CISSP Study Guide — 2026 Edition cover

CISSP — Certified Information Systems Security Professional · 2026 版

CISSP Study Guide — 2026 Edition

Organized by the eight domains of the ISC2 CISSP exam outline effective 15 April 2024: 250 original questions with worked explanations and a 150-question practice exam.

  • 250 道原创 CISSP 练习题,每题附解析,合成一本 PDF + EPUB 永久保存

PDF + EPUB · 英文 · 154 页 · $24.99 一次买断

本书为英文版,下载的 PDF 与 EPUB 均为英文。

付款后立即下载 —— 无需注册账号,无订阅。

14 天退款保证:任何原因不满意?购买后 14 天内发邮件至 support@preppass.org 即可全额退款。 退款政策

先免费读一章样章

还不想买?

先做 10 题,看看讲解 —— 免费

先答完这 10 题,交卷后每题都有解析 —— 还会指出本指南里讲这一点的那一节。约 5 分钟,无需注册。

开始 10 道免费题

翻开这本书看看

三页真实内页,直接从你将下载的 PDF 渲染而来 —— 依次是一页速查、一页讲解、一道带解析的例题。没有任何一页是为了好看而重画的。

  • 速查页
    Appendix B — Glossary of key terms · PDF 第 146 页

    一页可以随时翻回来的内容:把数字、期限或术语集中在一处。

  • 怎么讲
    Chapter 5 — Identity and Access Management · PDF 第 53 页

    讲解页:用文字把知识讲清楚,顺序与考试考查的顺序一致。

  • 一道题的完整解析
    Chapter 5 — Identity and Access Management · PDF 第 52 页

    一道练习题,连同答案和背后的推理 —— 不只是一个答案键。

关于这场考试本身

Certified Information Systems Security Professional (CISSP) — 考试事实
主管机构ISC2 —— 考试由 Pearson VUE 承办

来源: ISC2 — CISSP Certification Exam Outline (Effective Date: April 15, 2024)

题目数量100–150 道题

来源: ISC2 — CISSP Certification Exam Outline (Effective Date: April 15, 2024)

考试时限180 分钟

来源: ISC2 — CISSP Certification Exam Outline (Effective Date: April 15, 2024)

及格标准ISC2 计分: 1,000 分中至少 700 分

来源: ISC2 — CISSP Certification Exam Outline (Effective Date: April 15, 2024)

费用
  • $749 — 标准报名费(美洲、亚太、中东、非洲) (ISC2, 每次考试)

来源: ISC2 — ISC2 Exam Pricing

考试语言中文 · 英语 · 德语 · 日语 · 西班牙语

来源: ISC2 — CISSP Certification Exam Outline (Effective Date: April 15, 2024)

考试事实:每一项均附来源

免费的 CISSP — Certified Information Systems Security Professional 练习题与学习章节 →

包含什么,不包含什么

包含

  • Eight chapters, one per domain of the ISC2 CISSP outline (effective 15 April 2024)
  • A quiz closing each chapter, with worked explanations
  • A 150-question practice exam at the published domain weights
  • 250 original questions, each explained and cited to its source
  • Sourced from NIST FIPS and SP publications, IETF RFCs and the ISC2 Code
  • PDF + EPUB you keep

不包含

  • 不寄送纸质书 —— 这是一份你下载后可自行打印的文件
  • 购书不含视频课程、讲师或一对一辅导 —— 站上的免费视频是另一回事
  • 不含考试报名费与考点费用,这些仍需向官方机构缴纳

目录

查看 14 个部分及各部分起始页
  1. Chapter 1 — Security and Risk Management第 6 页
  2. Chapter 2 — Asset Security第 19 页
  3. Answer key & explanations第 24 页
  4. Chapter 3 — Security Architecture and Engineering第 27 页
  5. Chapter 4 — Communication and Network Security第 38 页
  6. Chapter 5 — Identity and Access Management第 47 页
  7. Chapter 6 — Security Assessment and Testing第 56 页
  8. Chapter 7 — Security Operations第 64 页
  9. Chapter 8 — Software Development Security第 74 页
  10. Practice Exam — Domain 3: Security Architecture and Engineering (20 questions)第 98 页
  11. Practice Exam — Domain 5: Identity and Access Management (20 questions)第 114 页
  12. Appendix A — Exam-day reference第 144 页
  13. Appendix B — Glossary of key terms第 146 页
  14. Appendix C — Acronyms第 148 页

取自你将下载的那份 PDF,并标明各章起始页 —— 不是在此手工录入的。

免费读完整一章

完整的一章,与电子书正文一字不差。直接在此窗口滚动阅读;无需下载,无需邮箱。

在本页直接阅读第 1 章
免费试读 —— 就在这里读
第 1 章 · 约 13 分钟读完
Security and Risk Management
向下滚动 ↓

Domain 1 carries the heaviest weight on the exam at 16%[1], and it sets the tone for everything after it: governance before technology, risk before controls, and the manager's view before the technician's. Read it as the person who will have to defend the program to executives, auditors, and regulators.

1.1 Professional ethics

ISC2's Code of Ethics has four mandatory canons: protect society, the common good, public trust, and the infrastructure[2]; act honorably, honestly, justly, responsibly, and legally[2]; provide diligent and competent service to principals[2]; and advance and protect the profession[2]. On the exam, when an ethics scenario pits loyalty to an employer against one of these duties, the canons outrank the employer's instructions — the first canon, protecting society, outranks them all.

1.2 Security concepts

The CIA triad — confidentiality, integrity, availability — is the vocabulary of the whole field, and FIPS 199 states the three objectives in the words of federal law: confidentiality means "preserving authorized restrictions on information access and disclosure, including means for protecting personal privacy and proprietary information"; integrity means "guarding against improper information modification or destruction, and includes ensuring information non-repudiation and authenticity"; and availability means "ensuring timely and reliable access to and use of information"[3, 4]. Related concepts the outline names here include threats, vulnerabilities, and risk: NIST defines risk as a function of the adverse impacts of an event and the likelihood it occurs[5]. Controls are the safeguards you select against that risk, and they come in families — NIST organizes its controls into 20 families[6].

1.3 Security governance principles

Governance is the system by which the organization's security is directed and controlled. NIST's Cybersecurity Framework puts a GOVERN function at the center: the organization's cybersecurity risk management strategy, expectations, and policy are established, communicated, and monitored[7]. In practice this means policies (management's high-level intent), standards (mandatory rules), procedures (step-by-step instructions), and guidelines (recommended practices) — and a board and executive team that own risk rather than delegating it away.

1.4 Legal, regulatory, and compliance issues

Several regimes appear repeatedly. The EU General Data Protection Regulation requires breach notification to the supervisory authority without undue delay and, where feasible, not later than 72 hours after becoming aware of a personal data breach[8], and its top tier of administrative fines reaches 20 million euros or 4% of worldwide annual turnover, whichever is higher[8]. In U.S. health care, the HIPAA Security Rule sets forth the administrative, physical, and technical safeguards that covered entities and business associates must put in place to secure electronic protected health information[9]. For payment cards, PCI DSS provides a baseline of technical and operational requirements designed to protect payment account data[10], applying to entities that store, process, or transmit cardholder data[10]. For software, copyright subsists in original works of authorship fixed in any tangible medium of expression[11], while fair use — for purposes such as criticism, comment, news reporting, teaching, scholarship, or research — is not infringement[12], judged on four factors including the purpose and character of the use and its effect on the market[12].

1.5 Investigation types

Administrative investigations address policy violations and support HR action; criminal investigations support prosecution and demand the strictest evidence handling; civil investigations support lawsuits between parties. The key exam distinction is the standard of handling: criminal matters require preserving chain of custody and involving law enforcement, because mishandled evidence is inadmissible. Never let an internal investigation contaminate a potential criminal case.

1.6 Security policy, standards, procedures, and guidelines

Policy states management's intent and assigns responsibility; standards set the mandatory rules that implement policy; procedures give the step-by-step instructions; guidelines offer recommended practices for situations where judgment applies. NIST's contingency planning guidance makes the same point about authority: a formal policy provides the authority and guidance necessary to develop an effective plan[13]. Write policies short, get executive sign-off, and review them on a schedule — an unsigned, unreviewed policy is decoration.

1.7 Business continuity requirements

Business continuity is about keeping the mission alive through disruption. The analysis that drives it is the business impact analysis: the BIA helps identify and prioritize information systems and components critical to supporting the organization's mission and business processes[13]. From the BIA come the recovery targets — how long you can be down and how much data you can afford to lose — and the strategies to meet them. Continuity planning starts with policy and the BIA before any technology is chosen.

1.8 Personnel security policies and procedures

People are part of the control set: background checks before hiring, least privilege from day one, mandatory vacations and job rotation to expose fraud, and a termination procedure that revokes access the same day. Personnel controls also include nondisclosure and noncompete agreements where lawful. The exam treats separation of duties and least privilege as personnel controls first and technical controls second.

1.9 Risk management concepts

Risk management is a cycle: assess, treat, monitor. NIST defines risk assessment as the process of identifying, estimating, and prioritizing information security risks[5], and risk itself as a function of adverse impact and likelihood[5]. Treatment options are the classic four: avoid, transfer, mitigate, or accept the risk. The Risk Management Framework gives this a formal seven-step shape — a preparatory step plus six main steps, all essential[14] — beginning with preparing to execute the RMF by establishing context and priorities[14] and categorizing each system based on the impact of loss[14]. Senior management formally accepts the leftover risk; that acceptance is what makes the program legitimate.

1.10 Threat modeling concepts and methodologies

Threat modeling is structured brainstorming about what can go wrong, done early enough to influence design. Methodologies decompose the system (data flows, trust boundaries, entry points), enumerate threats against each element, and rank them so design effort goes to the worst first. The output feeds directly into control selection: you don't buy controls and then look for threats, you model threats and then select controls.

1.11 Supply chain risk management

Modern systems are assembled from other people's components, so the supply chain is part of your attack surface. SCRM means vetting suppliers, demanding evidence of their secure development practices — NIST's SSDF gives acquirers a common vocabulary for exactly these conversations with suppliers[15] — and planning for supplier failure or compromise. Counterfeit components, tampered updates, and a vendor's breach becoming your breach are the scenarios to plan for.

1.12 Security awareness, education, and training

Awareness changes behavior across the whole workforce; education builds deeper understanding for those who need it; training builds job-specific skill. The program must be established and maintained — one annual slide deck is not a program — with role-based training for privileged users and developers, and metrics (such as phishing-simulation click rates) that show whether behavior is actually changing.

Key numbers

  • Exam: 3 hours, 100–150 items, pass at 700/1000[1]
  • Breach notification under GDPR: 72 hours to the supervisory authority[8]
  • Top GDPR fines: 20 million euros or 4% of worldwide annual turnover[8]
  • RMF: seven steps (one preparatory plus six main)[14]
  • NIST controls: 20 families[6]

Key takeaways

  • Domain 1 is the manager's domain: governance, risk, law, and ethics before technology.
  • The four ethics canons outrank any employer's instruction; protecting society comes first.
  • Risk is impact times likelihood; assessment identifies, estimates, and prioritizes.
  • The BIA identifies and prioritizes what the mission cannot lose, and it comes before recovery strategies.
  • When in doubt on the exam, choose the answer that manages risk at the program level rather than fixing one technical symptom.

Chapter 1 quiz — 16 questions

Answer each question, then check the key that follows.

1. A security manager discovers the company is quietly selling customer location data in a way that endangers domestic-violence victims. The CEO orders the manager to stay silent. What should guide the manager's decision first?

  • A. The duty to protect society and the common good
  • B. The manager's personal employment contract terms
  • C. The company's public privacy policy statements
  • D. The CEO's direct order, as the highest internal authority

2. Which definition best matches how NIST describes information security risk?

  • A. The difference between threats and vulnerabilities
  • B. A function of adverse impacts and likelihood of occurrence
  • C. The number of vulnerabilities found in the last assessment
  • D. The annual cost of all security controls in the program

3. The board asks what governance of cybersecurity actually requires of them. Which answer is most accurate?

  • A. Setting and monitoring risk strategy and policy
  • B. Reviewing penetration test reports line by line
  • C. Approving every firewall rule change personally
  • D. Delegating all security decisions to the IT department

4. A company discovers a breach of EU residents' personal data on Monday morning. By when must it notify the supervisory authority, where feasible?

  • A. Within 30 days of completing the investigation
  • B. Only after notifying affected individuals first
  • C. Within 24 hours of discovery
  • D. Within 72 hours of becoming aware

5. Under the GDPR's highest tier, administrative fines can reach which maximum?

  • A. 10 million euros or 2% of worldwide annual turnover
  • B. 1 million euros or 1% of worldwide annual turnover
  • C. 20 million euros or 4% of turnover
  • D. 50 million euros with no turnover alternative

6. A U.S. hospital is documenting its safeguards for patient records systems. Which rule's framework of administrative, physical, and technical safeguards applies?

  • A. The GDPR's data protection principles
  • B. The FedRAMP authorization baseline
  • C. The PCI Data Security Standard
  • D. The HIPAA Security Rule

7. A retailer that stores and processes payment card numbers wants the baseline of technical and operational requirements for protecting that data. Which standard provides it?

  • A. The CISSP exam outline
  • B. PCI DSS
  • C. NIST SP 800-53
  • D. ISO/IEC 27001

8. A developer copies a competitor's proprietary program into a new product. Under U.S. copyright law, what determines whether the program is protected?

  • A. Whether the program was registered before publication
  • B. Whether the program contains more than 1,000 lines of code
  • C. Whether it is an original work in a tangible medium
  • D. Whether the competitor sells the program commercially

9. A trainer wants to quote short passages of a copyrighted article in a security awareness course. Which factor is part of the fair-use analysis?

  • A. The number of students enrolled in the course
  • B. The trainer's job title and seniority
  • C. Effect on the work's potential market
  • D. Whether the article was published in the last year

10. An employee is suspected of stealing trade secrets, and prosecution is possible. What is the most important handling requirement for the evidence?

  • A. Preserving chain of custody so the evidence stays admissible
  • B. Confronting the employee immediately to get a confession
  • C. Deleting the employee's accounts before collecting anything
  • D. Publishing findings internally as a deterrent

11. Which document should state management's high-level intent for information security and assign responsibility for it?

  • A. A guideline
  • B. A procedure
  • C. A standard
  • D. A policy

12. Before buying backup infrastructure, a company wants to know which systems the mission cannot survive without and for how long each can be down. What should it conduct first?

  • A. A vulnerability scan of the data center
  • B. A business impact analysis
  • C. A penetration test of the backup systems
  • D. A code review of the recovery scripts

13. According to NIST, risk assessment is best described as which activity?

  • A. Installing controls to reduce all risks to zero
  • B. Identifying, estimating, and prioritizing information security risks
  • C. Documenting accepted risks for the auditors
  • D. Transferring risk to an insurance provider

14. An organization adopts the NIST Risk Management Framework. How many steps does it include?

  • A. Seven steps: a preparatory step plus six main steps
  • B. Four steps, one per risk treatment option
  • C. Twelve steps, one per control family
  • D. Five steps matching the CSF functions

15. A company buys most of its product's components from outside vendors. Which practice best addresses the resulting supply chain risk?

  • A. Buying only from the lowest-cost supplier in each category
  • B. Testing finished products once a year for defects
  • C. Keeping the supplier list secret from internal auditors
  • D. Requiring vendors to demonstrate secure development practices during acquisition

16. A phishing simulation shows 30% of staff clicking malicious links. What does a mature awareness program do next?

  • A. Block all external email to eliminate the threat
  • B. Punish the staff who clicked with formal warnings
  • C. Treat it as a metric and deliver targeted training
  • D. Run the same simulation monthly without any training

Answer key & explanations

1. A. The first canon requires protecting society, the common good, public trust, and the infrastructure[2] — that duty is what the manager's decision must serve first. The remaining canons then require acting honorably, honestly, justly, responsibly, and legally[2], providing diligent and competent service to principals[2], and advancing and protecting the profession itself[2].

2. B. NIST defines risk as a measure of the extent to which an entity is threatened by a potential circumstance or event, typically a function of the adverse impacts that would arise and the likelihood of occurrence[5]. Cost of controls, vulnerability counts, and threat-vulnerability arithmetic are not the definition. Risk assessment is the separate process of identifying, estimating, and prioritizing information security risks[5] — the mechanism that produces the likelihood-and-impact judgments the definition calls for.

3. A. The GOVERN function is defined as establishing, communicating, and monitoring the organization's cybersecurity risk management strategy, expectations, and policy[7]. Boards govern through strategy and oversight, not by approving individual technical changes or reviewing raw test output. The CSF organizes all cybersecurity outcomes at their highest level into six Core Functions — GOVERN, IDENTIFY, PROTECT, DETECT, RESPOND, and RECOVER[7] — with GOVERN setting the strategy that the other five execute.

4. D. GDPR Article 33 requires notification to the supervisory authority without undue delay and, where feasible, not later than 72 hours after becoming aware of the breach[8]. Waiting for the investigation to finish or notifying individuals first does not satisfy the deadline. Breaches at this scale also expose the company to the top fine tier — up to 20 million euros or 4% of worldwide annual turnover[8] — which is why the clock starts at awareness, not at the end of the investigation.

5. C. The top tier of GDPR administrative fines is up to 20 million euros or, for an undertaking, up to 4% of total worldwide annual turnover of the preceding financial year, whichever is higher[8]. The lower 10 million / 2% tier applies to a different set of infringements. The same regulation separately imposes the 72-hour breach notification duty[8], framing all of this as protecting a fundamental right — the protection of natural persons in relation to the processing of personal data[8].

6. D. The HIPAA Security Rule sets forth the administrative, physical, and technical safeguards that covered entities and business associates must put in place to secure electronic protected health information[9]. PCI DSS covers payment cards, not patient records. The rule's protected object is electronic protected health information — PHI maintained in or transmitted by electronic media[9] — so the first scoping question is always whether the system handles ePHI at all.

7. B. PCI DSS provides a baseline of technical and operational requirements designed to protect payment account data[10], and its intended audience is entities that store, process, or transmit cardholder data[10]. ISO 27001 and SP 800-53 are general control frameworks, not the card-data baseline. The distractors name real frameworks, but neither is scoped to cardholder data: ISO 27001 is a general ISMS standard and SP 800-53 a federal control catalog, while PCI DSS exists specifically for the payment-card baseline.

8. C. Copyright protection subsists in original works of authorship fixed in any tangible medium of expression[11]. Registration, length, and commercial sale are not the test for whether protection exists. The owner's exclusive rights include reproduction of the work[16], so copying the program infringes regardless of registration; fair use remains only a limited defense, judged by factors including the purpose and character of the use[12].

9. C. The four fair-use factors include the effect of the use upon the potential market for or value of the work, alongside the purpose and character of the use, the nature of the work, and the amount used[12]. Job title, publication recency, and class size are not factors. Protection itself subsists in original works fixed in a tangible medium[11], and the owner's exclusive rights include reproduction[16] — fair use is the limited exception to those rights, not the default.

10. A. Criminal investigations support prosecution, so evidence must survive legal challenge: NIST's incident handling guidance says evidence should be accounted for at all times, with chain of custody forms detailing every transfer[17]. Confronting the suspect, deleting accounts, or publicizing findings all risk contaminating the case the prosecution depends on. The response lifecycle itself runs preparation, detection and analysis, containment, eradication and recovery, and post-incident activity[17] — evidence discipline sits inside that structure, which is why improvising outside it destroys the case.

11. D. A security policy is "a definite goal, course, or method of action to guide and determine present and future decisions concerning security in a system"[18] — management's high-level intent, which is why it is the document that assigns responsibility. A standard is the tempting wrong answer: it sets mandatory specifics (an approved algorithm, a baseline) that implement the policy, not the intent itself. Procedures give the steps and guidelines advise; NIST's contingency guidance makes the same point about authority, noting that a formal policy "provides the authority and guidance" for the plans beneath it[13].

Sources cited in this excerpt

  1. ISC2 CISSP Certification Exam Outline. https://www.isc2.org/certifications/cissp
  2. ISC2 Code of Ethics. https://www.isc2.org/ethics
  3. FIPS 199, Standards for Security Categorization of Federal Information and Information Systems. NIST. https://csrc.nist.gov/pubs/fips/199/final
  4. FIPS 199, Standards for Security Categorization of Federal Information and Information Systems. NIST. https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.199.pdf
  5. NIST SP 800-30 Rev. 1, Guide for Conducting Risk Assessments. https://csrc.nist.gov/pubs/sp/800/30/r1/final
  6. NIST SP 800-53 Rev. 5, Security and Privacy Controls. https://csrc.nist.gov/pubs/sp/800/53/r5/final
  7. NIST Cybersecurity Framework (CSF) 2.0. https://www.nist.gov/cyberframework
  8. Regulation (EU) 2016/679 (GDPR), official text, EUR-Lex. Publications Office of the European Union. https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679
  9. 45 CFR Part 164, Subpart C — Security Standards for the Protection of Electronic Protected Health Information (eCFR). U.S. HHS / eCFR. https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C
  10. PCI Security Standards Council — PCI DSS. https://www.pcisecuritystandards.org/standards/pci-dss/
  11. 17 U.S.C. § 102, U.S. Copyright Office, Title 17 Chapter 1. https://www.copyright.gov/title17/92chap1.html
  12. 17 U.S.C. § 107, U.S. Copyright Office, Title 17 Chapter 1. https://www.copyright.gov/title17/92chap1.html
  13. NIST SP 800-34 Rev. 1, Contingency Planning Guide for Federal Information Systems. https://csrc.nist.gov/pubs/sp/800/34/r1/final
  14. NIST SP 800-37 Rev. 2, Risk Management Framework. https://csrc.nist.gov/pubs/sp/800/37/r2/final
  15. NIST SP 800-218, Secure Software Development Framework (SSDF). https://csrc.nist.gov/pubs/sp/800/218/final
  16. 17 U.S.C. § 106, Exclusive rights in copyrighted works. https://www.copyright.gov/title17/92chap1.html
  17. NIST SP 800-61 Rev. 2, Computer Security Incident Handling Guide. https://csrc.nist.gov/pubs/sp/800/61/r2/final
  18. RFC 4949, Internet Security Glossary, Version 2. Internet Engineering Task Force (IETF), 2007-08. https://www.rfc-editor.org/rfc/rfc4949.txt
打开免费章节 →

购买前

怎么拿到?
付款后下载入口立即出现在本页,链接同时发到你的邮箱。无需注册账号。
不合适怎么办?
14 天内发邮件即可全额退款,无需理由。
免费练习会取消吗?
不会。站上的每一道练习题、计时模考和免费章节都继续免费。这本书是「学」的那一半,不是把免费部分围起来的门。
能在手机上看吗?
可以 —— EPUB 适合手机和电子书阅读器,PDF 适合打印和贴标签,两种都给你。

完整退款政策

详细信息

Organized by the eight domains of the ISC2 CISSP exam outline effective 15 April 2024: 250 original questions with worked explanations and a 150-question practice exam.

PrepPass 团队 · 依据官方资料核对 ISC2's CISSP Certification Exam Outline (effective 15 April 2024), with NIST, IETF and U.S. federal primary sources · 我们如何核对
  • Format: PDF + EPUB download · 154 pages
  • 250 practice questions in the book, with a full answer key
  • 122 free practice questions for this exam on PrepPass, included at no cost
  • $24.99 one-time — no subscription
  • 14-day money-back guarantee · refund policy
  • Cross-referenced against: ISC2's CISSP Certification Exam Outline (effective 15 April 2024), with NIST, IETF and U.S. federal primary sources
  • Last updated: September 2026
  • 官方来源核验(ISC2's CISSP Certification Exam Outline (effective 15 April 2024), with NIST, IETF and U.S. federal primary sources)
  • 122 道免费练习题
  • 即时下载,永久拥有
同一门考试,零头的价格
$3,695–$4,399→$24.99

CISSP boot camp 要 $3,695–$4,399。这本书讲的是同一门考试 —— 同样的规则、核对到最新标准 —— 只需一次性 $24.99,永久归你。

练习免费,为什么还要买书?

我们的练习题和计时模考一直免费 —— 网站上的东西不会因为这本书而收起来。这本 $24.99 的书是「学」的那一半:知识本身,按顺序讲清楚,存成一份属于你的文件。

  • 系统讲解 —— 每个考试部分按章节从头讲到尾,不只是题目
  • 可打印可贴标签 —— 一份适合打印的 PDF,能划重点、做批注、带到书桌前
  • 随处离线学 —— EPUB 放手机或电子书阅读器;不用 wifi,不用一堆浏览器标签
  • 全在一处 —— 章节和练习题都在同一份文件里
  • 永久归你 —— 一次 $24.99,即时下载,无订阅

而且零风险:14 天退款保证 —— 不满意?发邮件即可全额退款,无需理由。 详见退款政策。

获取电子书 —— $24.99(PDF + EPUB)↑

14 天退款保证 · 全额退款,无需理由。

一次购买,永久下载访问。此电子书是完整的 CISSP — Certified Information Systems Security Professional 学习指南,含 PDF 与 EPUB。仅为教育性摘要,非专业或法律意见 —— 请始终以官方来源核实当前规定。最后更新:September 2026。

反馈