ISC2 Certified Information Systems Security Professional
CISSP practice questions from your own study material
The English CISSP is adaptive: 100 to 150 items in 3 hours, and 700 of 1000 passes.
Eight domains is more reading than any question bank covers in your words.
Your first 10-question diagnostic is free, and every answer cites the page it came from.
Free. No credit card required.
- Code
- CISSP
- Questions
- 100 to 150, adaptive in English
- Duration
- 3 hours
- Pass mark
- 700 of 1000, scaled
- Price
- $749, region-dependent
- Delivery
- ISC2-authorized Pearson VUE centers
- Format
- multiple choice and advanced item types
- Experience
- 5 years in 2 or more domains
Exam facts from ISC2 CISSP exam outline, April 2024. QuizPDF is not affiliated with the exam body.
- Readiness pass mark
- 72
- Gap
- −11
- To exam day
- 18 days
Readiness 61%. Cryptography is the topic holding it down. 1 topic untested.
| Topic | Misses | Last seen |
|---|---|---|
| Cryptography and PKI | 9 | Page 188 |
| Security models | 5 | Page 174 |
| Risk frameworks | 3 | Page 42 |
| Software development security | — | Untested |
What CISSP tests
The official weightings. QuizPDF reads your syllabus and finds its own topics, then reports Readiness per topic.
| Domain | Weight | Covers |
|---|---|---|
| Security and Risk Management | 16% | ISC2 ethics, governance, compliance and privacy law, investigation types, policy and standards, business impact analysis, risk frameworks, threat modelling, supply-chain risk, awareness programs |
| Asset Security | 10% | classifying information and assets, handling requirements, data lifecycle and roles, retention, remanence and destruction, data in use, in transit and at rest, DRM, DLP, CASB |
| Security Architecture and Engineering | 13% | secure design principles, Bell-LaPadula and Biba, TPM and memory protection, cloud, IoT, ICS, container and serverless weaknesses, cryptography and PKI, side-channel attacks, physical security |
| Communication and Network Security | 13% | OSI and TCP/IP, IPv4 and IPv6, IPSec, SSH and TLS, SDN, micro-segmentation, wireless and cellular, CDNs, NAC, endpoint security, remote access and third-party connectivity |
| Identity and Access Management | 13% | physical and logical access control, MFA, passwordless and SSO, federated identity, RBAC against MAC against DAC against ABAC, provisioning and deprovisioning, access review, privilege escalation |
| Security Assessment and Testing | 12% | assessment and audit strategies, vulnerability assessment, penetration testing, log review, code review, breach and attack simulation, reporting and remediation, internal and third-party audits |
| Security Operations | 13% | evidence handling and forensics, logging, SIEM and UEBA, configuration management, need-to-know and separation of duties, privileged account management, incident management, patching, disaster recovery |
| Software Development Security | 10% | the development lifecycle, secure coding practices, security controls in the development environment, software supply chain |
Where candidates lose points
Self-reported, from candidate write-ups. Your own Miss list will disagree with this one, and it is the one that counts.
- 01
Answering as a manager
The expected answer is the risk-based, policy-first one, not the technical fix. Practitioners report this as the whole adjustment.
- 02
Security Architecture and Engineering
Security models, cryptography and cryptanalytic attacks in one 13% domain. Self-reports name it among the hardest.
- 03
Software Development Security
The smallest domain at 10%, and the one candidates from an infrastructure background report skipping until too late.
- 04
How the adaptive exam feels
It gets harder when you are doing well, and there is no running score. Candidates report leaving convinced they failed.
- 05
Breadth over depth
Eight domains at 10 to 16% each. Reported plans run from seven weeks to over a year, and high practice-test scores have not guaranteed a pass.
Self-reported plans run from about seven weeks to more than a year, on the ISC2 official course, the Sybex study guide, 11th Hour and a question bank. ISC2 publishes no recommended duration.
How a readiness drill on your own syllabus works
- 01Upload the syllabusYour syllabus: the study guide, the course notes, the official PDF. Text PDF, up to 40 MB.
- 02Take the free diagnostic10 questions written from your pages. Each answer is revealed at once, with the page it came from.
- 03Read the scoreYour score, the topics you missed named from your own document, and Readiness beside the pass mark.
- 04Drill the Miss list$29 once unlocks that syllabus forever. Every drill after that is weighted toward what you keep getting wrong.
Questions about CISSP
- How many questions are on the CISSP?
- The English exam is adaptive: between 100 and 150 items in 3 hours. Non-English versions are a fixed 250 items in 6 hours.
- What score do you need to pass the CISSP?
- 700 out of 1000, published by ISC2. It is a scaled score on an adaptive exam, so it is not a percentage of items correct.
- Do I need five years of experience before the exam?
- To be certified, yes: five years across two or more domains, with up to one year waived by a degree or an approved credential. You can pass first and hold Associate of ISC2 for six years.
- Can I drill my own CISSP notes instead of a question bank?
- Yes. That is what this is. Upload your syllabus as a text PDF and the questions are written from its pages.
- Does the free drill need a card?
- No. A free account, one upload, 10 questions, your score and your missed topics. No card.
- What does the $29 unlock buy?
- Unlimited drills on that one syllabus, forever, weighted to your Miss list, plus the Readiness number. One payment, no subscription.
Drill your CISSP notes. 10 questions free.
No card to create the account. The score, the missed topics and the pages are yours either way. $29 once turns that syllabus into unlimited practice.