A clearer path through eight domains
CISSP practice questions & study guides.
Build understanding, one layer at a time. Review core concepts, work through security decisions, and use your practice results to plan what to study next.
Independent preparation · Original public samples · Explanations included
Before you begin
What does the CISSP exam cover?
CISSP is an ISC2 information security certification spanning technical and management decisions. Its eight domains provide a useful map for organizing your preparation. Exam Onion helps you revisit concepts and practice applying them to security scenarios.
Use this workspace if you want a structured review, need to find gaps in familiar topics, or want to move from recalling definitions to explaining a decision.
8 domainsBroad security coverage
100–150 itemsOfficial adaptive exam
3 hoursOfficial exam time limit
Exam facts and domain weights checked September 8, 2026 against the official ISC2 exam outline. Confirm current requirements with ISC2 before booking.
Your study map
Explore the eight CISSP domains
Use the official weightings as context, then give extra attention to the concepts you find hardest to explain.
Domain 1 · 16% exam weight
Security and Risk Management
Connect security decisions to business priorities.
Practice weighing business impact, choosing risk responses, and distinguishing policy ownership from day-to-day implementation.
Study domain 1 →Domain 2 · 10% exam weight
Asset Security
Protect information throughout its lifecycle.
Review who owns data decisions, how classification guides handling, and what changes when information is retained, shared or destroyed.
Study domain 2 →Domain 3 · 13% exam weight
Security Architecture and Engineering
Understand why a control fits a system.
Work through trust boundaries, security models, cryptographic choices and resilience. Consider the assumptions that make each control effective.
Study domain 3 →Domain 4 · 13% exam weight
Communication and Network Security
Reason about secure connections and boundaries.
Study segmentation, communication paths and protocol choices. Ask which boundary a control protects and which traffic can still cross it.
Study domain 4 →Domain 5 · 13% exam weight
Identity and Access Management (IAM)
Give the right identity the right access.
Distinguish proof of identity from permission to act. Review access reviews, account lifecycle decisions and privileged access.
Study domain 5 →Domain 6 · 12% exam weight
Security Assessment and Testing
Find evidence that controls work.
Choose assessment methods for a stated objective, interpret findings and understand the difference between a discovered weakness and validated assurance.
Study domain 6 →Domain 7 · 13% exam weight
Security Operations
Maintain security through everyday work and incidents.
Review incident handling, recovery priorities and operational safeguards. Identify the next action using the situation and established procedures.
Study domain 7 →Domain 8 · 10% exam weight
Software Development Security
Build security into software decisions.
Study how requirements, design reviews, testing and change control work together to reduce software risk across the development lifecycle.
Study domain 8 →From concepts to decisions
A study loop you can repeat
01Review a knowledge point
Read the domain study guide. Explain the concept in your own words and identify when it would matter in a real security decision.
02Test your understanding
Use knowledge checks and domain practice, then work through broader simulated practice to apply concepts across scenarios.
03Return to the explanation
Review answers, revisit missed concepts and track progress in your account. A correct answer is more useful when you can explain why the alternatives do not fit.
Try the approach
Free CISSP sample questions with explanations
These three original introductory examples are written for this public guide. They illustrate security reasoning and are not a representative exam or a readiness assessment. Choose your answer before opening the explanation.
Domain 1 · Risk management
1. Who accepts the remaining risk?
A security team has documented the residual risk of a proposed service and recommended additional controls. The business wants to launch without those controls. Who should formally accept the residual risk within the organization’s delegated authority?
- The analyst who documented the findings
- The accountable business risk owner
- The vendor implementing the service
- The auditor reviewing the control evidence
Reveal answer and explanation for question 1
B is correct. The accountable risk owner makes the acceptance decision within delegated authority because the decision trades business exposure against business objectives.
A: Analysis informs the decision but does not grant acceptance authority. C: A vendor cannot accept the customer’s business risk merely by implementing a service. D: An auditor provides independent assurance; owning the acceptance decision would compromise that role.
Study takeaway: Separate advice and assurance from accountability for a business decision.
Domain 5 · Access management
2. What changes when an employee transfers?
An employee moves from payroll to customer support. The new role has been approved, and there is no business requirement to retain payroll access. Which action best maintains least privilege?
- Keep both sets of permissions until the annual review
- Disable the employee’s identity permanently
- Remove unneeded payroll permissions and provision the approved support access
- Copy the permissions of the most experienced support administrator
Reveal answer and explanation for question 2
C is correct. Access should match the approved current role. Removing obsolete entitlements prevents privilege accumulation during transfers.
A: Waiting leaves unnecessary access in place. B: Permanent disablement prevents authorized work. D: Copying an administrator’s permissions can grant privileges beyond the employee’s approved duties.
Study takeaway: A role change requires both granting needed access and removing access that is no longer justified.
Domain 7 · Recovery planning
3. Which service should recover first?
After a site outage, two services compete for limited recovery resources. Both can be restored safely, and neither is a technical dependency of the other. What should primarily guide their recovery order?
- Which system was purchased most recently
- Which team sends the most urgent messages
- Which service has the largest storage allocation
- The approved business impact analysis and recovery priorities
Reveal answer and explanation for question 3
D is correct. Approved impact analysis and recovery priorities connect restoration order to the consequences of downtime for the organization.
A: Purchase date does not establish business criticality. B: Message volume is not an agreed recovery criterion. C: Storage size alone does not measure the business impact of losing a service.
Study takeaway: Use established business priorities to guide recovery instead of technical size or informal pressure.
Know what to expect
Free previews. Account-based practice.
Read before signing in
This overview, the domain summaries and all three sample explanations are freely accessible without an account.
Continue in your workspace
Read study guides without an account. Sign in for practice sessions and saved progress. Before starting a session, review its required credits and your available balance.
Choose when to purchase
One-time credit packs and Pro subscriptions are available in the workspace. Check the purchase screen for current pricing and plan details before buying.
Refunds and cancellation →A few useful answers
CISSP practice: frequently asked questions
Can I try CISSP questions without an account?
Yes. The three original questions on this page and their explanations are free to read without signing in. Knowledge point reading is also public. Sign in for practice and saved learning progress.
How should I use the study guides and practice questions?
Start with a domain, review a knowledge point, then test your understanding. Read the explanation even when you answer correctly. Revisit missed concepts before moving to broader scenario practice.
Does practice require credits?
The workspace shows the credit requirement and your available balance before you confirm a practice session. Credit packs and Pro subscriptions are available. Review the current purchase screen for prices, allowances and any applicable offer.
Is this the official CISSP exam or an adaptive test?
No. Exam Onion provides independent study material and simulated practice. Practice sessions do not reproduce ISC2’s computerized adaptive testing algorithm, official scoring or certification decision.
Does a practice score predict whether I will pass?
No. Use practice results to identify topics to revisit. A practice percentage is not the official scaled score and is not a guarantee of exam readiness or a passing result.
Where can I confirm certification requirements?
Use the official ISC2 exam outline and certification pages for eligibility, exam policies and booking information. Exam Onion is a supplementary study tool.
About this study resource
Published by Exam Onion. The public samples are original educational examples, separate from the account-based question bank. Domain summaries explain study priorities; they do not replace the official exam outline. If an explanation seems unclear, contact us with the question title.
Exam Onion is not affiliated with, endorsed by or sponsored by ISC2. CISSP is a registered trademark of ISC2. Practice results do not guarantee certification or an exam pass.
Official exam outline ↗ · Official certification information ↗ · Full disclaimer
Take the next step
Choose a domain.
Start with one concept.
Open CISSP study workspace ↗Already have an account? Use the same sign-in to continue.