ISC2 Certified Information Systems Security Professional (CISSP) (2024) Cert Prep

Master CISSP domains and pass the exam

Duration 21h 27m Rating (4.9) Price Included with subscription on LinkedIn Learning
Created by Mike Chapple
Last updated 2024-04-25
Platform: LinkedIn Learning Topic: IT Certifications Network & Security Skills: CISSP Identity and Access Management Network Security

ISC2 Certified Information Systems Security Professional (CISSP) (2024) Cert Prep is an instructor-led certification course on LinkedIn Learning taught by Mike Chapple that targets candidates preparing for the ISC2 CISSP exam. It delivers a structured, domain-by-domain review of the CISSP body of knowledge to align study with the certification blueprint.

Designed for security practitioners seeking focused exam preparation, the course combines conceptual explanation with practical guidance and exam-relevant practice to help learners apply core principles in realistic contexts. It emphasizes domains such as security and risk management, network and communication security, identity and access management, security assessment and operations, and software development security to close knowledge gaps before sitting the exam.

At a Glance

ISC2 Certified Information Systems Security Professional (CISSP) (2024) Cert Prep is a comprehensive CISSP exam-preparation course taught by Mike Chapple.

The course broadly covers the CISSP domains, including security and risk management, asset security, security architecture and engineering, communication and network security, identity and access management, security assessment and testing, security operations, and software development security.

Level Advanced
Rating 4.9 out of 5
Duration 20+ hours
Languages English
Certificate Certificate of Completion (shareable)
Access Access while your LinkedIn Learning subscription is active (free trial available)
Course includes
  • Video lessons
  • Exercise file
  • 51 quizzes
  • Mobile access and offline downloads
  • Continuing education units
Price Subscription-based (monthly or annual plans); free trial available

What This Course Teaches

The course frames outcomes as measurable competencies tied to CISSP domains so learners can demonstrate applied knowledge and exam-relevant skills.

Network Security
Implement and configure network security controls and analyze network designs to protect confidentiality and availability.
Information Security
Explain and apply core information security principles such as confidentiality, integrity, and availability to evaluate protections across systems.
Security Assessments
Perform vulnerability scans and analyze assessment results to prioritize remediation and improve security posture.
Security Operations
Build incident response procedures and practice forensic-handling steps to investigate and recover from security incidents.

How the Course Is Structured

The course is organized as a detailed, chapter-style syllabus spanning the full CISSP body of knowledge.

It is presented as 67 modules/sections and runs about 20+ hours in total.

Curriculum overview

01The CISSP Exam

Overview of the CISSP exam scope, purpose, and candidate considerations.

02Inside the CISSP Exam

Explains registration, exam environment, question types, and computerized adaptive testing.

03Preparing for the Exam

Practical study tips and recommendations for practice tests to ready candidates.

04Experience Requirement

Describes professional experience, endorsement, and continuing education requirements for CISSP.

05Domain 1: Security and Risk Management

Introduces the Security and Risk Management domain and its key themes.

06Security Fundamentals

Covers core principles such as the five pillars of information security and related concepts.

07Security Governance

Examines alignment of security with business objectives and organizational control frameworks.

08Compliance and Ethics

Addresses legal, privacy, and ethical issues including GDPR and other data-protection topics.

09Security Policy

Discusses security policy frameworks and how to craft and manage security policies.

10Business Continuity

Covers business continuity planning, high availability, and fault-tolerance strategies.

11Personnel Security

Reviews hiring, termination, privacy, and personnel-related security controls.

12Risk Management

Explains risk analysis, quantitative assessment, treatment, and continuous monitoring processes.

13Threat Modeling

Introduces threat intelligence, hunting, and methods for identifying and modeling threats.

14Supply Chain Risk Management

Covers vendor management, agreements, and cloud-audit considerations for supply-chain risks.

15Awareness and Training

Focuses on designing and measuring security awareness and compliance training programs.

16Domain 2: Asset Security

Introduces the Asset Security domain and principles for protecting information assets.

17Data Security

Explores data security policies, roles, lifecycle, and limits on data collection.

18Data Security Controls

Discusses baselines, standards, cloud storage security, classification, and DLP techniques.

19Change and Configuration Management

Covers change-management processes, configuration controls, and physical asset handling.

20Domain 3: Security Engineering

Introduces security architecture and engineering principles for secure systems design.

21Secure Design

Reviews secure-design principles, models, secure defaults, and privacy-by-design concepts.

22Virtualization and Cloud Computing

Explains cloud concepts, deployment and service models, virtualization, and containerization security.

23Hardware Security

Covers hardware and firmware protections, memory protection, and hardware encryption topics.

24Server Security Issues

Addresses server and database security, NoSQL considerations, and distributed computing risks.

25Embedded Systems Security

Discusses IoT and industrial control security, securing smart and embedded devices.

26Encryption

Introduces cryptographic goals, algorithms, and the cryptographic lifecycle.

27Symmetric Cryptography

Covers symmetric algorithms, modes, and historical ciphers such as DES and AES families.

28Asymmetric Cryptography

Explains RSA, PGP/GnuPG, elliptic-curve topics and considerations for quantum threats.

29Key Management

Discusses key exchange, escrow, stretching, and hardware security modules for key lifecycle management.

30Public Key Infrastructure

Covers PKI concepts, certificates, authorities, signing, and revocation mechanics.

31Cryptanalytic Attacks

Reviews attack types against cryptography including brute-force, implementation, and eavesdropping attacks.

32Physical Security

Discusses site design, environmental controls, access control, and data-center protections.

33Software Security Architecture

Introduces architectural topics such as SOAP/REST, SOA, and microservices security considerations.

34Domain 4: Communication and Network Security

Introduces network and communication security domain concepts and scope.

35TCP/IP Networking

Covers TCP/IP fundamentals, addressing, DNS, ports, ICMP, and multilayer protocols.

36Secure Network Design

Explores secure network architectures, segmentation, VLANs, security zones, and device placement.

37Network Security Devices

Reviews routers, firewalls, IDS/IPS, VPNs, proxies, load balancers, and related devices.

38Network Security Techniques

Covers access restriction, firewall rule management, monitoring, logging, and availability practices.

39Specialized Networking

Addresses telephony, multimedia collaboration, and storage-network security topics.

40Transport Encryption

Explains TLS/SSL, IPsec, and secure remote access mechanisms.

41Wireless Networking

Covers wireless fundamentals, encryption, authentication, and signal propagation considerations.

42Mobile Device Security

Discusses mobile MDM, tracking, app security, BYOD, and deployment models.

43Host Security

Covers OS security, malware prevention, application management, and host-based controls.

44Domain 5: Identity and Access Management

Introduces IAM concepts and scope within CISSP.

45Identification

Discusses identification processes including identity proofing and biometric considerations.

46Authentication

Covers authentication factors, MFA, protocols like Kerberos/LDAP, SAML, OAuth, and passwordless methods.

47Accountability

Examines session management, logging, and accountability mechanisms for user actions.

48Account Management

Covers provisioning, deprovisioning, password policies, roles, and account-monitoring practices.

49Authorization

Explains access control models, ACLs, database access controls, and advanced authorization concepts.

50Access Control Attacks

Reviews social-engineering vectors, impersonation, identity fraud, and physical social engineering tactics.

51Domain 6: Security Assessment and Testing

Introduces assessment and testing practices for identifying security weaknesses.

52Vulnerability Scanning

Explains vulnerability-management concepts, scan configuration, and report analysis.

53Penetration Testing

Covers pen-testing methodology, ethical disclosure, bug-bounty programs, and exercises.

54Log Reviews

Discusses logging, SIEM, continuous monitoring, and endpoint telemetry review.

55Code Testing

Covers code review, fuzz testing, test coverage, and interface and misuse-case testing.

56Disaster Recovery Planning

Addresses backups, recovery sites, testing BC/DR plans, and after-action reporting.

57Assessing Security Processes

Covers collecting process data, audits, metrics, and control-management review procedures.

58Domain 7: Security Operations

Introduces operations topics including monitoring, response, and operational controls.

59Investigations and Forensics

Reviews forensic processes, types of evidence, network and file forensics, and chain-of-custody.

60Privilege Management

Discusses least-privilege models and privileged-account management practices.

61Incident Management

Outlines building incident-response programs, identification, escalation, containment, and recovery steps.

62Personnel Safety

Covers emergency management and personnel safety considerations during operations and incidents.

63Domain 8: Software Development Security

Introduces application and development security topics and their role in CISSP.

64Software Development Lifecycle

Covers development methodologies, SDLC models, automation, and DevOps security concerns.

65Application Attacks

Reviews common application attacks including OWASP Top Ten and prevention techniques.

66Secure Coding Practices

Covers input validation, parameterized queries, output encoding, and secure error-handling practices.

67What’s Next

Final guidance on preparing for the exam and suggested next steps for study.

Audience & Requirements

This course is aimed at experienced security professionals preparing specifically for the CISSP exam and practitioners who need a systematic, domain-by-domain review.

It is appropriate for professionals who already work with security controls or governance and who want an exam-focused consolidation of the CISSP body of knowledge.

Who It’s For
  • Security professionals preparing for the CISSP certification.
  • Security managers and architects seeking a structured domain review.
  • IT auditors and compliance specialists wanting CISSP-aligned knowledge.
  • Experienced IT practitioners transitioning into security-focused roles.
What You’ll Need
  • Prior cybersecurity experience or strong familiarity with core security concepts is recommended.
  • Working knowledge of networking, cryptography, and risk-management fundamentals.
  • Active LinkedIn Learning subscription to access the course materials.
  • No special software or hardware; the course delivers videos, quizzes, and an exercise file.

Final Verdict

Recommended for experienced security professionals and CISSP candidates who need a structured, domain-by-domain review and exam-focused consolidation.

Given its strong platform rating and wide learner adoption, the course is an efficient, instructor-led way to reinforce the full CISSP body of knowledge before taking the exam and pairs well with targeted practice tests and hands-on study. Value is highest for learners who already use the host platform’s subscription—access and a shareable completion certificate are included—while those without prior cybersecurity experience should complete foundational materials first to get the most from this course.

Course Details

Platform LinkedIn Learning
Rating (4.9)
Duration 21h 27m
Level Advanced
Language English
Price Included with subscription
View on LinkedIn Learning