CISSP Study Guide — 2026 Edition cover

CISSP — Certified Information Systems Security Professional · 2026 Edition

CISSP Study Guide — 2026 Edition

Organized by the eight domains of the ISC2 CISSP exam outline effective 15 April 2024: 250 original questions with worked explanations and a 150-question practice exam.

  • 250 original CISSP practice questions, each with a worked explanation, in one PDF + EPUB you keep

PDF + EPUB · English · 154 pages · $24.99 one-time

This book is written in English.

Instant download after payment — no account needed, no subscription.

14-day money-back guarantee: not satisfied for any reason? Email support@preppass.org within 14 days of purchase for a full refund. Refund policy

Read a free sample chapter first

Not ready to buy?

Try 10 questions first — free

Answer all 10, then see every answer explained — with the section of this guide that teaches it. About 5 minutes, no sign-up.

Start 10 free questions

Look inside the book

Three real pages, rendered straight from the PDF you download — a reference page, a teaching page, and a worked question, always in that order. Nothing here was redrawn to look better.

  • Quick reference
    Appendix B — Glossary of key terms · PDF page 146

    A page you can turn back to: the numbers, deadlines or terms gathered in one place.

  • How it's taught
    Chapter 5 — Identity and Access Management · PDF page 53

    An explanation page: the material taught in prose, in the order the exam tests it.

  • A question, worked
    Chapter 5 — Identity and Access Management · PDF page 52

    A practice question with its answer and the reasoning behind it — not just a key.

About the exam itself

Certified Information Systems Security Professional (CISSP) — Exam facts
Administering bodyISC2 — exam delivered by Pearson VUE

Source: ISC2 — CISSP Certification Exam Outline (Effective Date: April 15, 2024)

Questions100–150 questions

Source: ISC2 — CISSP Certification Exam Outline (Effective Date: April 15, 2024)

Time limit180 minutes

Source: ISC2 — CISSP Certification Exam Outline (Effective Date: April 15, 2024)

Passing scoreISC2 points: 700 of 1,000 points

Source: ISC2 — CISSP Certification Exam Outline (Effective Date: April 15, 2024)

Fees
  • $749 — Standard registration (Americas, Asia Pacific, Middle East, Africa) (ISC2, per attempt)

Source: ISC2 — ISC2 Exam Pricing

Languages offeredChinese · English · German · Japanese · Spanish

Source: ISC2 — CISSP Certification Exam Outline (Effective Date: April 15, 2024)

Exam facts, with a source for every line

Questions buyers ask

Which outline is the CISSP — Certified Information Systems Security Professional exam based on?
CISSP Certification Exam Outline, in force from 2024-04-15. Check ISC2 for the current outline before you book.
Is a study guide enough for the CISSP — Certified Information Systems Security Professional exam, or do I need a course?
Check eligibility first — per ISC2: candidates need at least five years of cumulative, full-time experience in two or more of the eight CISSP domains; a relevant bachelor's or master's degree or an ISC2-approved credential can satisfy one year of it. A candidate without the experience can pass the exam to become an Associate of ISC2 and then has six years to earn the five years of experience. A book does not replace those requirements. For the exam content itself, this 154-page guide teaches the material chapter by chapter with 250 practice questions and explanations inside, and 122 more practice questions are free on PrepPass. A prep course adds live instruction and a set schedule; whether you need one beyond any required education is your call.
What is the cheapest way to prepare for the CISSP — Certified Information Systems Security Professional exam?
Start with what costs nothing: 122 practice questions on PrepPass, with explanations and no signup. If you want it taught in one file you keep, the full study guide is $24.99 once. No subscription on any of them.
What happens if I fail the CISSP — Certified Information Systems Security Professional exam?
You can retake it under ISC2's rule: after a first attempt you may retest after 30 test-free days, after a second after 60, and after a third or any later attempt after 90. You may attempt the CISSP at most 4 times within a 12-month period. Confirm the current policy with ISC2 before you book.
Who administers the Certified Information Systems Security Professional (CISSP)?
ISC2 — exam delivered by Pearson VUE. The current CISSP exam outline took effect on April 15, 2024. Its eight domains are weighted: Security and Risk Management 16%, Asset Security 10%, Security Architecture and Engineering 13%, Communication and Network Security 13%, Identity and Access Management (IAM) 13%, Security Assessment and Testing 12%, Security Operations 13%, Software Development Security 10%. The exam is taken at ISC2-authorized Pearson test centers.
How many questions are on the Certified Information Systems Security Professional (CISSP)?
100–150 questions. The CISSP uses Computerized Adaptive Testing (CAT), so the number of items a candidate sees varies within this range. Items are multiple choice and advanced item types.
How long is the Certified Information Systems Security Professional (CISSP)?
180 minutes
What is the passing score for the Certified Information Systems Security Professional (CISSP)?
ISC2 points: 700 of 1,000 points. ISC2 states the passing grade in points, not as a percentage of questions answered correctly. Because the exam is adaptive, the pass/fail decision rests on the candidate's estimated ability against the passing standard.
How much does the Certified Information Systems Security Professional (CISSP) cost?
$749 — Standard registration (Americas, Asia Pacific, Middle East, Africa) (ISC2, per attempt). ISC2 prices the exam in euros for the EU region and in pounds for the United Kingdom, and says pricing and taxes depend on where the exam is taken.
What languages is the Certified Information Systems Security Professional (CISSP) offered in?
Chinese · English · German · Japanese · Spanish. ISC2 offers the Chinese-language CISSP only in select appointment windows: March, June, September and December.
Does the CISSP — Certified Information Systems Security Professional study guide come as a PDF?
Yes — CISSP Study Guide — 2026 Edition downloads as PDF and EPUB, 154 pages. The download link is emailed the moment payment clears and does not expire.
How much does the CISSP — Certified Information Systems Security Professional study guide cost?
$24.99, once. There is no subscription and no account to create; the PDF and EPUB files are yours to keep.
Are there free CISSP — Certified Information Systems Security Professional practice questions?
Yes — 122 of them, free to use with no signup and an explanation on every one. They are separate from this study guide, which is what you are buying here.
Can I read part of the CISSP — Certified Information Systems Security Professional study guide before buying?
Yes. A full chapter is free to read on this page — not a summary of one, the chapter itself.
Is this the official CISSP — Certified Information Systems Security Professional study guide?
No. This is an independent study guide and is not affiliated with or endorsed by the exam's awarding body. It is written from ISC2's CISSP Certification Exam Outline (effective 15 April 2024), with NIST, IETF and U.S. federal primary sources. Always confirm current requirements with the body that issues your licence.

Free CISSP — Certified Information Systems Security Professional practice questions and study chapters →

What's included — and what isn't

Included

  • Eight chapters, one per domain of the ISC2 CISSP outline (effective 15 April 2024)
  • A quiz closing each chapter, with worked explanations
  • A 150-question practice exam at the published domain weights
  • 250 original questions, each explained and cited to its source
  • Sourced from NIST FIPS and SP publications, IETF RFCs and the ISC2 Code
  • PDF + EPUB you keep

Not included

  • No printed copy is shipped — this is a file you download and can print yourself
  • No video course, instructor or tutoring comes with the book — the free videos on the site are separate
  • Not your exam registration or the testing centre's fee, which you still pay to the official body

Contents

See 14 sections and the page each one starts on
  1. Chapter 1 — Security and Risk Managementp. 6
  2. Chapter 2 — Asset Securityp. 19
  3. Answer key & explanationsp. 24
  4. Chapter 3 — Security Architecture and Engineeringp. 27
  5. Chapter 4 — Communication and Network Securityp. 38
  6. Chapter 5 — Identity and Access Managementp. 47
  7. Chapter 6 — Security Assessment and Testingp. 56
  8. Chapter 7 — Security Operationsp. 64
  9. Chapter 8 — Software Development Securityp. 74
  10. Practice Exam — Domain 3: Security Architecture and Engineering (20 questions)p. 98
  11. Practice Exam — Domain 5: Identity and Access Management (20 questions)p. 114
  12. Appendix A — Exam-day referencep. 144
  13. Appendix B — Glossary of key termsp. 146
  14. Appendix C — Acronymsp. 148

Taken from the PDF you download, with the page each one starts on — not typed here.

Read a chapter free, in full

One complete chapter, exactly as it ships in the eBook. Scroll the window to read it right here; no download, no email.

Read chapter 1 here, without leaving the page
FREE SAMPLE — READ IT RIGHT HERE
Chapter 1 · ≈13 min read
Security and Risk Management
scroll ↓

Domain 1 carries the heaviest weight on the exam at 16%[1], and it sets the tone for everything after it: governance before technology, risk before controls, and the manager's view before the technician's. Read it as the person who will have to defend the program to executives, auditors, and regulators.

1.1 Professional ethics

ISC2's Code of Ethics has four mandatory canons: protect society, the common good, public trust, and the infrastructure[2]; act honorably, honestly, justly, responsibly, and legally[2]; provide diligent and competent service to principals[2]; and advance and protect the profession[2]. On the exam, when an ethics scenario pits loyalty to an employer against one of these duties, the canons outrank the employer's instructions — the first canon, protecting society, outranks them all.

1.2 Security concepts

The CIA triad — confidentiality, integrity, availability — is the vocabulary of the whole field, and FIPS 199 states the three objectives in the words of federal law: confidentiality means "preserving authorized restrictions on information access and disclosure, including means for protecting personal privacy and proprietary information"; integrity means "guarding against improper information modification or destruction, and includes ensuring information non-repudiation and authenticity"; and availability means "ensuring timely and reliable access to and use of information"[3, 4]. Related concepts the outline names here include threats, vulnerabilities, and risk: NIST defines risk as a function of the adverse impacts of an event and the likelihood it occurs[5]. Controls are the safeguards you select against that risk, and they come in families — NIST organizes its controls into 20 families[6].

1.3 Security governance principles

Governance is the system by which the organization's security is directed and controlled. NIST's Cybersecurity Framework puts a GOVERN function at the center: the organization's cybersecurity risk management strategy, expectations, and policy are established, communicated, and monitored[7]. In practice this means policies (management's high-level intent), standards (mandatory rules), procedures (step-by-step instructions), and guidelines (recommended practices) — and a board and executive team that own risk rather than delegating it away.

1.4 Legal, regulatory, and compliance issues

Several regimes appear repeatedly. The EU General Data Protection Regulation requires breach notification to the supervisory authority without undue delay and, where feasible, not later than 72 hours after becoming aware of a personal data breach[8], and its top tier of administrative fines reaches 20 million euros or 4% of worldwide annual turnover, whichever is higher[8]. In U.S. health care, the HIPAA Security Rule sets forth the administrative, physical, and technical safeguards that covered entities and business associates must put in place to secure electronic protected health information[9]. For payment cards, PCI DSS provides a baseline of technical and operational requirements designed to protect payment account data[10], applying to entities that store, process, or transmit cardholder data[10]. For software, copyright subsists in original works of authorship fixed in any tangible medium of expression[11], while fair use — for purposes such as criticism, comment, news reporting, teaching, scholarship, or research — is not infringement[12], judged on four factors including the purpose and character of the use and its effect on the market[12].

1.5 Investigation types

Administrative investigations address policy violations and support HR action; criminal investigations support prosecution and demand the strictest evidence handling; civil investigations support lawsuits between parties. The key exam distinction is the standard of handling: criminal matters require preserving chain of custody and involving law enforcement, because mishandled evidence is inadmissible. Never let an internal investigation contaminate a potential criminal case.

1.6 Security policy, standards, procedures, and guidelines

Policy states management's intent and assigns responsibility; standards set the mandatory rules that implement policy; procedures give the step-by-step instructions; guidelines offer recommended practices for situations where judgment applies. NIST's contingency planning guidance makes the same point about authority: a formal policy provides the authority and guidance necessary to develop an effective plan[13]. Write policies short, get executive sign-off, and review them on a schedule — an unsigned, unreviewed policy is decoration.

1.7 Business continuity requirements

Business continuity is about keeping the mission alive through disruption. The analysis that drives it is the business impact analysis: the BIA helps identify and prioritize information systems and components critical to supporting the organization's mission and business processes[13]. From the BIA come the recovery targets — how long you can be down and how much data you can afford to lose — and the strategies to meet them. Continuity planning starts with policy and the BIA before any technology is chosen.

1.8 Personnel security policies and procedures

People are part of the control set: background checks before hiring, least privilege from day one, mandatory vacations and job rotation to expose fraud, and a termination procedure that revokes access the same day. Personnel controls also include nondisclosure and noncompete agreements where lawful. The exam treats separation of duties and least privilege as personnel controls first and technical controls second.

1.9 Risk management concepts

Risk management is a cycle: assess, treat, monitor. NIST defines risk assessment as the process of identifying, estimating, and prioritizing information security risks[5], and risk itself as a function of adverse impact and likelihood[5]. Treatment options are the classic four: avoid, transfer, mitigate, or accept the risk. The Risk Management Framework gives this a formal seven-step shape — a preparatory step plus six main steps, all essential[14] — beginning with preparing to execute the RMF by establishing context and priorities[14] and categorizing each system based on the impact of loss[14]. Senior management formally accepts the leftover risk; that acceptance is what makes the program legitimate.

1.10 Threat modeling concepts and methodologies

Threat modeling is structured brainstorming about what can go wrong, done early enough to influence design. Methodologies decompose the system (data flows, trust boundaries, entry points), enumerate threats against each element, and rank them so design effort goes to the worst first. The output feeds directly into control selection: you don't buy controls and then look for threats, you model threats and then select controls.

1.11 Supply chain risk management

Modern systems are assembled from other people's components, so the supply chain is part of your attack surface. SCRM means vetting suppliers, demanding evidence of their secure development practices — NIST's SSDF gives acquirers a common vocabulary for exactly these conversations with suppliers[15] — and planning for supplier failure or compromise. Counterfeit components, tampered updates, and a vendor's breach becoming your breach are the scenarios to plan for.

1.12 Security awareness, education, and training

Awareness changes behavior across the whole workforce; education builds deeper understanding for those who need it; training builds job-specific skill. The program must be established and maintained — one annual slide deck is not a program — with role-based training for privileged users and developers, and metrics (such as phishing-simulation click rates) that show whether behavior is actually changing.

Key numbers

  • Exam: 3 hours, 100–150 items, pass at 700/1000[1]
  • Breach notification under GDPR: 72 hours to the supervisory authority[8]
  • Top GDPR fines: 20 million euros or 4% of worldwide annual turnover[8]
  • RMF: seven steps (one preparatory plus six main)[14]
  • NIST controls: 20 families[6]

Key takeaways

  • Domain 1 is the manager's domain: governance, risk, law, and ethics before technology.
  • The four ethics canons outrank any employer's instruction; protecting society comes first.
  • Risk is impact times likelihood; assessment identifies, estimates, and prioritizes.
  • The BIA identifies and prioritizes what the mission cannot lose, and it comes before recovery strategies.
  • When in doubt on the exam, choose the answer that manages risk at the program level rather than fixing one technical symptom.

Chapter 1 quiz — 16 questions

Answer each question, then check the key that follows.

1. A security manager discovers the company is quietly selling customer location data in a way that endangers domestic-violence victims. The CEO orders the manager to stay silent. What should guide the manager's decision first?

  • A. The duty to protect society and the common good
  • B. The manager's personal employment contract terms
  • C. The company's public privacy policy statements
  • D. The CEO's direct order, as the highest internal authority

2. Which definition best matches how NIST describes information security risk?

  • A. The difference between threats and vulnerabilities
  • B. A function of adverse impacts and likelihood of occurrence
  • C. The number of vulnerabilities found in the last assessment
  • D. The annual cost of all security controls in the program

3. The board asks what governance of cybersecurity actually requires of them. Which answer is most accurate?

  • A. Setting and monitoring risk strategy and policy
  • B. Reviewing penetration test reports line by line
  • C. Approving every firewall rule change personally
  • D. Delegating all security decisions to the IT department

4. A company discovers a breach of EU residents' personal data on Monday morning. By when must it notify the supervisory authority, where feasible?

  • A. Within 30 days of completing the investigation
  • B. Only after notifying affected individuals first
  • C. Within 24 hours of discovery
  • D. Within 72 hours of becoming aware

5. Under the GDPR's highest tier, administrative fines can reach which maximum?

  • A. 10 million euros or 2% of worldwide annual turnover
  • B. 1 million euros or 1% of worldwide annual turnover
  • C. 20 million euros or 4% of turnover
  • D. 50 million euros with no turnover alternative

6. A U.S. hospital is documenting its safeguards for patient records systems. Which rule's framework of administrative, physical, and technical safeguards applies?

  • A. The GDPR's data protection principles
  • B. The FedRAMP authorization baseline
  • C. The PCI Data Security Standard
  • D. The HIPAA Security Rule

7. A retailer that stores and processes payment card numbers wants the baseline of technical and operational requirements for protecting that data. Which standard provides it?

  • A. The CISSP exam outline
  • B. PCI DSS
  • C. NIST SP 800-53
  • D. ISO/IEC 27001

8. A developer copies a competitor's proprietary program into a new product. Under U.S. copyright law, what determines whether the program is protected?

  • A. Whether the program was registered before publication
  • B. Whether the program contains more than 1,000 lines of code
  • C. Whether it is an original work in a tangible medium
  • D. Whether the competitor sells the program commercially

9. A trainer wants to quote short passages of a copyrighted article in a security awareness course. Which factor is part of the fair-use analysis?

  • A. The number of students enrolled in the course
  • B. The trainer's job title and seniority
  • C. Effect on the work's potential market
  • D. Whether the article was published in the last year

10. An employee is suspected of stealing trade secrets, and prosecution is possible. What is the most important handling requirement for the evidence?

  • A. Preserving chain of custody so the evidence stays admissible
  • B. Confronting the employee immediately to get a confession
  • C. Deleting the employee's accounts before collecting anything
  • D. Publishing findings internally as a deterrent

11. Which document should state management's high-level intent for information security and assign responsibility for it?

  • A. A guideline
  • B. A procedure
  • C. A standard
  • D. A policy

12. Before buying backup infrastructure, a company wants to know which systems the mission cannot survive without and for how long each can be down. What should it conduct first?

  • A. A vulnerability scan of the data center
  • B. A business impact analysis
  • C. A penetration test of the backup systems
  • D. A code review of the recovery scripts

13. According to NIST, risk assessment is best described as which activity?

  • A. Installing controls to reduce all risks to zero
  • B. Identifying, estimating, and prioritizing information security risks
  • C. Documenting accepted risks for the auditors
  • D. Transferring risk to an insurance provider

14. An organization adopts the NIST Risk Management Framework. How many steps does it include?

  • A. Seven steps: a preparatory step plus six main steps
  • B. Four steps, one per risk treatment option
  • C. Twelve steps, one per control family
  • D. Five steps matching the CSF functions

15. A company buys most of its product's components from outside vendors. Which practice best addresses the resulting supply chain risk?

  • A. Buying only from the lowest-cost supplier in each category
  • B. Testing finished products once a year for defects
  • C. Keeping the supplier list secret from internal auditors
  • D. Requiring vendors to demonstrate secure development practices during acquisition

16. A phishing simulation shows 30% of staff clicking malicious links. What does a mature awareness program do next?

  • A. Block all external email to eliminate the threat
  • B. Punish the staff who clicked with formal warnings
  • C. Treat it as a metric and deliver targeted training
  • D. Run the same simulation monthly without any training

Answer key & explanations

1. A. The first canon requires protecting society, the common good, public trust, and the infrastructure[2] — that duty is what the manager's decision must serve first. The remaining canons then require acting honorably, honestly, justly, responsibly, and legally[2], providing diligent and competent service to principals[2], and advancing and protecting the profession itself[2].

2. B. NIST defines risk as a measure of the extent to which an entity is threatened by a potential circumstance or event, typically a function of the adverse impacts that would arise and the likelihood of occurrence[5]. Cost of controls, vulnerability counts, and threat-vulnerability arithmetic are not the definition. Risk assessment is the separate process of identifying, estimating, and prioritizing information security risks[5] — the mechanism that produces the likelihood-and-impact judgments the definition calls for.

3. A. The GOVERN function is defined as establishing, communicating, and monitoring the organization's cybersecurity risk management strategy, expectations, and policy[7]. Boards govern through strategy and oversight, not by approving individual technical changes or reviewing raw test output. The CSF organizes all cybersecurity outcomes at their highest level into six Core Functions — GOVERN, IDENTIFY, PROTECT, DETECT, RESPOND, and RECOVER[7] — with GOVERN setting the strategy that the other five execute.

4. D. GDPR Article 33 requires notification to the supervisory authority without undue delay and, where feasible, not later than 72 hours after becoming aware of the breach[8]. Waiting for the investigation to finish or notifying individuals first does not satisfy the deadline. Breaches at this scale also expose the company to the top fine tier — up to 20 million euros or 4% of worldwide annual turnover[8] — which is why the clock starts at awareness, not at the end of the investigation.

5. C. The top tier of GDPR administrative fines is up to 20 million euros or, for an undertaking, up to 4% of total worldwide annual turnover of the preceding financial year, whichever is higher[8]. The lower 10 million / 2% tier applies to a different set of infringements. The same regulation separately imposes the 72-hour breach notification duty[8], framing all of this as protecting a fundamental right — the protection of natural persons in relation to the processing of personal data[8].

6. D. The HIPAA Security Rule sets forth the administrative, physical, and technical safeguards that covered entities and business associates must put in place to secure electronic protected health information[9]. PCI DSS covers payment cards, not patient records. The rule's protected object is electronic protected health information — PHI maintained in or transmitted by electronic media[9] — so the first scoping question is always whether the system handles ePHI at all.

7. B. PCI DSS provides a baseline of technical and operational requirements designed to protect payment account data[10], and its intended audience is entities that store, process, or transmit cardholder data[10]. ISO 27001 and SP 800-53 are general control frameworks, not the card-data baseline. The distractors name real frameworks, but neither is scoped to cardholder data: ISO 27001 is a general ISMS standard and SP 800-53 a federal control catalog, while PCI DSS exists specifically for the payment-card baseline.

8. C. Copyright protection subsists in original works of authorship fixed in any tangible medium of expression[11]. Registration, length, and commercial sale are not the test for whether protection exists. The owner's exclusive rights include reproduction of the work[16], so copying the program infringes regardless of registration; fair use remains only a limited defense, judged by factors including the purpose and character of the use[12].

9. C. The four fair-use factors include the effect of the use upon the potential market for or value of the work, alongside the purpose and character of the use, the nature of the work, and the amount used[12]. Job title, publication recency, and class size are not factors. Protection itself subsists in original works fixed in a tangible medium[11], and the owner's exclusive rights include reproduction[16] — fair use is the limited exception to those rights, not the default.

10. A. Criminal investigations support prosecution, so evidence must survive legal challenge: NIST's incident handling guidance says evidence should be accounted for at all times, with chain of custody forms detailing every transfer[17]. Confronting the suspect, deleting accounts, or publicizing findings all risk contaminating the case the prosecution depends on. The response lifecycle itself runs preparation, detection and analysis, containment, eradication and recovery, and post-incident activity[17] — evidence discipline sits inside that structure, which is why improvising outside it destroys the case.

11. D. A security policy is "a definite goal, course, or method of action to guide and determine present and future decisions concerning security in a system"[18] — management's high-level intent, which is why it is the document that assigns responsibility. A standard is the tempting wrong answer: it sets mandatory specifics (an approved algorithm, a baseline) that implement the policy, not the intent itself. Procedures give the steps and guidelines advise; NIST's contingency guidance makes the same point about authority, noting that a formal policy "provides the authority and guidance" for the plans beneath it[13].

Sources cited in this excerpt

  1. ISC2 CISSP Certification Exam Outline. https://www.isc2.org/certifications/cissp
  2. ISC2 Code of Ethics. https://www.isc2.org/ethics
  3. FIPS 199, Standards for Security Categorization of Federal Information and Information Systems. NIST. https://csrc.nist.gov/pubs/fips/199/final
  4. FIPS 199, Standards for Security Categorization of Federal Information and Information Systems. NIST. https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.199.pdf
  5. NIST SP 800-30 Rev. 1, Guide for Conducting Risk Assessments. https://csrc.nist.gov/pubs/sp/800/30/r1/final
  6. NIST SP 800-53 Rev. 5, Security and Privacy Controls. https://csrc.nist.gov/pubs/sp/800/53/r5/final
  7. NIST Cybersecurity Framework (CSF) 2.0. https://www.nist.gov/cyberframework
  8. Regulation (EU) 2016/679 (GDPR), official text, EUR-Lex. Publications Office of the European Union. https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679
  9. 45 CFR Part 164, Subpart C — Security Standards for the Protection of Electronic Protected Health Information (eCFR). U.S. HHS / eCFR. https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C
  10. PCI Security Standards Council — PCI DSS. https://www.pcisecuritystandards.org/standards/pci-dss/
  11. 17 U.S.C. § 102, U.S. Copyright Office, Title 17 Chapter 1. https://www.copyright.gov/title17/92chap1.html
  12. 17 U.S.C. § 107, U.S. Copyright Office, Title 17 Chapter 1. https://www.copyright.gov/title17/92chap1.html
  13. NIST SP 800-34 Rev. 1, Contingency Planning Guide for Federal Information Systems. https://csrc.nist.gov/pubs/sp/800/34/r1/final
  14. NIST SP 800-37 Rev. 2, Risk Management Framework. https://csrc.nist.gov/pubs/sp/800/37/r2/final
  15. NIST SP 800-218, Secure Software Development Framework (SSDF). https://csrc.nist.gov/pubs/sp/800/218/final
  16. 17 U.S.C. § 106, Exclusive rights in copyrighted works. https://www.copyright.gov/title17/92chap1.html
  17. NIST SP 800-61 Rev. 2, Computer Security Incident Handling Guide. https://csrc.nist.gov/pubs/sp/800/61/r2/final
  18. RFC 4949, Internet Security Glossary, Version 2. Internet Engineering Task Force (IETF), 2007-08. https://www.rfc-editor.org/rfc/rfc4949.txt
Open the free chapter →

Before you buy

How do I get it?
Pay, and the download appears on this page straight away. The links are also emailed to you. No account is required.
What if it isn't for me?
Email us within 14 days for a full refund, no questions asked.
Is the free practice going away?
No. Every practice question, the timed mock and the free chapters on this site stay free. This book is the studying half, not a gate around the free half.
Can I read it on my phone?
Yes — the EPUB is for phones and e-readers, the PDF is for printing and tabbing. You get both.

Full refund policy

The details

Organized by the eight domains of the ISC2 CISSP exam outline effective 15 April 2024: 250 original questions with worked explanations and a 150-question practice exam.

PrepPass team · Verified against ISC2's CISSP Certification Exam Outline (effective 15 April 2024), with NIST, IETF and U.S. federal primary sources · How we review
  • Format: PDF + EPUB download · 154 pages
  • 250 practice questions in the book, with a full answer key
  • 122 free practice questions for this exam on PrepPass, included at no cost
  • $24.99 one-time — no subscription
  • 14-day money-back guarantee · refund policy
  • Cross-referenced against: ISC2's CISSP Certification Exam Outline (effective 15 April 2024), with NIST, IETF and U.S. federal primary sources
  • Last updated: September 2026
  • Verified from the official source(ISC2's CISSP Certification Exam Outline (effective 15 April 2024), with NIST, IETF and U.S. federal primary sources)
  • 122 free practice questions
  • Instant download, yours for life
Same exam, a fraction of the price
$3,695–$4,399→$24.99

A CISSP boot camp runs $3,695–$4,399. This book teaches the same exam — same rules, verified to current standards — for a one-time $24.99 you keep for life.

Why buy the book when the practice is free?

Our practice questions and timed mock stay free — nothing on the site moves behind this book. The $24.99 book is the studying half: the material itself, taught in order, in a file you own.

  • Systematic teaching — every exam section explained chapter by chapter, start to finish, not just questions
  • Print it & tab it — a paper-ready PDF you can highlight, mark up, and bring to your study table
  • Study anywhere, offline — EPUB on your phone or e-reader; no wifi, no browser tabs
  • Everything in one place — the chapters and the practice questions in one file
  • Yours for life — one-time $24.99, instant download, no subscription

And it's risk-free: 14-day money-back guarantee — not satisfied? Email us for a full refund, no questions asked. See the refund policy.

Get the eBook — $24.99 (PDF + EPUB) ↑

14-day money-back guarantee · full refund, no questions asked.

One-time purchase, lifetime access to the download. The eBook is the full CISSP — Certified Information Systems Security Professional study guide in PDF and EPUB. Educational summary, not professional or legal advice — always confirm the current rules with the official source. Last updated: September 2026.

Report