Free study guide book

ISC2 CISSP (Certified Information Systems Security Professional) — the study guide

9 chapters · 34 sections. Read it like a book: diagrams, worked examples, flip-card key terms and a check question in every section.

Chapter 1 of 9

🚀 Getting Started: CISSP Exam Essentials

2 sections · read, flip the key terms, then check yourself.

1.1

CISSP Exam Structure and Format

Understanding the CISSP exam's structure and format is crucial for effective preparation. Knowing what to expect on exam day helps manage anxiety and focus your study efforts on high-yield areas, directly impacting your chances of success. This knowledge is also valuable in your career as you'll be able to advise others on certification paths.

Computerized Adaptive Testing (CAT) for English Exams

The CISSP exam for English-speaking candidates uses a Computerized Adaptive Testing (CAT) format. This means the exam engine dynamically selects questions based on your previous answers. If you answer a question correctly, the system presents a more difficult question; if you answer incorrectly, it presents an easier one. This adaptive approach efficiently determines your proficiency level with fewer questions than a traditional linear exam. The CAT algorithm continuously re-estimates your ability based on your responses. The exam concludes when the system is sufficiently confident that you have either passed or failed, or when the maximum number of questions or time limit is reached. This format is designed to be highly precise in assessing your knowledge across the domains.

Exam Length, Time, and Scoring

For English CAT exams, candidates will answer between 100 and 150 questions. The maximum time allotted for the exam is three hours. Not all questions count towards your score; some are pre-test items used for future exams, which are indistinguishable from scored questions. You must achieve a minimum score of 700 out of 1000 points to pass the CISSP exam. It's important to remember that the CAT format means you cannot skip questions or go back to review previous answers. Once you select an answer and confirm it, you move to the next question, and your response is locked in. This requires careful consideration for each question before answering.

CISSP Domains and Weighting

The CISSP exam is organized into eight domains, each representing a critical area of information security. These domains are not equally weighted; some contribute more to your overall score than others. Understanding these weightings helps you prioritize your study time, focusing more on domains with higher percentages. The domains are regularly reviewed and updated by ISC2 to ensure they reflect current industry best practices and emerging threats. This ensures the certification remains relevant and valuable in the ever-evolving cybersecurity landscape. The current domain weights are critical to memorize for the exam.

Linear Format for Non-English Exams

Candidates taking the CISSP exam in languages other than English, such as Japanese or German, will experience a linear, fixed-form exam. This format presents a predetermined set of 250 questions. The time allotted for these exams is six hours, double the time for the English CAT exam, reflecting the larger number of questions. Unlike the CAT exam, the linear format allows candidates to mark questions for review and revisit them before submitting the exam. All 250 questions are scored, and the passing score remains 700 out of 1000 points. While the format differs, the content and difficulty level are designed to be equivalent across all language versions.

🖼️ CISSP Exam Domains and Weights
⚖️Security & Risk Management15% of exam
🔒Asset Security10% of exam
🏗️Security Architecture & Engineering13% of exam
🌐Communication & Network Security14% of exam
👤Identity & Access Management13% of exam
🔎Security Assessment & Testing12% of exam
⚙️Security Operations13% of exam
💻Software Development Security10% of exam

📌 Workplace example: Advising on Certification

A junior security analyst asks you about pursuing the CISSP certification. They are concerned about the exam's difficulty and time commitment.

What to do: You explain the CAT format for English exams, mentioning the 100-150 questions and 3-hour time limit. You also highlight the 8 domains and their weightings, advising them to focus more on areas like Security and Risk Management (15%) and less on Asset Security (10%) to optimize study.

Takeaway: Understanding exam format helps you guide colleagues and manage expectations effectively.

📌 Workplace example: Prioritizing Study Efforts

You are preparing for the CISSP exam and have limited study time. You need to decide which domains to prioritize.

What to do: You review the official CISSP exam outline and identify the domains with the highest weighting, such as Security and Risk Management (15%) and Communication and Network Security (14%). You allocate more study hours to these areas, ensuring a strong foundation, while still covering all domains adequately.

Takeaway: Strategic study based on domain weighting maximizes your chances of passing.

Key terms — tap to check

Memory trick: Remember the 8 domains with 'SAM Can't See All Secure Software Dev'. (Security & Risk, Asset, Comm & Net, Security Arch & Eng, Identity & Access, Security Assess & Test, Security Ops, Software Dev Security)

Common mistakes

  • Assuming all questions count towards your score; some are pre-test items.
  • Trying to guess the difficulty of questions to determine if you are doing well; focus on each question individually.
  • Not allocating study time according to domain weighting; this can lead to under-preparation in critical areas.

Which of the following best describes the Computerized Adaptive Testing (CAT) format used for the English CISSP exam?

1.2

Effective Study Strategies and Resources for CISSP

Preparing for the CISSP exam requires a strategic approach, not just rote memorization. On the job, effective learning and resource utilization are critical for staying current with security threats and technologies. This lesson will equip you with the best practices to conquer the exam and enhance your professional development.

Understanding the CISSP CBK and Domains

The CISSP Common Body of Knowledge (CBK) is the foundation of the exam, encompassing eight domains. Each domain represents a critical area of information security, and the exam draws questions from all of them. A balanced understanding across all domains is crucial, as a weakness in one area can significantly impact your overall score. Familiarize yourself with the official ISC2 exam outline. This document details the specific topics covered within each domain and their respective weightings on the exam. It serves as your primary guide for content coverage.

  • 8 domains of the CISSP CBK
  • Official ISC2 exam outline is your primary guide
  • Balanced understanding across all domains is key

Developing a Personalized Study Plan

A structured study plan is essential for effective preparation. Begin by assessing your current knowledge across the eight domains. Identify your strengths and weaknesses to allocate study time appropriately. Don't neglect domains you feel confident in; a review can solidify your understanding. Set realistic daily or weekly study goals. Consistency is more important than cramming. Integrate different study methods, such as reading, practice questions, and flashcards, to keep your learning engaging and reinforce concepts. Regularly review previously studied material to aid retention.

  • Assess current knowledge across all 8 domains
  • Set realistic and consistent study goals
  • Integrate diverse study methods

Leveraging Official and Unofficial Resources

The official ISC2 CISSP Study Guide and Official Practice Tests are indispensable resources. These materials are directly aligned with the exam content and provide a solid foundation. Supplement these with other reputable textbooks, online courses, and video lectures to gain different perspectives and explanations. Consider joining study groups or online forums. Discussing concepts with peers can clarify difficult topics and expose you to different viewpoints. Practice questions are vital; they help you understand the exam's question style and identify areas needing further study. Aim for a variety of practice questions from different sources.

  • Official ISC2 Study Guide and Practice Tests are primary
  • Supplement with reputable textbooks and online courses
  • Utilize study groups and practice questions

Mastering Exam-Taking Strategies

The CISSP exam is not just about knowing the material; it's also about understanding how to answer scenario-based questions. Many questions require you to think like a manager, prioritizing risk and business impact over purely technical solutions. Look for keywords such as 'MOST appropriate,' 'BEST,' or 'FIRST.' Practice time management during your study sessions. The exam is long, and pacing yourself is crucial. Read each question carefully, eliminating obviously incorrect answers first. If unsure, make an educated guess and move on. Don't dwell too long on a single question.

  • Think like a manager, prioritize risk and business impact
  • Identify keywords like 'MOST appropriate' or 'BEST'
  • Practice time management and educated guessing
🖼️ CISSP Study Strategy Cycle
  1. 1📊 Assess DomainsIdentify strengths and weaknesses
  2. 2🗓️ Create PlanSet goals, allocate time
  3. 3📚 Study ResourcesOfficial guides, practice tests
  4. 4❓ Practice QuestionsTest knowledge, refine skills
  5. 5🔄 Review & AdaptAdjust plan, revisit weak areas
  6. ↻ …and the cycle repeats

📌 Workplace example: Prioritizing Study Areas

An IT professional, primarily experienced in network security, is preparing for the CISSP. While confident in network topics, they have limited exposure to software development security and legal aspects.

What to do: The professional should allocate more study time and resources to the software development security and legal domains. They should use official study guides and supplementary materials specifically for these areas, and seek out practice questions that focus on these weaker domains to build proficiency.

Takeaway: Tailor your study plan to address your individual knowledge gaps across all CISSP domains.

📌 Workplace example: Applying Managerial Thinking

During a practice exam, a question asks for the 'BEST' way to respond to a data breach. One option is a highly technical solution, while another focuses on communication and legal notification requirements.

What to do: The professional should choose the option that emphasizes communication and legal notification. While technical remediation is important, the CISSP often prioritizes the managerial, risk-based, and compliance aspects of security incidents over purely technical fixes.

Takeaway: Always consider the 'managerial' perspective and business impact when answering CISSP questions.

Key terms — tap to check

Memory trick: To remember key study steps: 'Assess, Plan, Resource, Practice, Review' – APRPR. Like 'April's Pretty Radiant, Right?'

Common mistakes

  • Focusing too heavily on technical details without understanding the managerial and risk-based implications.
  • Relying on only one study resource, missing out on diverse perspectives and question styles.
  • Neglecting weaker domains, assuming strong areas will compensate for deficiencies.

Which of the following is the MOST important first step when beginning your CISSP exam preparation?