CISSP · Professional
Certified Information Systems Security Professional
Apply security governance, engineering, identity, assurance and operational decisions across an enterprise.
Your free account includes a full CISSP practice exam.
ExamNova practice
Your first session
- Questions
- 150
- Time limit
- 180 min
- Coverage
- 8 domains
Practise, review your answers and see where to focus next.
Is CISSP your next step?
Explore the coverage below to see how this certification fits your study goals.
What you’ll study
Your CISSP practice covers every domain on the exam.
- Security and Risk Management
- Asset Security
- Security Architecture and Engineering
- Communication and Network Security
- Identity and Access Management (IAM)
- Security Assessment and Testing
- Security Operations
- Software Development Security
Consult the official guide for the vendor’s current exam outline.
Put it into practice.
Explore hands-on tasks connected to CISSP. These are real Labs from the catalogue.
Repair inherited access and enforce conflicting-role boundaries
Edit role-review.json. roles contains unique {id,permissions,inherits}; assignments contains one {user,roles} for each supplied user; sessions contains one {id,user,activeRoles} for each supplied session, without changing its user. Referenced roles must exist and inheritance must be acyclic. Use only the seven supplied permission IDs. Bounds: at most 12 roles, 8 users and 12 sessions; each ID is ASCII letters, digits, hyphens or underscores, 1..60 characters. Arrays have no duplicate values. Repair all direct/transitive excess, current static assignment conflicts and current dynamic activation conflicts. Keep every required operation available: a rejected activation grants no permissions. separation has static and dynamic arrays of distinct two-permission pairs. Static needs [vendor-prepare,vendor-approve]; dynamic needs [invoice-prepare,invoice-approve]. Each may hold at most eight pairs. enforcement has assignment and activation, each reject or log. Log records a conflict but permits it. Future probes enumerate every role subset through actual inheritance; assignment proposals with a static conflict and authorized activation proposals with a dynamic conflict must be rejected. Safe current snapshots alone do not satisfy prevention. You may restructure role edges/permissions or redesign assignments; equivalent safe strategies are accepted. Legacy roles may remain unused. Review named failures, save partial progress, repair without Reset and rerun. Reset restores the unsafe starter. This simulated model permits different sessions for invoice duties and does not check per-invoice history.
medium · About 30 min
LabTest operating evidence for change approvals
Write one read-only query over changes, approvals and approvers. Return exactly service, total_changes, exceptions, one row per service with production changes implemented from minute 100 inclusive to 200 exclusive. changes has one row per change_id; retain changes with no approval in the denominator. A valid review has the same change_id, a reviewer different from the implementer, and an approvers row for that reviewer AND service where valid_from <= approved_min < valid_until. Normal reviews must be at or before implemented_min; an emergency review may be no later than implemented_min + 15. Earlier authorized reviews are valid for either type. A critical=1 change needs at least two DISTINCT valid reviewers; critical=0 needs one. Count the change as one exception if that quorum is missing. Repeated approvals by one person add no reviewer; extra eligible reviewers do not add tested changes. Unknown, wrong-service and expired reviewers add none. Group by actual service; row order is unrestricted. An empty population returns no rows. Derive the report for new identifiers and repair defects without Reset. These deadlines and quorums are the supplied fictional policy, not universal NIST criteria.
hard · About 35 min
Make CISSP your next step.
Create your free account. Start practising.
Start Free