Learning Hub › CISSP Master Track › CISSP Lab
Learn by playing · All 8 domains
CISSP Lab
Reading notes gets you halfway. This lab is the other half: calculate risk, sort data and protocols, break security models, order an incident response, spot vulnerable code, and train the "think like a manager" mindset the exam rewards. Every activity earns XP and badges. Your progress is saved in this browser only.
The exam at a glance
The CISSP tests eight domains. The bars show how much of the exam each one carries. Click a domain to jump straight to its mini-lab.
Format
Adaptive (CAT)
Questions
100–150
Time
3 hours
Pass mark
700 / 1000
Experience
5 years paid work in 2+ domains (a degree or approved credential waives 1 year). Pass without it and you become an Associate of ISC2.
Source: ISC2 CISSP Certification Exam Outline, effective April 15, 2024.
Domain mini-labs
One hands-on challenge per domain. Finish a lab to earn its badge and 50 XP. Stuck? Every answer explains itself, and the full study notes are in the CISSP Master Track.
Think like a manager
CISSP questions often have several technically correct answers. The exam wants the one a risk-aware senior manager would pick: people first, then process and policy, then technology. Watch the keyword (FIRST, BEST, MOST) and choose.
Quiz arena
Ten questions per run, drawn from all domains or the one you pick. Score 70% or more (the exam's 700/1000 mark) to earn the Arena badge. Each new question you get right is worth 10 XP.
Practice questions written for this site. They are not official ISC2 items.
Flashcards
Flip a card, then be honest. Got it moves it up a box and it comes back less often; Again sends it to box 1. This is the Leitner system: a simple form of spaced repetition.
Sources & further reading
- ISC2 CISSP Exam Outline (April 2024)
Domain weights, format and the full list of objectives.
- NIST SP 800-30 Rev. 1: Guide for Conducting Risk Assessments
The risk vocabulary behind the D1 lab.
- NIST SP 800-88: Guidelines for Media Sanitization
Clear, purge and destroy, and why degaussing does nothing to an SSD.
- NIST SP 800-61 Rev. 3: Incident Response
The 2025 revision maps incident response onto the NIST CSF 2.0 functions.
- OWASP Top 10:2025
The categories used in the D8 code spotter.
- NIST CSRC Glossary
Authoritative definitions for most flashcard terms.
Keep going: read the full domain notes in the CISSP Master Track, explore Zero Trust and Cryptography Basics, or try the IAM Fundamentals labs.