CISSP study material // original practice items

Not exam content · rev 2026-10

CISSP CAT Practice

CISSP prep console8 domains · outline Apr 2024

Get the app

Doc CC-05Rev 2026-10Class study materialRead ~9 min

CISSP study guide: the 8 domains and their 2024 weights

The ISC2 CISSP (Certified Information Systems Security Professional) exam covers eight domains: Security and Risk Management (16%), Asset Security (10%), Security Architecture and Engineering (13%), Communication and Network Security (13%), Identity and Access Management (13%), Security Assessment and Testing (12%), Security Operations (13%) and Software Development Security (10%). Those are the weights of the current outline, effective April 2024. Below: what each domain actually asks, its favorite trap, and how the eight lean on each other.

Exam readout

Format
CAT, every language
Items
100–150
Time
3 hours
Pass mark
700 / 1000 scaled
Outline
8 domains · Apr 2024

The eight domains by weight

  1. D1Security and Risk Management

    16%

  2. D2Asset Security

    10%

  3. D3Security Architecture and Engineering

    13%

  4. D4Communication and Network Security

    13%

  5. D5Identity and Access Management

    13%

  6. D6Security Assessment and Testing

    12%

  7. D7Security Operations

    13%

  8. D8Software Development Security

    10%

Average weight per domain in the ISC2 CISSP outline effective April 15, 2024. D1 and D3 link to their guides.

Reading the chart

Domain 1 is the only one above 13%. Five domains sit at 12–13%, and Asset Security and Software Development Security share the floor at 10% each — still roughly a tenth of your exam, which is a lot of items to concede on purpose.

The April 2024 refresh moved exactly one point: Domain 1 went from 15% to 16% and Domain 8 from 11% to 10%. Every other weight, and every domain name, stayed where the 2021 outline put them. If a set of notes still says 15% and 11%, it was written against the old outline — the quickest dating test there is.

The full outline, with every objective under every domain, is published on isc2.org. Read it once. Every study guide, this one included, is a paraphrase of it.

The eight domains, one card each

Scope in two or three sentences per domain. The two guides that exist are linked; the other six are being written and are marked as such.

  • D116%

    Security and Risk Management

    The judgment domain: governance and roles, the ISC2 Code of Ethics, law, privacy and intellectual property, the policy hierarchy, continuity requirements and quantitative risk. Questions put you in an advisor’s seat and ask what comes first — rarely the technical fix.

    Open the guide

  • D210%

    Asset Security

    How information is classified, owned, handled, retained and finally destroyed. Expect the owner-versus-custodian split, the three data states, and picking a sanitization method that actually works on the media in front of you.

    In preparation

  • D313%

    Security Architecture and Engineering

    Secure design principles, the formal security models, cryptography and PKI, the weak spots of cloud, ICS, IoT and container platforms, and facility design down to fire suppression. Heavy on things you memorize and then have to apply under a scenario.

    Open the guide

  • D413%

    Communication and Network Security

    Networks from the OSI model up: where protocols and devices sit, IPsec and TLS, segmentation, wireless security, SDN and converged protocols. Less about configuration syntax than about which layer a control lives on and what it protects.

    In preparation

  • D513%

    Identity and Access Management (IAM)

    Who gets in and what they may do once inside: authentication factors and biometric error rates, SSO and federation, access-control models from DAC to ABAC, provisioning and access reviews. Two different things are abbreviated RBAC, and the exam knows it.

    In preparation

  • D612%

    Security Assessment and Testing

    Choosing the test that fits the goal — vulnerability scan, penetration test, code review, SAST, DAST, synthetic transactions — plus audits, SOC reports, KPIs and KRIs. Written authorization and honest reporting count as much as technique.

    In preparation

  • D713%

    Security Operations

    Running security every day: investigations and evidence, logging and monitoring, incident management, patch and change control, backups, recovery sites and disaster recovery testing. A large share of its questions are about doing steps in the right order.

    In preparation

  • D810%

    Software Development Security

    Security inside software: where it enters the development lifecycle, maturity models, CI/CD and repository controls, code-level weaknesses, API security, and the risk of software you buy, rent or borrow. The answer to “when should security start?” is earlier than the option you were about to pick.

    In preparation

What each domain actually asks

The outline lists topics; the exam asks for decisions. This is the shape of the question per domain, and the mistake it is built to catch.

Question shape and classic trap, by domain
RefDomainThe question usually wants you toThe classic trap
R-01D1 Security and Risk ManagementPick the first or best action from a manager’s chair: human safety, then business objectives, then the controlSwapping due care (acting as a prudent person would) with due diligence (investigating and verifying); treating a guideline as mandatory
R-02D2 Asset SecurityDecide who classifies, who protects day to day, who processes; choose a sanitization method by media typeDegaussing an SSD — it only works on magnetic media; assuming the custodian classifies the data
R-03D3 Security Architecture and EngineeringMatch a security model to the property it enforces; choose symmetric, asymmetric or hashing for a stated serviceReversing the Bell-LaPadula and Biba rules, which are mirror images; expecting an HMAC to give non-repudiation
R-04D4 Communication and Network SecurityPlace a protocol or device on its layer; choose the IPsec mode and protocol for a requirementForgetting that AH only authenticates — encryption needs ESP
R-05D5 Identity and Access ManagementIdentify factor types, choose an access-control model, read FAR, FRR and CERCounting a password plus a PIN as two factors; mixing up role-based and rule-based access control
R-06D6 Security Assessment and TestingPick the assessment that answers the question asked; tell SOC 1 from SOC 2, Type I from Type IICalling a vulnerability scan a penetration test; testing anything without written authorization from management
R-07D7 Security OperationsPut incident, evidence and recovery steps in order; choose a backup type and recovery siteCollecting the disk before the RAM, against the order of volatility; thinking a parallel test takes the primary site down
R-08D8 Software Development SecurityChoose a development methodology and the phase where security enters; match a test type to the state of the codeRunning SAST against a live app — SAST reads source, DAST needs the application running

How the domains interlock

The eight domains are filing categories, not separate subjects. A single scenario often needs two of them, and studying each as a sealed box is how you end up knowing every definition and still choosing the second-best answer.

Risk is the spine

Domain 1’s decisions set the budget for every control in the other seven. Asset value, annualized loss expectancy and senior management’s risk acceptance decide whether a control is worth buying at all. A Domain 7 question about recovery sites is frequently a Domain 1 question in disguise: maximum tolerable downtime has to cover the recovery time objective plus the work-recovery time, and the recovery point objective decides how often you back up.

Data, and who touches it

Domain 2 and Domain 5 are two halves of one idea. The owner classifies the data in Domain 2; the access-control model enforces that decision in Domain 5. Under discretionary access control the owner grants access directly, under mandatory access control the system compares labels with clearances — and those labels are the classification you assigned two domains earlier.

Build, connect, check, run

SAST, DAST and code review appear in both Domain 6 and Domain 8. Domain 6 asks which test fits a goal; Domain 8 asks where in the lifecycle that test belongs and who acts on the findings. Supply-chain risk works the same way: Domain 1 frames it as third-party risk, Domain 8 as the open-source library you did not write.

The practical consequence: once a domain feels solid, practice it mixed with the others. The CISSP practice test lets you filter by domain in Drill and then take all eight shuffled together in Timed 60.

The outline is eight chapters long because the job is. The exam just declines to tell you which chapter a question came from.

Margin note on the 2024 outline

CBK, outline, syllabus: what the words mean

The CISSP CBK — Common Body of Knowledge — is ISC2’s name for the body of security knowledge the credential is built on, organized into the same eight domains. The exam outline is the document that says what the exam tests within it: domains, weights and objectives. If you were looking for a CISSP syllabus or course outline, the exam outline is the closest real thing.

When people search for “the 8 domains of cyber security”, they almost always mean this list. It is ISC2’s way of dividing the field for one exam, not an industry-wide standard, and other certifications slice the same ground differently. ISC2 has revised the outline roughly every three years — 2018, 2021, 2024 — and, as of October 2026, has not announced the next revision.

Four terms the outline assumes you know

Common Body of Knowledge (CBK)
ISC2’s name for the body of security knowledge a credential rests on; for CISSP it is organized into the eight domains.
Exam outline
The CISSP-specific list of domains, weights and objectives. The current one took effect on April 15, 2024.
Job task analysis
The survey of working practitioners that ISC2 uses to decide what goes into a new outline and how much each domain weighs.
Average weight
The share of exam content a domain carries across sittings. A planning figure, not a guaranteed item count.

Weighting your hours by domain

Start from the chart and adjust for your own distance from each domain. Out of every 100 study hours, the outline alone would give 16 to Domain 1, 10 each to Domains 2 and 8, and 12 or 13 to the rest. Your résumé then redistributes them.

  • A network engineer can borrow hours from Domain 4 and spend them on Domains 1 and 8.
  • An auditor usually finds Domain 6 familiar and Domain 3’s cryptography anything but.
  • A developer starts ahead on Domain 8 and tends to under-read Domain 2’s data roles.
  • A manager can read Domain 1 at speed and should slow down for Domain 4.

Whatever the split, log every miss by domain. The weakest one decides where next week goes — less fun than following your curiosity, considerably more effective. The week-by-week version, with resources, is the CISSP study plan.

Three items from Domain 8

Software Development Security is tied for the smallest weight at 10%, and it is the domain non-developers most often skim. Its guide is still in preparation, so here are three original practice items with a note on every option. Nobody is timing this one.

Domain drill

Item 01 / 03

Answer, then read why each option is right or wrong. Keys 1–4 pick, N goes next.

D8Software Development Security

A CISO is preparing a quarterly update for the board of directors. The current presentation highlights that '14,000 static analysis findings were resolved.' Which replacement metric best translates this technical telemetry into an appropriate business risk indicator for executive leadership?

Rationale

Pick an answer. The reasoning for every option lands here — including why the wrong ones looked right.

Debrief · key takeaways

  1. Eight domains, weighted 16 / 10 / 13 / 13 / 13 / 12 / 13 / 10 in the outline effective April 2024.
  2. Only D1 (15% → 16%) and D8 (11% → 10%) changed in the 2024 refresh; notes showing the old split are pre-2024.
  3. Weights are averages for planning, not item quotas, and items carry no domain label.
  4. Domain 1’s risk thinking feeds every other domain, so it earns its larger share of your hours.
  5. Study domain by domain, then practice them mixed — the exam never separates them.

Questions people ask

Q01What are the 8 domains of CISSP?

Security and Risk Management (16%), Asset Security (10%), Security Architecture and Engineering (13%), Communication and Network Security (13%), Identity and Access Management (13%), Security Assessment and Testing (12%), Security Operations (13%) and Software Development Security (10%), per the outline effective April 15, 2024.

Q02How many domains are required for the CISSP exam?

All eight are tested; you cannot choose or skip any. The number two applies elsewhere: certification requires five years of cumulative work experience in at least two of the eight domains, with up to one year waivable. The details are on CISSP requirements.

Q03Which CISSP domain is the most important?

By weight, Domain 1, Security and Risk Management, at 16%. It also sets the mindset — business-first, manager’s-chair judgment — that many questions in other domains expect. The lighter domains still carry 10% each, so none is safe to skip.

Q04What is the CISSP CBK?

The Common Body of Knowledge: ISC2’s body of security knowledge behind the credential, organized into the eight domains. The exam outline is the document that lists what the exam tests, with published weights.

Q05Did the CISSP domains change in 2024?

The names did not. The outline effective April 15, 2024 moved one point of weight from Domain 8 (11% → 10%) to Domain 1 (15% → 16%) and left the other six weights unchanged.

Field kit

Keep the practice going on your phone

The CISSP prep app carries a much larger question bank — on iPhone and Android.

Get the appPractice free on this site

End of document

Handle with mild caffeine