CISSP Certification Guide / Chapter 2
The CISSP Exam Blueprint and the Eight Domains
The public CISSP exam outline and its current domain weights, how the adaptive exam runs and stops, what proficiency and compensatory scoring mean, and the manager-perspective decision hierarchy that turns blueprint knowledge into answers.
Read the instrument before you touch it
Most candidates study the eight domains long before they study the machine that measures them, and that order is backwards. The CISSP is a computerized adaptive test with a fixed passing standard, delivered against a public outline that ISC2 publishes and revises. If you know exactly how that machine runs, a surprising share of exam-day anxiety evaporates, because the questions candidates dread, “how hard is this item?”, “is the exam ending too early?”, “did a short session mean failure?”, all have mechanical, published answers.
The contract is the CISSP Certification Exam Outline, effective April 15, 2024. ISC2 publishes it as a PDF in every exam language, and it is the closest thing to a syllabus the certification has. The outline names the eight domains, assigns each an average weight, and breaks each domain into numbered objectives with the subtopics the exam may touch. The adaptive exam is constructed from that outline: ISC2’s published description of its computerized adaptive testing says the content of every CAT exam complies with the domain weights stated in the outline, regardless of how long your particular exam runs. Nothing on the exam is outside the outline, and anything in the outline is fair game.
Two properties of the outline shape how you should study. First, it is the syllabus, not a rumor: if a topic is absent from it, it cannot cost you points. Second, it is versioned: each revision carries an effective date, so the weights in older books and forum posts can drift out of date. The numbers in this chapter come from the April 15, 2024 outline, the version in force when this book was written. If you are reading this after ISC2 publishes a newer outline, pull the current PDF and re-check the weights. The differences are usually small, and knowing where to look is the point.
How the adaptive exam actually runs
The exam is delivered by Pearson VUE at Pearson Professional Centers and ISC2-authorized Pearson VUE Select test centers, in Chinese, English, German, Japanese, and Spanish. The facts that govern your session are public and worth memorizing.
| Fact | Value |
|---|---|
| Delivery | Computerized Adaptive Test (CAT) |
| Time | 3 hours maximum; breaks count against the clock; there is no minimum time |
| Items | 100 to 150, selected adaptively |
| Item types | Multiple choice and advanced item types |
| Unscored items | 25 pretest items inside the minimum length; you cannot tell them apart from scored items |
| Graded minimum | 75 scored (operational) items plus the 25 pretest items |
| Passing standard | 700 out of 1000 on the scaled score |
| Result | Pass or fail, available immediately at the test center; no numerical score is reported |
| Item review | None: you cannot skip, return to, or change a finalized answer |
The mechanics behind that table matter more than the table itself. The exam opens with an item well below the passing standard, and from then on every answer feeds the scoring engine. After each response, the engine re-estimates your ability from the difficulty of everything you have seen and how you answered it, then selects the next item so that you have roughly a fifty-fifty chance of answering it correctly. That is why the exam feels hard throughout, even for strong candidates: it is calibrated to feel challenging at your level, whatever your level is. Feelings of difficulty are information for the engine, not verdicts for you.
The engine stops the exam under one of three rules, applied in order. First is the confidence interval rule: once you have answered the minimum 100 items, the exam ends as soon as the estimate of your ability excludes the passing standard with 95 percent statistical confidence. That rule ends most exams. Second is the maximum-length rule: if confidence has not been reached, the exam runs to 150 items, and the final estimate is compared to the standard. Third is the run-out-of-time rule: if the clock expires first, the final estimate decides, and if you have not answered the minimum 75 scored items plus the 25 pretest items by then, you fail automatically.
Because difficulty adapts, the exam cannot let you review. You cannot skip a question, return to a flagged one, or change a finalized answer, so the only time you have with an item is the time you spend on it the first time. The items do not arrive in sections or in any fixed order: the selection algorithm draws them to satisfy the outline’s domain weights, which means your fortieth question can come from any of the eight domains. None of this is a trick. It is the price of a test that stops exactly when it knows your level.
The mechanics hand you three concrete rules for exam day. Answer everything: a blank answer is a wrong answer, and the pretest items must be answered to reach the graded minimum even though they do not score. Hold a steady pace: 100 items in 180 minutes is 1.8 minutes per item, and 150 items is 1.2 minutes per item, so plan on about a minute and a quarter per item and check the clock at the 50-item mark. And never read meaning into length: an exam that stops at 101 is a pass when the engine found your level quickly, an exam that runs to 150 is simply one where confidence took longer, and both lengths can end either way. The only reliable signal is the pass or fail printed when the session ends.
The retake arithmetic is public too: after a first attempt you may retest after 30 test-free days, after a second attempt after 60 days, and after a third or later attempt after 90 days, with at most four attempts per program in any 12-month period. Plan as if you will pass on the first attempt, but know the schedule exists so that a failed attempt is a plan, not a surprise.
What the exam measures
The passing standard is fixed and published: 700 out of 1000 on ISC2’s scaled score. The exam is criterion-referenced, which means your result depends on your ability measured against that standard, not on how the other candidates in the testing center performed. There is no curve, no quota, and no competition between candidates. The person in the next seat is irrelevant to your result, which is exactly how a professional credential should behave.
Scoring is compensatory. A single pass or fail is computed over all the operational items you answer, and ISC2 states plainly that a candidate does not need to score above the proficiency level in every domain to pass: strong performance in a heavily weighted domain can offset weaker performance in a lightly weighted one. Failing candidates receive domain-level feedback labeled below, near, or above proficiency, precisely so the next attempt can target the right material. Passing candidates receive none of that detail, only the pass.
The design choices hidden in those rules matter on exam day. If you hit a rough stretch of items from a domain you dislike, the compensatory rule says your outcome is still one number, so one bad stretch is not a verdict. After a fail, the proficiency feedback is the closest thing to a diagnostic the exam offers, and the score rules in Chapter 1 tell you how to spend it: below-proficiency domains go through the re-read, redo, retest loop, near-proficiency domains get targeted maintenance, and above-proficiency domains get spaced review.
There is one more layer beneath the scoring that candidates routinely forget. The outline grounds the entire exam in five security principles, which it calls the five pillars: confidentiality, integrity, availability, authenticity, and nonrepudiation. Almost every scenario question is, at bottom, asking which pillar is at risk and which control protects it. When you read a question and cannot see the pillar underneath it, you have not understood the question yet.
The eight domains and their weights
ISC2 publishes an average weight for each domain: the share of items on the exam drawn from that domain’s objectives. The weights below come from the April 15, 2024 outline and total 100 percent. If you see different numbers in older books and posts, Domain 1 at 15 percent and Domain 8 at 11 percent, for example, those are the figures from the previous outline. The current weights are the ones that matter, and the direction of the change is instructive: the governance domain grew and the software domain shrank.
| Domain | Weight | What it tests |
|---|---|---|
| 1. Security and Risk Management | 16% | Governance, ethics, law and privacy, policy, risk, continuity, personnel, supply chain |
| 2. Asset Security | 10% | Classification, ownership, handling, data lifecycle, retention and disposal |
| 3. Security Architecture and Engineering | 13% | Design principles, security models, cryptography, secure platforms, physical security |
| 4. Communication and Network Security | 13% | Network architecture and protocols, segmentation, secure channels, network attacks |
| 5. Identity and Access Management | 13% | Identification and authentication, authorization models, lifecycle, federation |
| 6. Security Assessment and Testing | 12% | Test strategies, vulnerability and penetration testing, data collection, auditing |
| 7. Security Operations | 13% | Monitoring, investigations, incident response, resilience, physical operations |
| 8. Software Development Security | 10% | Secure SDLC, development ecosystems, acquired software, secure coding |
Domain 1, Security and Risk Management, is the exam’s center of gravity and the one most likely to surprise hands-on engineers. It covers the ISC2 Code of Professional Ethics and organizational ethics, governance structures that align security to business strategy, legal and regulatory obligations including privacy regimes such as the GDPR, the policy hierarchy of policy, standard, procedure, and guideline, investigations in their administrative, criminal, civil, and regulatory forms, business continuity analysis, personnel security across hiring and exit, risk management from identification through treatment, threat modeling, supply chain risk, and awareness and training programs. If you want one reason engineers underperform here, it is that they treat governance as paperwork instead of as the set of decisions that make technical work legal, funded, and repeatable.
Domain 2, Asset Security, is the shortest domain and a gift to the organized candidate. It asks who owns information, how it is classified, how it may be handled in each of its states (in use, in transit, at rest), how its lifecycle runs from collection through retention to remanence and destruction, and how controls such as data loss prevention, digital rights management, and cloud access security brokers are scoped and selected.
Domain 3, Security Architecture and Engineering, is where the exam goes deepest technically. Design principles such as least privilege, defense in depth, fail securely, and zero trust meet formal security models such as Bell-LaPadula and Biba, then cryptography and key management, then the security capabilities and weaknesses of real platforms: servers, databases, cloud services, containers, IoT, industrial control systems, and embedded devices. Site and facility security closes the domain, because a data center you cannot defend physically is a cryptography problem you have already lost.
Domain 4, Communication and Network Security, runs from the OSI and TCP/IP models up through secure protocols such as IPsec, SSH, and TLS, across segmentation from VLANs to micro-segmentation, through wireless and cellular networks and software-defined networking, and into the secure channels a business actually uses: remote access, VoIP and collaboration, and third-party connections. Expect questions that name a protocol and ask what it protects, and questions that name a trust boundary and ask where to draw the line.
Domain 5, Identity and Access Management, is the plumbing beneath every other domain. The exam covers the identification, authentication, authorization, and accountability chain, authentication factors and multi-factor authentication, authorization models from discretionary and mandatory access control through role-based, attribute-based, and risk-based control, federation and single sign-on, and the full provisioning lifecycle from onboarding to deprovisioning, including privileged access and service accounts.
Domain 6, Security Assessment and Testing, asks how you know the controls work. Strategy comes first: internal, external, and third-party testing, and where each one runs. Then the techniques: vulnerability assessment, penetration testing with red, blue, and purple teams, log reviews, synthetic transactions, code review, and misuse case testing. The domain also owns the evidence side: collecting process data, analyzing test output, reporting results, and conducting audits.
Domain 7, Security Operations, is the most applied domain and the book’s longest part. It spans investigations and digital forensics, logging and monitoring with SIEM and threat intelligence, configuration and change management, incident response from detection through lessons learned, recovery strategies and disaster recovery testing, business continuity exercises, the detection and prevention toolkit of firewalls, IDS/IPS, honeypots, and sandboxes, patch and vulnerability management, physical security, and personnel safety including travel and duress.
Domain 8, Software Development Security, asks how software is built, bought, and run securely. It covers development methodologies from waterfall to agile to DevSecOps, maturity models, the development ecosystem of CI/CD pipelines, repositories, and application security testing in its static, dynamic, interactive, and composition analysis forms, the risks of acquired software from commercial packages to open source to managed services, and secure coding standards for source code and APIs. The domain has grown steadily in importance as software has eaten the enterprise, even as its exam weight ticked down in the current outline.
The weights should drive your study calendar the way they drive the exam’s question draw. On a 125-item practice run, the weight math is simple: Domain 1 is roughly 20 items and Domain 8 roughly 13. No domain can be skipped, because the outline expects competence in all eight, but a 10 percent domain earns fewer hours than a 16 percent one, and the practice tests in this book mirror the weights so your score sheet stays honest.
The manager-perspective decision hierarchy
The eight domains are the what. The decision hierarchy is the how. This book’s method, set out in Chapter 1, assumes the exam rewards the judgment of an accountable security manager, and Chapter 1 promised that this chapter would build that intuition into a complete tool. Here it is: work a question through these levels in order, and you will almost always land on the answer a well-run organization would actually implement.
-
People before property. Safety of life outranks every asset. A question about evacuation, duress, or life safety has exactly one first answer, and it is not “save the data.”
-
Name the risk. Before choosing a control, name the asset, the threat, the vulnerability, the likelihood, and the impact. When two answers are both defensible, the one that reflects a correct risk identification usually wins. A control chosen without a named risk is a decoration.
-
Prevention over detection, detection over correction. Prefer the control that stops the event, but never choose a preventive control that leaves you blind: every prevention question expects you to pair it with detection and response. The hierarchy favors stopping the incident, then detecting it early, then recovering from it fast.
-
Least privilege and need to know. Grant the smallest set of rights that lets the work happen, and review it. Access granted “just in case” is risk without benefit.
-
Defense in depth. One control is a single point of failure. The hierarchy favors layered, independent controls: preventive, detective, and corrective; technical and administrative; physical and logical. When a question offers a second independent control, it is usually the answer.
-
Business alignment and cost-effectiveness. A control that costs more than the loss it prevents is a business loss in disguise, so weigh the control against the expected impact. But the math is never pure: safety, reputation, and regulatory exposure are qualitative impacts, and they routinely outweigh the spreadsheets.
-
Escalation and accountability. When residual risk remains after mitigation, the party accountable for the asset must accept it in writing. Risk acceptance is a management decision, documented and periodically reviewed. If a question asks who owns a risk you cannot eliminate, the answer is the risk owner at the level that can bear it, not the analyst who found it.
The tie-breaker sits above all seven levels: choose the answer a responsible manager would defend in front of the board. That sentence is not a slogan. It is the selection rule the exam uses when two technically correct options differ in judgment, and it resolves more borderline questions than any vocabulary list.
The question stems hand you the same rule in miniature, because their qualifiers are load-bearing. “Best” and “most” invite the strongest overall judgment call, the kind the hierarchy produces. “Least” points at the smallest safe step, usually least privilege or least disruption. “Should” asks what a reasonable manager would do. “Must” and “always” mark mandatory requirements, where a single non-negotiable obligation outranks a merely good idea. Read the qualifier before you read the scenario: it tells you which level of the hierarchy the question is testing.
See the hierarchy move through a classic question shape. A hospital’s billing system is hit by ransomware, and the attackers claim they exfiltrated patient records. The candidate’s options are to pay the ransom and restore, isolate the affected systems, rebuild everything from backups immediately, or do nothing until law enforcement arrives.
Level 1 says confirm that no person is endangered and keep patient-safety systems running; nothing in the scenario triggers an evacuation. Level 2 names the risk: encrypted systems plus possible theft of patient data, with breach-notification obligations under applicable law. Level 3 settles the main question: isolation contains the spread and preserves evidence, which is prevention serving detection, because you cannot know the blast radius while the infection can still move. Rebuilding from backups immediately looks decisive but can destroy evidence and may restore from infected images; paying funds the adversary and buys no guarantee, and paying is widely discouraged in government and industry guidance; doing nothing leaves the infection spreading. Level 4 and 5 add texture: emergency access for the incident team only, and containment layered at the network and host levels. Level 6 explains why the payment option is not a control at all: it transfers money, not risk. Level 7 routes breach notification and any acceptance decisions to legal and executive management.
The hierarchy picks isolation first, with evidence preservation and notification to follow. That is not only the right incident response, it is the answer pattern the exam rewards, and Chapter 26 builds it into the full incident response lifecycle.
Using the blueprint in your study loop
This book’s ten parts follow the outline in study order. Part I is orientation. Parts II through IX map one-to-one onto the eight domains, each ending in a 25-question practice test. Part X carries the exam strategy chapter and the full practice exam, a 125-item run built at the current blueprint weights, which mirrors a mid-length adaptive session: the real exam can stop at 100 items or run to 150, so 125 is a fair training distance either way.
Two habits keep the blueprint honest in your head. First, log every practice result by domain and feed the triage loop from Chapter 1. The exam itself is compensatory, but your study plan should not be, because a weak domain costs you its items whether or not another domain saves the overall pass. Second, re-read the outline’s objective list for your weak domains after each practice test. The outline is the source the questions are drawn from, and reading its objectives is the cheapest way to find vocabulary you have been glossing over. When a domain test shows a pattern of misses, find the objective that matches those questions and redo that material before your next session.
The blueprint also gives you a shared vocabulary for grading yourself. The exam’s own feedback labels are below, near, and above proficiency. Use them on your practice results: a near-proficiency domain is a maintenance problem, a below-proficiency domain is a re-read, redo, retest problem. Chapter 1’s 60 percent practice threshold is the same triage in a different dialect.
Practice questions
-
A manager has eight weeks before the exam. The score sheet shows Domain 1 at 55 percent, Domain 6 at 70 percent, and Domain 8 at 74 percent. Which plan best matches the blueprint and the triage rules?
A. Split time evenly across the three domains so nothing slides further. B. Put Domain 1 first with the largest time block, and give Domains 6 and 8 lighter maintenance passes. C. Re-read Domain 6 first because assessment testing is the most practical domain. D. Drop Domain 8 practice entirely since it has the smallest weight.
-
A candidate’s adaptive exam stops at 104 items and reports a pass. What does the short length most likely indicate?
A. The engine reached 95 percent confidence that the candidate’s ability was above the passing standard shortly after the minimum length. B. The candidate answered a run of easy items, so the engine raised the passing standard. C. The candidate correctly answered all 25 pretest items, which closed the exam early. D. The engine always stops at the first item count divisible by four.
-
Which behavior is impossible on the CISSP CAT?
A. Answering every item, including the 25 pretest items. B. Skipping a question and returning to it after answering others. C. Taking a break that counts against the three-hour clock. D. Receiving the pass or fail result at the test center.
-
Which statement about the exam’s 25 pretest items is true?
A. They are always the first 25 questions of the exam. B. They are easier than the scored items, so they are good warm-up material. C. You cannot tell them apart from scored items, and you must answer them to reach the graded minimum. D. Correct answers to pretest items earn bonus points toward the scaled score.
-
A candidate finishes an exam with strong performance in Domain 1 and weak performance in Domain 6. Which statement about the outcome is accurate?
A. The exam is scored per domain, and the candidate must pass each domain independently. B. A single pass or fail is computed over all operational items, so strength in a heavily weighted domain can offset weakness elsewhere. C. Weakness in any domain automatically produces a fail at the minimum length. D. Domain 6 items are removed from scoring for that candidate.
-
A manufacturer’s production systems are encrypted by ransomware, and the attackers threaten to publish stolen engineering data. Which first response best matches the manager-perspective decision hierarchy?
A. Pay the ransom immediately to restore production and stop the disclosure. B. Rebuild the affected systems from backups without further analysis to minimize downtime. C. Isolate the affected systems to contain the spread, preserve evidence, and activate the incident response plan. D. Leave the systems running while legal investigates, so the attackers see no response.
-
A support analyst requests administrative access to the payroll system “just in case” a manager needs help during month-end. Which decision matches the hierarchy?
A. Grant the access permanently, because the request is preventive. B. Deny the request outright, because no one outside payroll should ever touch it. C. Scope the access to the specific task window, grant the minimum needed, and review it after month-end. D. Grant it and document that the analyst accepted the risk.
-
After controls are applied, a project retains residual risk that the CISO considers unacceptable. Who should accept the residual risk, and how?
A. The CISO, informally, because the security team found the risk. B. The accountable business owner, with the acceptance documented, dated, and reviewed. C. The insurer, by paying a premium that transfers the risk. D. The vendor who sold the system, by contract.
Answers and rationales
-
B. Domain 1 carries the largest weight on the exam (16 percent) and sits below the 60 percent practice threshold, so the triage loop sends it through re-read, redo, retest first, and weight sizes the time block. Even time ignores weight, re-reading Domain 6 first is wrong because it is already above threshold and is a maintenance problem, and dropping Domain 8 abandons a 10 percent slice of the blueprint when the outline expects competence in all eight domains.
-
A. The confidence interval rule ends the exam once the ability estimate excludes the passing standard with 95 percent confidence after the minimum 100 items, so a pass at 104 items means the engine found the candidate’s level quickly. Easy items do not raise the passing standard, which is fixed and published; pretest items do not affect scoring decisions; and the engine has no arithmetic stop rule.
-
B. The CAT does not permit item review, so skipping and returning cannot happen; you answer each item once and move on. The other three behaviors describe the exam accurately: pretest items must still be answered, breaks count against the three-hour clock, and the result is available immediately.
-
C. ISC2 states that pretest items are unscored and indistinguishable from operational items, and that a candidate who fails to answer the minimum 75 scored items plus the 25 pretest items fails automatically. They are not grouped at the front, not labeled as easier, and not worth points.
-
B. ISC2 describes its exams as compensatory: one pass or fail is computed over all operational items, with no requirement to score above the proficiency level in every domain. Independent per-domain passes do not exist, weakness in one domain alone does not produce a fail, and no items are removed for any candidate.
-
C. The hierarchy puts containment and evidence preservation first: isolation prevents further spread and keeps the investigation possible, while recovery and notification follow as accountable, documented steps. Paying funds the adversary and buys no guarantee, rebuilding immediately can destroy evidence and may restore from infected images, and inaction lets the incident expand.
-
C. Least privilege grants the smallest working set that lets the work happen and reviews it, so a temporary, scoped grant serves the business without creating standing access. Permanent “just in case” access is unnecessary risk, an outright denial ignores a legitimate business need, and an analyst cannot accept risk on the organization’s behalf: acceptance is an accountable management decision.
-
B. Residual risk that cannot be mitigated is accepted by the party accountable for the asset or operation, and the acceptance is documented, dated, and periodically reviewed. The CISO advises but does not silently accept risk for the business; insurance transfers financial exposure, which is a legitimate risk treatment but not acceptance of what remains; and a vendor rarely accepts your residual risk by default.
The blueprint on one page
When the anxiety spikes, come back to this. The exam is an adaptive instrument with a published standard: 3 hours, 100 to 150 items, 25 of them pretest, graded on 75 or more scored items against a fixed passing standard of 700 out of 1000, with a single compensatory pass or fail and no numerical score. It stops when it is 95 percent confident, when it reaches 150 items, or when the clock runs out, whichever comes first, and it never lets you revisit an answer.
The outline is the syllabus: eight domains at 16, 10, 13, 13, 13, 12, 13, and 10 percent, grounded in the five pillars of confidentiality, integrity, availability, authenticity, and nonrepudiation. Study time follows the weights, and every chapter of this book maps to one of those domains.
And when a question has you stuck between two defensible answers, run the hierarchy: people first, name the risk, prevention over detection, least privilege, defense in depth, cost-effective and business-aligned, escalate what you cannot accept, and if it is still a coin toss, choose the answer a responsible manager would defend in front of the board. The domains give you the material; the hierarchy gives you the judgment. You need both, and from here the book spends a part on each.
Continue reading
Full table of contents