to credential
Passing is one stage out of four. The other three are administrative, which counts as good news after months of studying.
Step 01
Sit the adaptive exam
At a Pearson VUE test center; there is no at-home option. Length, timing and retakes are on the CISSP exam; current pricing is on isc2.org.
Step 02
Show the experience
Five years of cumulative work in at least two of the eight domains. A relevant degree or one approved credential waives a single year, and only one. The fine print is on CISSP requirements.
Step 03
Get endorsed within 9 months
An ISC2-certified professional in good standing vouches for your experience, or ISC2 reviews it directly if nobody in your network holds a credential.
Step 04
Keep it in good standing
120 CPE credits per three-year cycle, at least 90 of them Group A, plus an annual maintenance fee.
How to prepare without guessing
The best CISSP prep is a loop, not a reading marathon: answer a scenario, read why every option is right or wrong, log the miss by domain, repeat. Read the outline once early so you know the shape of the eight domains. Rereading the same chapter a third time mostly trains your eyes to skim.
Plan in hours, not weekends. A reasonable starting assumption for someone already working in security is 8 to 12 weeks at about 10 hours a week, plus extra for each domain that is new territory. The study plan splits the weeks by domain weight, so Domain 1 gets its 16% and subnet arithmetic does not quietly eat two weeks.
Measure with mixed sets. The exam does not group items by domain, so once each domain has had its turn, set Drill to all domains or run Timed 60: 60 items, 72:00 on the clock, no going back, feedback at the end. It copies the pacing, not the scoring.
One prep week, start to finish
- Pick the weakest domain from last week’s miss log.
- Read its guide or outline section once, then stop reading.
- Work its practice items and spend longer on the rationales than on the questions.
- Close with a mixed set to check the other seven did not slip.
- Write every miss down with its domain number.
Most options on a CISSP item are defensible. The job is to pick the one a risk owner would sign.
House rule
Questions people ask first
Q01What is the best way to prepare for the CISSP exam?
Let practice lead and the weights decide the order. Start with the sampler above or the practice test to find your weakest domain, study that one first, and read the rationale for every option, including the ones you got right. Mixed timed sets come last, once each domain has had a pass.
Q02Where should I start if I am new to the CISSP?
With eligibility, not with chapter one. Check the five-year experience rule and the Associate route on CISSP requirements, read how the adaptive exam behaves on the exam page, then take the sampler above to pick a first domain.
Q03Does the sampler predict my CISSP score?
No. Eight items, one per domain, cannot copy an adaptive exam that scores 100–150 items on a 700/1000 scale. What the sampler shows is where to start: a miss in a domain is a reason to open that domain in Drill on the practice test, not a verdict on exam day.
Q04Is the practice on this site free?
Yes. The sampler, the 60-item practice test with Drill, Weak-spot and Timed 60, the two domain guides and the study plan work in the browser, without an account. The app is a separate, larger question bank for phones; nothing here requires it.
Q05Are these real CISSP exam questions?
No. Every item here is an original practice question written for this site and checked by hand; actual exam content is covered by ISC2’s non-disclosure agreement. The items train the same kind of reasoning, not the same questions.
Every page on this site
Field kit
Keep the domain drills on your phone
The CISSP prep app carries a much larger question bank, on iPhone and Android, for the gaps between meetings.