The CISSP CAT Exam: Why Finishing at 100 Questions Tells You Nothing

By Moussa BENALI, Senior Network & Security Engineer · Exam format verified against ISC2

The English CISSP is Computerized Adaptive Testing: a minimum of 100 items, a maximum of 150, and up to three hours. The pass standard is 700 out of 1000. Those are the facts. The reason this page exists is that the format produces a specific kind of anxiety - an exam that deliberately gives you no feedback, ends without warning, and leaves you walking to the desk with no idea which way it went.

💡
The single most important thing to know: the exam stops as soon as the algorithm is confident your ability is clearly above or clearly below the pass standard. Confidence can be reached in either direction. Finishing at 100 items means the decision was decisive - not that it was good. People pass at 100 and people fail at 100.

How it actually works

CAT is built on item response theory. Rather than giving everyone the same paper and counting correct answers, it maintains a running estimate of your ability and picks each next item to be maximally informative about that estimate.

  1. You start with an assumed ability somewhere near the middle.
  2. Every answer updates the estimate - and so does the difficulty of the item you answered. Getting a hard item right moves it more than getting an easy one right.
  3. The next item is chosen close to your current estimate, because items far above or below tell the algorithm almost nothing.
  4. After each answer the algorithm asks: am I now confident this candidate is above or below the standard? Once that confidence is high enough - and no earlier than item 100 - the exam ends.
  5. If it never reaches that confidence, you continue to 150 items or three hours, whichever comes first.

What the question count actually means

You finished at…What it meansWhat it does not mean
100 itemsThe algorithm reached confidence as early as it possibly could - your performance was consistently clear of the line, in one directionThat you passed. The same speed happens to candidates clearly below the standard
Somewhere in betweenConfidence arrived once enough evidence accumulated. The overwhelmingly common outcomeAnything you can read either way
150 itemsYour estimate sat close to the standard, so it kept asking until items ran outThat you failed. Plenty of people pass at 150
Time expiredScored on what you answered, provided the minimum was metAn automatic fail
⚠️
The trap this creates. Candidates start counting. At item 100 the screen does not stop, and they conclude they are failing. Their focus goes, and the remaining fifty items are answered by someone who has already given up. That is a self-inflicted fail on an exam that was still winnable. The count is not a signal. Do not read it.

Why the exam feels brutally hard for everyone

This surprises people who scored well on practice tests. CAT converges on items near the limit of your ability, because those are the ones that carry information. If you are strong, it will find hard items and keep serving them. The experience of "I have no idea about most of these" is the algorithm working correctly, not a verdict.

Perceived difficulty is therefore useless as feedback, for a second reason too: item selection is not purely difficulty-driven. Content balancing rules ensure coverage across the eight domains, so a run of items in your weakest domain can feel like a collapse when it is simply the blueprint being honoured.

Why 700 is not 70%

The pass mark of 700 out of 1000 is a scaled score. It reflects the difficulty of the items you saw, not the raw count you got right. Two candidates can answer the same number correctly and receive different scores because they answered different items.

This has a practical consequence worth internalising: there is no number of questions you need to get right. Answering 65 of 100 hard items can beat answering 80 of 100 easier ones. Passing candidates are not shown a score at all - just a pass. Only failing candidates receive a report, ranked by domain, which is genuinely useful for a resit.

Practical consequences during the exam

Your free CISSP exam code

You cannot practise the format. You can practise the readiness.

Nothing simulates CAT usefully - an adaptive practice exam would stop early and tell you less. What helps is a full-length exam across all eight domains that shows you the shape of your performance, so you walk in knowing no domain is lagging. The code applies itself when you create the account.

CISSP-EXAM-FULL Redeem the code

Free, no credit card. Already have an account? Log in to start

How to prepare for a format that gives no feedback

Since you cannot read the exam while sitting it, the preparation that matters is the kind that removes the need to:

  1. Make your domain profile even. CAT will visit all eight. A candidate averaging 82% with nothing below 75% is in far better shape than one averaging 88% with a domain at 55% - the algorithm will find that domain. Use a full-length practice exam's per-domain breakdown rather than a headline score.
  2. Decide in advance how you will handle not knowing. You will meet items you cannot answer confidently. Have a rule ready: eliminate two, pick the most defensible of the rest, move on inside ninety seconds.
  3. Rehearse the manager perspective until it is automatic. Under pressure people revert to the technical answer. That reversion is the most common reason strong engineers fail.
  4. Get the cheap marks reliable - the risk formulas and the security models are the two areas where certainty is achievable, and certainty is worth more than usual on an exam that punishes hesitation.
  5. Check readiness before booking with the readiness rubric. A resit is another $749 and another wait.

Frequently asked questions

How many questions is the CISSP CAT exam?

Between 100 and 150 items, in a maximum of three hours. The number you get depends on how quickly the algorithm can place you confidently relative to the pass standard.

Does finishing at 100 questions mean I passed?

No. The exam ends when the algorithm is confident you are clearly above or clearly below the standard. Stopping early means the decision was decisive, not favourable. People pass at 100 and people fail at 100.

Is reaching 150 questions a bad sign?

Not in itself. It usually means your ability estimate sat close to the pass standard, so the algorithm kept gathering evidence. Many candidates pass at 150.

What score do I need to pass?

700 of 1000 - a scaled score reflecting item difficulty, not a percentage correct. There is no fixed number of questions you must answer correctly. Passing candidates are not shown a number; only failing candidates get a report, broken down by domain.

Do the questions get harder when I answer correctly?

Broadly, yes - the algorithm targets items near your estimated ability because they are the most informative. But do not use difficulty as feedback. The exam feels hard to everyone by design, and content balancing across the eight domains also drives selection.

Can I skip a question or go back?

Neither. Each item must be answered before the next is chosen, and there is no review at the end - the next question depends on this answer, so the path cannot be rewound.

What happens if I run out of time?

You are scored on what you answered, provided you reached the 100-item minimum. Running out of time is not an automatic fail, though it usually means pacing went wrong somewhere.