// FREE TO PREVIEW · ISC2

🔑 CISSP

The senior, management-level security certification — the eight domains, thought like a manager.

CREATE A FREE ACCOUNT & STARTNEW TO LINUX? START FREE
// WHO IT’S FOR

Experienced practitioners moving toward security leadership. CISSP is broad and deep; it rewards the single best answer, not the most technical one.

// EXAM AT A GLANCE

Computer-adaptive: 100–150 questions · up to 4 hours · passing score 700/1000 · requires 5 years’ experience to certify

EXAM DOMAINS

16% Security & Risk Management
CIA, governance, risk (SLE/ALE), law, BCP.
10% Asset Security
classification, ownership, data lifecycle, retention.
13% Security Architecture & Engineering
models, cryptography, physical security.
13% Communication & Network Security
secure protocols, segmentation, zero trust.
13% Identity & Access Management
AAA, MFA, access models, federation.
12% Security Assessment & Testing
audits, pen tests, SOC reports, metrics.
13% Security Operations
SoD, logging, backups, incident response, forensics.
10% Software Development Security
secure SDLC, OWASP, CI/CD, SBOM.

SAMPLE QUESTIONS

Three tasters — the real track has hundreds, graded, with full rationale.

Q1. In quantitative risk analysis, how is the Annualised Loss Expectancy (ALE) calculated?
A. AV × EF
B. SLE × ARO
C. ALE × ARO
D. AV × ARO
reveal answer

B. ALE = SLE × ARO. The Single Loss Expectancy (itself AV × EF) multiplied by the Annualised Rate of Occurrence gives expected yearly loss — the number you compare against a control’s cost.

Q2. A control is financially justified when:
A. It uses the newest technology
B. Its cost is less than the loss (ALE) it prevents
C. It is required by a vendor
D. It has the strongest encryption
reveal answer

B. Cost-benefit rule: implement a control only when its cost is below the annualised loss it avoids. Otherwise accepting the risk is the rational choice.

Q3. Under GDPR, a data controller must notify the supervisory authority of a breach within:
A. 24 hours
B. 72 hours
C. 30 days
D. It is optional
reveal answer

B. GDPR Article 33 sets a 72-hour clock for notifying the supervisory authority. (Do not confuse it with HIPAA’s 60-day individual-notification rule.)

// READY?

The full CISSP track — lectures, graded checks and labs — is free to start. Create an account to save your progress, earn points and climb the leaderboard.

💀
MODULE TITLE
▪ BEGINNER · 4 LESSONS · 0% COMPLETE

SELECT A LESSON TO BEGIN

🗂
LAB TITLE
LAB_01 · BEGINNER · ~20 MIN
🏆
LAB COMPLETE — ALL OBJECTIVES CLEARED

Well executed. Review your commands above or proceed to the next lab.

LAB_01 // ACTIVE
root@lab:~$