← Back to catalogue
Certification preparation

CISSP: security, risk, and operations

Prepare for CISSP through eight domains, security decisions, and banking management and operations scenarios.

ISC2Available
ISC2CIS8 lessons
Outline effective April 15, 2024, with current AI guidance integrated across eight domains. CAT exam in all languages: 100–150 items, 180 minutes, and official 700/1000 score, not equivalent to 70% correct answers. Chinese has limited booking windows; variant not inferred. Certification requires experience and other ISC2 conditions; passing the exam or completing DR does not alone award CISSP..

Objectives and progression

Eight lessons, 50 regular questions, and eight original cases with an internal 32-decision assessment in 50 minutes. First pass through eight domains of the outline effective April 15, 2024, including current guidance integrating AI across those domains. Fictional banking examples connect governance, assets, architecture, networking, IAM, assessment, operations, and software. Independent preparation; this fixed assessment neither reproduces CAT nor estimates an official score.

Audience: Security professionals, APS/L3 teams, architects, and technical managers responsible for services and risk.

Prerequisites: IT experience and security fundamentals. CISSP certification requires experience under ISC2 rules, normally five years across at least two domains with a maximum eligible one-year waiver. Passing the exam without experience may permit the Associate of ISC2 pathway; completing DR grants neither status.

290 estimated study minutes

  • Connect controls to objectives, impact, and decision authority.
  • Maintain protection and accountability when data changes format or location.
  • Design protection for normal conditions and concrete failures.
  • Distinguish reaching a resource, protecting a channel, and being allowed to perform an operation.
  • Manage access from onboarding through effective revocation.
  • Form conclusions matching what was actually tested.
  • Coordinate containment and continuity with measurable recovery criteria.
  • Integrate security requirements into design, pipeline, and acceptance.

Modules

  1. Governance, ethics, and risk decisions
  2. Assets, data, and decommissioning
  3. Architecture, cryptography, and common failures
  4. Networks, channels, and access boundaries
  5. Identity, sessions, and privileges
  6. Assessment, testing, and evidence limits
  7. Operations, incidents, and recovery
  8. Secure software and supply chain

Continue learning

Cybersecurity

References and version

CISSP outline effective April 15, 2024; current AI guidance consulted 2026-09-29

What you will explore

0 / 8

Learning is also trying.

Original explained questions, flashcards, and scenarios to apply the concepts.

Practice
This module covers foundations. It is not a complete certification course or a full simulation of the official exam.

Exam domains

Security and Risk Management16%
Asset Security10%
Security Architecture and Engineering13%
Communication and Network Security13%
Identity and Access Management (IAM)13%
Security Assessment and Testing12%
Security Operations13%
Software Development Security10%