By Fatskills Exam Guides Team — the exam nerds behind 28,500+ quizzes and 2.1M practice questions across 500+ global exams.
Mid-career cybersecurity / IT professionals | Format (all languages now): CAT exam, 100–150 Q, 3 hours max
Must-do topics
CISSP = broad managerial security view across 8 domains (ISC² CBK).
Security & Risk Management
CIA triad, governance, risk analysis (qual/quant), threat + vulnerability + impact.
Policies, standards, guidelines, procedures.
Legal/compliance, ethics, privacy, due care/due diligence, BCP basics.
Asset Security
Data classification, ownership, retention, handling, disposal.
Privacy, data roles (owner, custodian, user).
Security Architecture & Engineering
Secure design principles, security models, hardware/firmware trust, crypto basics.
Physical security concepts.
Communication & Network Security
Network architectures, protocols, segmentation, secure design, VPNs, wireless security.
Identity & Access Management (IAM)
Authentication, authorisation, accounting.
IAM models (RBAC, ABAC, MAC, DAC), SSO, federation, lifecycle management.
Security Assessment & Testing
Audits, assessments, penetration testing vs vulnerability scanning, logging/monitoring.
Security Operations
Incident response lifecycle, change management, logging, monitoring, forensics basics.
Admin tasks, backup/restore, DR/BCP operations.
Software Development Security
SDLC, secure coding principles, common vulns (OWASP-style thinking), dev/test/prod, change control.
Top traps (avoid)
Studying CISSP as if it were an exploit dev / tool-driven exam — it’s not. It’s about governance-level thinking, risk, and management choices.
Over-focusing on memorising every cipher/key length instead of understanding when/why to use crypto.
Answering like a sysadmin or pentester instead of a security manager / CISO.
Ignoring older domains (Asset Security, Security Assessment & Testing) because they “feel small.”
Not practising CAT-style questions and getting surprised by how punishing early mistakes can be.
Time split
100–150 questions, 3 hours max. The exam stops early if the algorithm is confident you pass or fail.
Rough pacing:
Treat it like ~1–1.5 min per question; you cannot really “bank” a lot of time.
Focus on calm, consistent performance — particularly in the first 30–40 questions.
Last-48h checklist
No new books; you’re curating what’s already in your head.
Do:
100–150 mixed practice questions per day, in one or two sittings, not 10 at a time.
Review:
Domain-by-domain summary notes — especially risk, IAM, and operations/IR.
Key standards and concepts at a high level (ISO 27001-style thinking, NIST ideas, but not clause-by-clause memorisation).
Write a small “brain reset” card:
8 domains list, IR lifecycle, risk formula basics, access control models, high-level crypto uses.
Quick frames
When you read a stem, immediately ask:
What role am I answering as?
CISSP usually → senior security professional / manager, not Level-1 helpdesk.
What’s the real problem?
Risk, compliance, availability, integrity, confidentiality, safety, cost, or business objective?
What phase are we in?
Prevention, detection, response, recovery, improvement?
This often eliminates 2–3 options outright.
Speed tactics
Prefer answers that:
Address root cause over band-aid fixes.
Are procedural and documented (policy, process, training) over ad-hoc heroics.
Respect law/regulation and contractual obligations.
If two answers seem good, pick the one that:
Protects human life, safety, and legal exposure first.
Don’t get stuck on one crypto/standards detail. Ask:
“What’s the most reasonable, best-practice answer for a large organisation?”
Day-of mini-plan
Morning: 15–20 warm-up questions, then close banks.
During exam:
If you feel shaken by a weird question, treat it as noise; CAT expects a mix of easy and brutal items.
Mantra:
“Think like the person who signs off the budget and owns the risk register, not the person rebooting the server.”
Join 4M+ learners. Unlock unlimited quizzes, wrong-answer tracking, flashcards + reminders, study guides, and 1-on-1 challenges.