Start Your Free Practice Test
Enter your details, then choose a 25-question Quick Test or the full 50-question, 60-minute practice test.
Hello, you are using an old browser that's unsafe and no longer supported. Please consider updating your browser to a newer version, or downloading a modern browser.
Check your readiness for the ISC2 Certified Information Systems Security Professional (CISSP) exam with 50 scenario-based questions across all eight domains of the current ISC2 exam outline (effective April 15, 2024), reviewed and updated for 2026, each with an instant explanation. Free to take, timed to the pace of the real exam, and retake it as often as you want.
New to CISSP? Learn more about the certification →
Enter your details, then choose a 25-question Quick Test or the full 50-question, 60-minute practice test.
This free ISC2 CISSP practice test checks your readiness with 50 scenario-based questions across all eight domains of the current ISC2 exam outline (effective April 15, 2024), each with an explanation for every answer choice. Built by Training Camp, an ISC2 Official Training Partner. New to CISSP? Learn what the certification is and who it is for, or see the accelerated CISSP Certification Boot Camp.
CISSP is organized into eight weighted domains under the ISC2 exam outline that took effect April 15, 2024. As of September 2026, ISC2 has not announced a successor CISSP outline, so that blueprint is the one you will sit. The weightings are listed below, and this practice test pulls questions from every domain in roughly those proportions. For the full breakdown, see our CISSP exam objectives. Domain 1 in particular expects familiarity with governance and risk frameworks such as the NIST Cybersecurity Framework and ISO/IEC 27001.
The exam is a computerized adaptive test (CAT) in every language it is offered in (English, Chinese, German, Japanese and Spanish): you answer between 100 and 150 questions in a three-hour session, and the passing score is 700 out of 1000 points. Questions are written from the point of view of a security manager or architect and ask for the BEST decision, so several of the wrong choices are usually reasonable actions that are simply not the best one. Certification also requires five years of cumulative paid work experience in two or more of the eight domains, one year of which can be waived.
ISC2 refreshes the CISSP outline and question pool on a regular cycle. On April 2, 2026 it published its Exam Guidance for Artificial Intelligence, which maps AI security concepts into the existing domains of every ISC2 exam, including CISSP, rather than adding a new domain. We keep our practice questions aligned with the current published outline and include AI and machine-learning security risks where they map to existing domain objectives.
Take all 50 questions once under the 60-minute timer without notes, which is the same pace as the real exam at its 150-question maximum, then read every explanation, including the ones for choices you did not pick. The wrong-answer explanations show the reasoning patterns ISC2 expects: think like a manager, weigh cost against risk, and choose the control that addresses the root problem rather than the symptom. Use the per-domain breakdown to decide where to study, then retake the test after a week to see whether your judgment has shifted.
8 domains, weighted as ISC2 weights them
Security and Risk Management 16%
Governance, risk analysis, policy, legal and compliance, BCP, and awareness.
Asset Security 10%
Data classification, ownership roles, handling, retention, and secure disposal.
Security Architecture and Engineering 13%
Secure design principles, security models, cryptography, and physical security.
Communication and Network Security 13%
Secure network design, protocols, segmentation, VPNs, and communication channels.
Identity and Access Management (IAM) 13%
Authentication, authorization models, federation, and the identity lifecycle.
Security Assessment and Testing 12%
Vulnerability assessment, penetration testing, audits, and security metrics.
Security Operations 13%
Incident response, forensics, logging and monitoring, change management, recovery.
Software Development Security 10%
Secure SDLC, threat modeling, secure coding, and software supply chain controls.
Four questions from the bank, one per domain, with the reasoning behind every answer. The full test has 50.
1.A risk analyst is evaluating a safeguard for the company's new AI-powered fraud-detection platform. A threat to the platform carries an annual loss expectancy (ALE) of $200,000. A proposed control would reduce the ALE to $50,000 but costs $250,000 per year to operate and maintain. Senior management asks for a recommendation. Which is the MOST defensible recommendation?
Why C is right: Cost-benefit analysis requires that the safeguard's cost be less than the reduction in ALE; here the control costs more than it saves, so a cheaper mitigation, transfer, or acceptance should be evaluated instead. (Security and Risk Management)
2.A database administrator configures encryption-at-rest, applies the retention schedule, and performs nightly backups for a system containing customer records. The classification level and handling requirements were set by the business unit that owns the data. Which role is the DBA fulfilling in this scenario?
Why C is right: The data custodian implements and maintains the protective controls (encryption, backups, retention) as directed by the owner. Encryption, backups and retention enforcement are custodial tasks; the business unit that set the classification is the owner. (Asset Security)
3.Which reference monitor property requires that every access by a subject to an object be checked, with no way to bypass the check?
Why B is right: Complete mediation (the always-invoked property) requires that the reference monitor check every access attempt, so there is no unchecked path to any object. (Security Architecture and Engineering)
4.A university network engineer investigating intercepted student logins finds that an attacker on the same switched subnet is sending forged ARP replies, so traffic between the gateway and other hosts flows through the attacker's machine. Which control MOST directly mitigates this attack?
Why B is right: Dynamic ARP Inspection validates ARP packets against the trusted DHCP snooping binding table and drops forged ARP replies, directly stopping ARP cache poisoning. (Communication and Network Security)
Every one of the 50 questions works this way: an explanation for the right answer and for the one you picked, so a wrong answer teaches you something. Questions last reviewed against the current ISC2 Certified Information Systems Security Professional (CISSP) objectives.
Quick answers about the test, the ISC2 Certified Information Systems Security Professional (CISSP) exam, and how to prepare.
Yes. Training Camp's CISSP practice test is completely free, with a written explanation for every answer choice across all eight ISC2 CISSP domains. You can retake it as often as you want.
50 scenario-based questions drawn from all eight CISSP domains, with an instant explanation after each answer and a 60-minute timer, which is timed to the pace of the real exam (up to 150 questions in 180 minutes). Your results break down by domain. You can retake it as often as you want. It is a readiness check, not a substitute for full preparation.
Since April 15, 2024, every CISSP exam uses Computerized Adaptive Testing (CAT) with 100 to 150 questions and a three-hour time limit, in all five exam languages. Because the exam adapts to your answers, the exact number of questions varies from one candidate to the next.
You need a scaled score of 700 on a scale of 1000 to pass the CISSP exam. The scaled score is not a percentage of questions answered correctly.
The current exam outline, effective April 15, 2024, has eight domains: Security and Risk Management (16%), Asset Security (10%), Security Architecture and Engineering (13%), Communication and Network Security (13%), Identity and Access Management (IAM) (13%), Security Assessment and Testing (12%), Security Operations (13%), and Software Development Security (10%).
You can sit the exam at any time, but to certify ISC2 requires five years of cumulative paid work experience in two or more of the eight domains. One year can be waived with a qualifying four-year degree or an approved credential, and candidates who pass without the full experience become an Associate of ISC2 while they earn it.
CISSP is an advanced exam aimed at experienced practitioners. It rewards management-level judgment and breadth across the whole security program: most questions describe a situation and ask for the BEST decision, and several of the wrong choices are usually reasonable. Candidates with hands-on experience across several domains tend to find the reasoning familiar; others need to practice thinking like a manager rather than a technician.
Work through the official CISSP exam outline, use a structured CISSP study guide, and consider an accelerated CISSP Certification Boot Camp that includes the exam voucher and a free retake if you need it. Practice questions help you get used to the exam's think-like-a-manager framing.