Printable reviewEight domainsCurrent reviewed track

CISSP cram sheet

Use this as a last-mile reasoning guide after full study. It condenses the distinctions, ownership rules, lifecycle ideas, and cross-domain patterns that commonly separate a good security answer from the best one.

Independent Zeph Tech study material. Not affiliated with or endorsed by ISC2. No recalled, leaked, copied, or live-exam questions.

Study guidePractice test
Current reviewed record

Check the official exam facts before exam day.

Use the registry summary for current timing, item policy, domain weights, experience rules, maintenance requirements, and official owner links. Do not rely on older CISSP pages that still describe previous CAT limits or previous domain weights.

Active

Last verified: 2026-10-01

Next review: 2026-11-01

Official certification page · Official exam objectives

Published domain weighting

Domain 1 — Security and Risk Management

Domain 2 — Asset Security

Domain 3 — Architecture and Engineering

Domain 4 — Communication and Network Security

Domain 5 — IAM

Domain 6 — Assessment and Testing

Domain 7 — Security Operations

Domain 8 — Software Development Security

High-value distinctions

Risk owner vs security practitioner: security identifies, analyzes, recommends, implements, and monitors. An accountable business owner accepts residual risk because acceptance is a business decision.

Authentication vs authorization: successful login only establishes identity. The resource-owning service must still enforce what that identity is permitted to do.

Due care vs due diligence: due care is taking reasonable protective action; due diligence is the continuing effort to understand whether protections remain appropriate and effective.

BC vs DR: business continuity sustains critical business functions; disaster recovery restores technology and supporting capabilities. A continuity strategy can include manual workarounds while technology is unavailable.

RTO vs RPO: RTO measures the restoration-time objective. RPO measures the acceptable data-loss interval. A backup frequency that cannot meet RPO is insufficient even if restoration is fast.

Preventive vs detective vs corrective: preventive controls attempt to stop an event, detective controls reveal it, and corrective controls restore or fix conditions. One technology can serve multiple purposes depending on implementation.

Vulnerability assessment vs penetration test: an assessment identifies weaknesses broadly; a penetration test attempts controlled exploitation to demonstrate attack paths and impact within authorization.

Containment vs eradication vs recovery: containment limits attacker capability, eradication removes root cause or persistence, and recovery restores systems to trusted service and verifies normal operation.

Scenario decision checklist

Before choosing an answer, identify the asset, the business objective, the decision owner, the current lifecycle stage, the available evidence, and the constraint introduced by words such as FIRST, BEST, MOST, PRIMARY, or LEAST.

If the question is managerial, do not jump straight to a product. Ask whether a policy, risk decision, legal requirement, contract, architecture, or owner must be addressed first. If the question is technical, still ensure the proposed control solves the stated layer and does not violate governance.

When evidence is incomplete, prefer actions that increase confidence and preserve options unless immediate containment is necessary to prevent material harm. Investigations are weakened when destructive action removes logs, memory, persistence artifacts, or timeline evidence before collection.

When several answers are true, choose the one that is most complete at the requested level. A CISSP answer often integrates people, process, and technology rather than assuming one configuration setting resolves the full risk.

Exam-day checklist

Last-mile review method

Select ten topics you still hesitate on and reduce each to four lines: the definition, the security objective, one example, and one common confusion. This forces active recall and exposes where you only recognize terminology without understanding the decision.

Then connect pairs of domains. Link risk management to asset classification, architecture to network segmentation, IAM to logging, testing to software development, and operations to continuity. CISSP is easier to reason through when the domains form one operating model instead of eight separate lists.

Finally, practice explaining a recommendation to three audiences: a system administrator, a business owner, and an auditor. The underlying control may be the same, but each audience needs different evidence and language. That communication discipline reflects the management and technical breadth the credential is intended to assess.