ISC2 Certification Exam Prep
Study guides, practice exams, and flashcards for all ISC2 certifications. 1 certification available.
About CISSP Certification
The CISSP (Certified Information Systems Security Professional) is the senior-level credential for cybersecurity practitioners. It is accredited under ISO/IEC 17024 and listed under DoD Manual 8570/8140 at IAM Level III, IAT Level III, and IASAE Level II — which is why it appears on so many federal and defense cybersecurity job postings.
The exam covers eight domains in the (ISC)² Common Body of Knowledge: Security and Risk Management, Asset Security, Security Architecture and Engineering, Communication and Network Security, Identity and Access Management, Security Assessment and Testing, Security Operations, and Software Development Security. The English-language exam uses Computerized Adaptive Testing (CAT), 100–150 questions in up to 3 hours.
Eligibility: five years of paid, full-time work experience in two or more of the eight domains (one year can be waived with a four-year degree or another approved credential like the CCSP or SSCP). Candidates without the experience yet can take the exam and hold Associate of (ISC)² status until they accrue the time.
Career value: CISSP-certified professionals in North America report an average salary around USD $150,000 in (ISC)² compensation surveys. The credential is required or preferred for security engineer, security architect, CISO, and federal cybersecurity roles. CISSP is fundamentally a managerial-level exam — it tests judgment across the security domains rather than hands-on tooling skill, so candidates who can think like a defender designing layered controls do best.
All ISC2 Certifications
Advanced
[CISSP] Certified Information Systems Security Professional
The gold-standard certification for experienced information security professionals.
Key Topic Areas
The core domains tested across ISC2 certifications. Each badge links to the study guide for an exam that covers the area.
Security and Risk Management
16% of examGovernance · Compliance · Risk management · Threat modeling · BCP/DR planning · Personnel security · Professional ethics
Asset Security
10% of examInformation classification · Data lifecycle · Data retention · Privacy controls · Data security controls
Security Architecture & Engineering
13% of examSecurity models · Cryptography · System architecture · Physical security · Cloud security
Communication & Network Security
13% of examNetwork architecture · Network components · Secure protocols · Wireless security · Software-defined networks
Identity & Access Management
13% of examPhysical and logical access · Identification and authentication · Federation · Authorization mechanisms · Access control attacks
Security Assessment & Testing
12% of examAssessment strategies · Security control testing · Audit · Vulnerability assessment · Penetration testing
Security Operations
13% of examInvestigations · Logging and monitoring · Incident management · Disaster recovery · BCP execution
Software Development Security
10% of examSDLC · Development methodologies · Source code security · Secure coding standards · API security
Frequently Asked Questions
Explore More Certifications
Browse all certification paths across AWS, Azure, CompTIA, and more.
Browse All Certifications