CISSP Bootcamp
8 domains · cram sheet · 40-question practice exam · free forever
A free, unofficial, self-paced bootcamp covering all eight CISSP
domains with dense technical notes, memory hooks, exam tips and practice questions
— built the RCW way: hands-on, high-yield, no fluff.
The eight modules
Domain 1 · 16% of examSecurity and Risk ManagementThe widest and heaviest domain.Domain 2 · 10% of examAsset SecurityA short, high-yield domain: classify data and assets, then protect them through their whole lifecycle — including the way they die (sanitisation).Domain 3 · 13% of examSecurity Architecture and EngineeringThe deep-technology domain: secure design principles, the classic security models, cryptography end-to-end, and hardware/trusted systems.Domain 4 · 13% of examCommunication and Network SecurityOSI, protocols, ports, and the devices that guard them.Domain 5 · 13% of examIdentity and Access Management (IAM)Who are you, prove it, what may you do, and how do we hold you accountable.Domain 6 · 12% of examSecurity Assessment and TestingBuilding confidence that controls actually work: vulnerability management, penetration testing, code review, continuous monitoring and the audit/report world (SOC 2, ISO, PCI DSS).Domain 7 · 13% of examSecurity OperationsRunning security day to day: logging, incident response, forensics, backups and disaster recovery, patching, and the SOC tooling (SIEM/SOAR/EDR).Domain 8 · 10% of examSoftware Development SecuritySecurity across the SDLC plus the web-attack playbook.
Exam facts (CAT, English)
- 100–150 questions, 3 hours, adaptive (CAT); linear form elsewhere: 250 questions / 6 hours.
- Pass mark: 700 / 1000 scaled. No penalty for wrong answers — never leave blanks.
- Experience requirement: 5 years cumulative paid work in 2+ domains (or 4 years + a degree/approved credential = 1-year waiver). You can pass FIRST and get endorsed within 9 months.
- Question style: scenario → “BEST” answer. Think risk, cost, and people/process before tooling. When two answers look right, choose the one a senior security advisor would recommend to management.
Six-week study plan
| Week | Focus | Output |
|---|---|---|
| 1 | Domain 1 + risk math drills | Q&A set 1, ALE practice |
| 2 | Domains 2 + 3 (crypto focus) | Model/algorithm flashcards |
| 3 | Domain 4 + port drills | Ports quiz daily |
| 4 | Domains 5 + 6 | Kerberos/SOC2 notes |
| 5 | Domains 7 + 8 + cram sheet | Backup/IR sequences |
| 6 | Practice exam ×3, weak-area review | ≥80% stable |
CISSP® and (ISC)²® are registered trademarks of ISC2, Inc.
This free bootcamp is independent study material and is not affiliated with, sponsored by,
or endorsed by ISC2. See our Disclaimer.