ISC2 Certification Exam Prep

Study guides, practice exams, and flashcards for all ISC2 certifications. 1 certification available.

About CISSP Certification

The CISSP (Certified Information Systems Security Professional) is the senior-level credential for cybersecurity practitioners. It is accredited under ISO/IEC 17024 and listed under DoD Manual 8570/8140 at IAM Level III, IAT Level III, and IASAE Level II — which is why it appears on so many federal and defense cybersecurity job postings.

The exam covers eight domains in the (ISC)² Common Body of Knowledge: Security and Risk Management, Asset Security, Security Architecture and Engineering, Communication and Network Security, Identity and Access Management, Security Assessment and Testing, Security Operations, and Software Development Security. The English-language exam uses Computerized Adaptive Testing (CAT), 100–150 questions in up to 3 hours.

Eligibility: five years of paid, full-time work experience in two or more of the eight domains (one year can be waived with a four-year degree or another approved credential like the CCSP or SSCP). Candidates without the experience yet can take the exam and hold Associate of (ISC)² status until they accrue the time.

Career value: CISSP-certified professionals in North America report an average salary around USD $150,000 in (ISC)² compensation surveys. The credential is required or preferred for security engineer, security architect, CISO, and federal cybersecurity roles. CISSP is fundamentally a managerial-level exam — it tests judgment across the security domains rather than hands-on tooling skill, so candidates who can think like a defender designing layered controls do best.

All ISC2 Certifications

Advanced

Certified Information Systems Security Professional logo

[CISSP] Certified Information Systems Security Professional

The gold-standard certification for experienced information security professionals.

Recommended Learning Paths

Cybersecurity Path

Key Topic Areas

The core domains tested across ISC2 certifications. Each badge links to the study guide for an exam that covers the area.

Security and Risk Management

16% of exam

Governance · Compliance · Risk management · Threat modeling · BCP/DR planning · Personnel security · Professional ethics

Covered in:CISSP

Asset Security

10% of exam

Information classification · Data lifecycle · Data retention · Privacy controls · Data security controls

Covered in:CISSP

Security Architecture & Engineering

13% of exam

Security models · Cryptography · System architecture · Physical security · Cloud security

Covered in:CISSP

Communication & Network Security

13% of exam

Network architecture · Network components · Secure protocols · Wireless security · Software-defined networks

Covered in:CISSP

Identity & Access Management

13% of exam

Physical and logical access · Identification and authentication · Federation · Authorization mechanisms · Access control attacks

Covered in:CISSP

Security Assessment & Testing

12% of exam

Assessment strategies · Security control testing · Audit · Vulnerability assessment · Penetration testing

Covered in:CISSP

Security Operations

13% of exam

Investigations · Logging and monitoring · Incident management · Disaster recovery · BCP execution

Covered in:CISSP

Software Development Security

10% of exam

SDLC · Development methodologies · Source code security · Secure coding standards · API security

Covered in:CISSP

Frequently Asked Questions

Explore More Certifications

Browse all certification paths across AWS, Azure, CompTIA, and more.

Browse All Certifications