Start Your Free Practice Test
Enter your details, then choose a 25-question Quick Test or the full 50-question, 60-minute practice test.
Hello, you are using an old browser that's unsafe and no longer supported. Please consider updating your browser to a newer version, or downloading a modern browser.
Check your readiness for the ISC2 Certified Information Systems Security Professional (CISSP) exam with 50 scenario-based questions across all eight domains of the current exam outline, updated for 2026, each with an instant explanation. Free to take, timed to the pace of the real exam, and retake it as often as you want.
New to CISSP? Learn more about the certification →
Enter your details, then choose a 25-question Quick Test or the full 50-question, 60-minute practice test.
This free ISC2 CISSP practice test checks your readiness with 50 scenario-based questions across all eight domains of the current exam outline, updated for 2026, each with an explanation for every answer choice. Built by Training Camp, an ISC2 Official Training Provider. New to CISSP? Learn what the certification is and who it is for, or see the accelerated CISSP Certification Boot Camp.
CISSP is organized into eight weighted domains under the current ISC2 exam outline, and this test reflects the 2026 content refinements ISC2 shares with its Official Training Partners: Security and Risk Management (16%), Asset Security (10%), Security Architecture and Engineering (13%), Communication and Network Security (13%), Identity and Access Management (IAM) (13%), Security Assessment and Testing (12%), Security Operations (13%), and Software Development Security (10%). This practice test pulls questions from every domain in roughly those proportions. For the full breakdown, see our CISSP exam objectives. Domain 1 in particular expects familiarity with governance and risk frameworks such as the NIST Cybersecurity Framework and ISO/IEC 27001.
The English-language exam is a computerized adaptive test (CAT): you answer between 100 and 150 questions in a three-hour session, and the passing score is 700 on a scale of 1000. Questions are written from the point of view of a security manager or architect and ask for the BEST decision, so several of the wrong choices are usually reasonable actions that are simply not the best one. Certification also requires five years of cumulative paid work experience in two or more of the eight domains, one year of which can be waived.
ISC2 refreshes the CISSP outline and question pool on a regular cycle. We keep our practice questions aligned with the current published outline and include emerging topics, such as AI and machine-learning security risks, where they map to existing domain objectives.
Take all 50 questions once under the 60-minute timer without notes, which is the same pace as the real exam at its 150-question maximum, then read every explanation, including the ones for choices you did not pick. The wrong-answer explanations show the reasoning patterns ISC2 expects: think like a manager, weigh cost against risk, and choose the control that addresses the root problem rather than the symptom. Use the per-domain breakdown to decide where to study, then retake the test after a week to see whether your judgment has shifted.
Domains Covered · 2026 Update
Governance, risk analysis, policy, legal and compliance, BCP, and awareness.
Data classification, ownership roles, handling, retention, and secure disposal.
Secure design principles, security models, cryptography, and physical security.
Secure network design, protocols, segmentation, VPNs, and communication channels.
Authentication, authorization models, federation, and the identity lifecycle.
Vulnerability assessment, penetration testing, audits, and security metrics.
Incident response, forensics, logging and monitoring, change management, recovery.
Secure SDLC, threat modeling, secure coding, and software supply chain controls.
Four questions from the bank, one per domain, with the reasoning behind every answer. The full test has 50.
A risk analyst is evaluating a safeguard for the company's new AI-powered fraud-detection platform. A threat to the platform carries an annual loss expectancy (ALE) of $200,000. A proposed control would reduce the ALE to $50,000 but costs $250,000 per year to operate and maintain. Senior management asks for a recommendation. Which is the MOST defensible recommendation?
Correct. Cost-benefit analysis requires that the safeguard's cost be less than the reduction in ALE; here the control costs more than it saves, so a cheaper mitigation, transfer, or acceptance should be evaluated instead.
A database administrator configures encryption-at-rest, applies the retention schedule, and performs nightly backups for a system containing customer records. The classification level and handling requirements were set by the business unit that owns the data. Which role is the DBA fulfilling in this scenario?
Correct. The data custodian implements and maintains the protective controls (encryption, backups, retention) as directed by the owner, which is exactly what the DBA is doing.
A security architect is reviewing the design of an operating system's security kernel, the part of the trusted computing base (TCB) that implements the reference monitor. She insists that every access by every subject to every object must pass through the kernel's authorization check, with no bypass path and no reliance on cached prior decisions. Which reference monitor requirement is the architect enforcing?
Correct. Complete mediation, sometimes stated as "always invoked", requires that every access to every object be checked against the authorization policy, preventing bypass or reuse of stale cached approvals. Together with being tamperproof and verifiable, it is one of the three defining requirements of the reference monitor concept that the security kernel implements.
On a switched LAN, an attacker connected to the same subnet sends forged ARP replies so that traffic between the gateway and other hosts flows through the attacker's machine, enabling interception. Which control MOST directly mitigates this attack?
Correct. Dynamic ARP Inspection validates ARP packets against the trusted DHCP snooping binding table and drops forged ARP replies, directly stopping ARP cache poisoning.
Every one of the 50 questions works this way: an explanation for the right answer and for the one you picked, so a wrong answer teaches you something. Questions last reviewed against the current ISC2 Certified Information Systems Security Professional (CISSP) objectives.
Quick answers about the test, the ISC2 Certified Information Systems Security Professional (CISSP) exam, and how to prepare.
Yes. Training Camp's CISSP practice test is completely free, with a written explanation for every answer choice across all eight ISC2 CISSP domains. You can retake it as often as you want.
50 scenario-based questions drawn from all eight CISSP domains, with an instant explanation after each answer and a 60-minute timer, which is timed to the pace of the real exam (up to 150 questions in 180 minutes). Your results break down by domain. You can retake it as often as you want. It is a readiness check, not a substitute for full preparation.
The English CISSP exam uses Computerized Adaptive Testing (CAT) with 100 to 150 questions and a three-hour time limit. Because the exam adapts to your answers, the exact number of questions varies from one candidate to the next.
You need a scaled score of 700 on a scale of 1000 to pass the CISSP exam. The scaled score is not a percentage of questions answered correctly.
The current exam outline, including the 2026 refinements ISC2 provides to Official Training Partners, has eight domains: Security and Risk Management (16%), Asset Security (10%), Security Architecture and Engineering (13%), Communication and Network Security (13%), Identity and Access Management (IAM) (13%), Security Assessment and Testing (12%), Security Operations (13%), and Software Development Security (10%).
You can sit the exam at any time, but to certify ISC2 requires five years of cumulative paid work experience in two or more of the eight domains. One year can be waived with a qualifying four-year degree or an approved credential, and candidates who pass without the full experience become an Associate of ISC2 while they earn it.
CISSP is an advanced exam aimed at experienced practitioners. It rewards management-level judgment and breadth across the whole security program: most questions describe a situation and ask for the BEST decision, and several of the wrong choices are usually reasonable. Candidates with hands-on experience across several domains tend to find the reasoning familiar; others need to practice thinking like a manager rather than a technician.
Work through the official CISSP exam outline, use a structured CISSP study guide, and consider an accelerated CISSP Certification Boot Camp that includes the exam voucher and a free retake if you need it. Practice questions help you get used to the exam's think-like-a-manager framing.