The CISSP CAT Exam: Why Finishing at 100 Questions Tells You Nothing
The English CISSP is Computerized Adaptive Testing: a minimum of 100 items, a maximum of 150, and up to three hours. The pass standard is 700 out of 1000. Those are the facts. The reason this page exists is that the format produces a specific kind of anxiety - an exam that deliberately gives you no feedback, ends without warning, and leaves you walking to the desk with no idea which way it went.
How it actually works
CAT is built on item response theory. Rather than giving everyone the same paper and counting correct answers, it maintains a running estimate of your ability and picks each next item to be maximally informative about that estimate.
- You start with an assumed ability somewhere near the middle.
- Every answer updates the estimate - and so does the difficulty of the item you answered. Getting a hard item right moves it more than getting an easy one right.
- The next item is chosen close to your current estimate, because items far above or below tell the algorithm almost nothing.
- After each answer the algorithm asks: am I now confident this candidate is above or below the standard? Once that confidence is high enough - and no earlier than item 100 - the exam ends.
- If it never reaches that confidence, you continue to 150 items or three hours, whichever comes first.
What the question count actually means
| You finished at… | What it means | What it does not mean |
|---|---|---|
| 100 items | The algorithm reached confidence as early as it possibly could - your performance was consistently clear of the line, in one direction | That you passed. The same speed happens to candidates clearly below the standard |
| Somewhere in between | Confidence arrived once enough evidence accumulated. The overwhelmingly common outcome | Anything you can read either way |
| 150 items | Your estimate sat close to the standard, so it kept asking until items ran out | That you failed. Plenty of people pass at 150 |
| Time expired | Scored on what you answered, provided the minimum was met | An automatic fail |
Why the exam feels brutally hard for everyone
This surprises people who scored well on practice tests. CAT converges on items near the limit of your ability, because those are the ones that carry information. If you are strong, it will find hard items and keep serving them. The experience of "I have no idea about most of these" is the algorithm working correctly, not a verdict.
Perceived difficulty is therefore useless as feedback, for a second reason too: item selection is not purely difficulty-driven. Content balancing rules ensure coverage across the eight domains, so a run of items in your weakest domain can feel like a collapse when it is simply the blueprint being honoured.
Why 700 is not 70%
The pass mark of 700 out of 1000 is a scaled score. It reflects the difficulty of the items you saw, not the raw count you got right. Two candidates can answer the same number correctly and receive different scores because they answered different items.
This has a practical consequence worth internalising: there is no number of questions you need to get right. Answering 65 of 100 hard items can beat answering 80 of 100 easier ones. Passing candidates are not shown a score at all - just a pass. Only failing candidates receive a report, ranked by domain, which is genuinely useful for a resit.
Practical consequences during the exam
- You cannot go back. The next item is selected from your answer to this one, so there is no review screen and no changing your mind later. Decide, commit, move on.
- You cannot skip. Every item must be answered before the next appears. Narrow it down and choose.
- Pace is generous but not infinite. Three hours across up to 150 items is roughly 72 seconds each. Most CISSP items are answerable in under a minute once you know the material; the ones that eat time are the ones you are unsure of - and those are exactly the ones not to spend five minutes on.
- Early items matter more than late ones. The estimate moves furthest when it is least certain. That is an argument for arriving fresh and starting carefully, not for panicking - just do not treat the first twenty as a warm-up.
You cannot practise the format. You can practise the readiness.
Nothing simulates CAT usefully - an adaptive practice exam would stop early and tell you less. What helps is a full-length exam across all eight domains that shows you the shape of your performance, so you walk in knowing no domain is lagging. The code applies itself when you create the account.
CISSP-EXAM-FULL
Redeem the code
Free, no credit card. Already have an account? Log in to start
How to prepare for a format that gives no feedback
Since you cannot read the exam while sitting it, the preparation that matters is the kind that removes the need to:
- Make your domain profile even. CAT will visit all eight. A candidate averaging 82% with nothing below 75% is in far better shape than one averaging 88% with a domain at 55% - the algorithm will find that domain. Use a full-length practice exam's per-domain breakdown rather than a headline score.
- Decide in advance how you will handle not knowing. You will meet items you cannot answer confidently. Have a rule ready: eliminate two, pick the most defensible of the rest, move on inside ninety seconds.
- Rehearse the manager perspective until it is automatic. Under pressure people revert to the technical answer. That reversion is the most common reason strong engineers fail.
- Get the cheap marks reliable - the risk formulas and the security models are the two areas where certainty is achievable, and certainty is worth more than usual on an exam that punishes hesitation.
- Check readiness before booking with the readiness rubric. A resit is another $749 and another wait.
Frequently asked questions
How many questions is the CISSP CAT exam?
Between 100 and 150 items, in a maximum of three hours. The number you get depends on how quickly the algorithm can place you confidently relative to the pass standard.
Does finishing at 100 questions mean I passed?
No. The exam ends when the algorithm is confident you are clearly above or clearly below the standard. Stopping early means the decision was decisive, not favourable. People pass at 100 and people fail at 100.
Is reaching 150 questions a bad sign?
Not in itself. It usually means your ability estimate sat close to the pass standard, so the algorithm kept gathering evidence. Many candidates pass at 150.
What score do I need to pass?
700 of 1000 - a scaled score reflecting item difficulty, not a percentage correct. There is no fixed number of questions you must answer correctly. Passing candidates are not shown a number; only failing candidates get a report, broken down by domain.
Do the questions get harder when I answer correctly?
Broadly, yes - the algorithm targets items near your estimated ability because they are the most informative. But do not use difficulty as feedback. The exam feels hard to everyone by design, and content balancing across the eight domains also drives selection.
Can I skip a question or go back?
Neither. Each item must be answered before the next is chosen, and there is no review at the end - the next question depends on this answer, so the path cannot be rewound.
What happens if I run out of time?
You are scored on what you answered, provided you reached the 100-item minimum. Running out of time is not an automatic fail, though it usually means pacing went wrong somewhere.