Intense 5 full days CISSP classes with the Official ISC2 training materials and books
The CISSP Exam FAQ is a series of questions gathered by CISSP.com to help prospective CISSPs in getting a better idea about the exam and what to expect. If you like to share your thoughts and add to this FAQ, please email us your comments and we will add them
The CISSP exam cost is $549.00 if you submit your registration 16 days or more in advance of the test date. If you register 15 days or less before the exam date, then you pay $599.00
What does the CISSP examination consist of?
The CISSP exam is a 250 question English language examination. Candidates are given 6 hours to complete the exam although most complete it in about 4 hours.
Are there different versions for each country?
No, the test is based on Internationally accepted information security standards and practices. There are no country specific questions or language. The same English language version is given throughout the world.
What do the questions cover?
The CISSP Certification examination consists of 250 multiple-choice questions. Candidates have up to 6 hours to complete the examination. Examination questions cover all ten domains in the Common Body of Knowledge (CBK). Questions are "scrambled" on the examination, they are not presented in domain order. The domains are:
- Access Control Systems & Methodology
- Applications & Systems Development
- Business Continuity Planning
- Cryptography
- Law, Investigation & Ethics
- Operations Security
- Physical Security
- Security Architecture & Models
- Security Management Practices
- Telecommunications, Network & Internet Security
- Security Management Practices
Are the pre-test questions identified?
No. They are scrambled into the examination along with the scored items.
What type of questions are there?
All test questions are multiple choice with four possible answers. They are designed to test a candidate's knowledge of information security facts and concepts and their application.
How hard is the examination?
The examination tests the expected knowledge a 3-5 year practitioner should have. It is designed to test for the minimum level of competency acceptable for someone to be certified as an information systems security professional. A knowledgeable candidate should not find the examination difficult.
If the examination isn't particularly difficult, why don't more people pass it?
What makes the examination difficult is the expansive knowledge base it covers. It's difficult to develop expertise in all ten domains.
Are the questions in the Study Guides really representative of examination questions?
The study guides questions are good examples of the format and type of questions you would see on the exam but are not necessarily representative of the difficulty.
Which domains are the hardest?
The domains that are not commonly used in every day security management such as cryptography, system architecture, and physical security usually score the lowest.
How current is the CISSP examination?
Each year between 100 and 150 new questions are added to the question pool, many are based on new security technologies. You can expect to find questions on current technologies, practices and standards.
How detailed are the questions, what depth of knowledge is being tested?
The CISSP examination is designed to evaluate the ability of a security manager, engineer or architect to properly evaluate, select, deploy and assess security measures. A candidate should have a detailed enough knowledge of security designs, measures, vulnerabilities, etc. to successfully accomplish these tasks.
What's the CISSP Examination passing score?
There is no fixed passing score for the examination. The cut score for each examination is calculated by equating the scoring values associated with each question. Passing rates estimated to be in the 70% to 80% range. Less than 8% of those tested achieve scores higher than 85%.
















