The vast majority of current CISSPs took their test in the old format. The test was a grueling 250 question test in which nearly 85% of the testers would take the entire allotted 6 hour exam time. But the exam was modernized at the end of 2017
The CISSP exam is now a “Smart Exam.”
Beginning in December of 2017, the CISSP exam was changed to an adaptive format. The official name for this is Computerized Adaptive Exam (CAT). The CISSP is one of the first certification exams to move to this new platform. But the rest will soon follow.
The adaptive format helps prevent cheating.
Since IT certifications are valuable, folks have a high incentive to try to take study shortcuts by cheating. This cheating incentive has lead to online marketplaces where you can buy questions and answers.
Older article, current brief.
This article gives you the background. The brief gives you what changed next.
Get the weekday cyber brief for hiring signals, skills shifts, and major cyber developments shaping the market now.
Free. Weekday mornings. 5 minutes or less.
Built from 100+ trusted cybersecurity sources.
If you do a web search for “CISSP Brain Dump”, you will find many websites that sell practice exams that claim to be actual exam questions. The CISSP exam has always maintained a high security and integrity level in keeping their test questions out of reach for cheaters trying to buy the questions and answers.
Some nefarious companies pay people to take tests and attempt to record the questions or memorize the questions to write them down.
The adaptive format of the CISSP exam adds a higher layer of security to the test. An exam taker no longer has access to all of the questions on the test. An unprepared test taker will receive very few questions that would lead to a passing score.
Here is how the CISSP Adaptive Test Works
First, you will go through the very high standard of security at the testing center – The ID check, Photo, Biometric Hand Scan, etc. – then they will escort you to the testing room. You will be on camera at all times, and the test administrator will watch from behind a glass window.
You will sit down at your testing station and receive instructions on how the test works and the testing terminal’s general functionality.
The test will start with questions that are quite easy. These questions test knowledge that is well below the standard required for passing the exam.
After you answer each question, the testing algorithm determines your competence by analyzing your completed questions and answers.
The algorithm analyzes many factors. The exact details of the algorithm are proprietary, but the following list of likely factors.
- The correctness of the answer – Was the “best correct” answer chosen?
- The candidate’s aptitude on each of the testing domains based on the questions answered correctly.
- The candidate’s ability to know or ascertain the best answer on obscure domain topics
- The time that it takes the candidate to answer each question (This data is used to help identify potential cheaters)
After you answer one question, the next one is determined.
Based on the above factors, the next question to be presented is determined. The candidate cannot go back and change previous answers because the answers are locked in as soon as you click the “Submit” button.
If you answer a question correctly, then the next question will be 50% more difficult to answer. In other words, there will be a 50% greater chance that you will get the next question wrong.
Older article, current brief.
This article gives you the background. The brief gives you what changed next.
Get the weekday cyber brief for the new exploitation, policy moves, and risk shifts this article could not cover when it was published.
Free. Weekday mornings. 5 minutes or less.
Built from 100+ trusted cybersecurity sources.
Get a question right, and the test gets harder – much harder!
The questions get exponentially more difficult as you continue to do answer correctly. The algorithm’s objective is to test your breaking point: The point at which you can no longer answer the questions correctly.
Your breaking point determines your success on the CISSP exam.
The exam candidate will undoubtedly get to the point where the test questions are so obscure that the answers will come down to educated guesses. The further you get while maintaining an overall score of at least 80% in each testing domain will determine if you pass the whole exam.
Is the Adaptive CISSP exam harder than the old one?
The adaptive CISSP exam will seem pretty tricky because if the tester does well, the questions will get to the point that they seem almost impossible to answer. The test may be considered more comfortable because it is no longer a marathon 6-hour test with 250 questions. Most test-takers will complete the test when the question count reaches between 100 and 150.
Most people – including me – have never taken both the old format CISSP and the new format adaptive CISSP test. Therefore, it is difficult to say which format is harder.
The old format may be more difficult for some people due to the stamina required to sit and concentrate for 6 hours. For others, the new format might be more of a challenge because of the questions’ escalating difficulty.
In theory, both formats of the test are equally challenging to pass. This is the stance and the objective of the adaptive test according to ISC2.
Don’t let the CISSP test scare you.
Part of the value of holding a CISSP certification is that it is difficult to obtain. Not everybody is going to pass this test. However, that does not mean that you can’t do it. If you prepare well, understand the material, and do a ton of practice questions, you can certainly succeed on the exam! A great study plan worked for me: How to pass the CISSP exam without reading any books.
Newer CyberExperts coverage on this topic
This article still works as background. If you want the current picture, start with the freshest related coverage below and today's brief.
How to Stay Secure Managing End-of-Life Software
Legacy software often operates under the "if it isn't broken, don't fix it" mentality until a security crisis forces action. However, managing...
Best 6 Tools to Eliminate CVEs in Container Images
Key Takeaways Container image CVEs often come from inherited base image packages, not only application code. The strongest tools reduce vulnerabilities before...
8 Best Virtual CISO Companies of 2026
The virtual CISO market has changed. A few years ago, many companies hired a vCISO mainly to prepare for SOC 2, satisfy...
The 5-Minute Cyber Brief: September 3, 2026
The fastest way to catch up on what changed after this article was published.