““Excellent coverage of ISSAP architecture concepts.””
Siddharth A
Security Architect
Practice Tests Will Be Available Soon
We are preparing practice tests for this exam. Please check back shortly.
ISC2 rewrote the ISSAP exam outline effective August 1, 2025, collapsing what used to be six architecture domains into four — and folding application security and physical security into the survivors rather than keeping them as standalone sections. If you studied from an older ISSAP guide, or you're using a friend's notes from two years ago, you're working from a syllabus that no longer matches what's tested. This page is built against the current four-domain outline, so what you practice here is what you'll actually see.
ISSAP is not a knowledge-recall exam the way parts of the CISSP can feel. It's a design-judgment exam. Nearly every question hands you a scenario — a merger, a regulatory audit, a legacy system migration, a cloud repatriation — and asks which architectural decision holds up under scrutiny, not which term matches a textbook definition. The four domains, per the current ISC2 outline:
Domain 1: Governance, Risk, and Compliance (GRC) — identifying legal, regulatory, and contractual requirements; designing for auditability; risk treatment decisions (mitigate, transfer, accept, avoid); monitoring and reporting design.
Domain 2: Security Architecture Modeling — choosing and applying frameworks like TOGAF and SABSA, reference architectures, threat modeling (STRIDE, CVSS), and validating a design through code review, tabletop exercises, or simulation.
Domain 3: Infrastructure and System Security Architecture — this is the heaviest domain by a wide margin, spanning network, platform, storage, endpoint, OT/ICS, cloud (IaaS/PaaS/SaaS), and cryptographic architecture, including key management lifecycle.
Domain 4: Identity and Access Management (IAM) Architecture — identity lifecycle, authentication protocols (SAML, RADIUS, Kerberos, OAuth), authorization models (RBAC, ABAC, PAM), and identity accounting for forensic and compliance requirements.
Weighting isn't published by ISC2 down to the percentage point on their public outline page, but based on how the domain content is structured, Domain 3 (Infrastructure and System Security) and Domain 4 (IAM) together account for roughly half or more of the exam — which tells you where to put your heaviest study hours if your time is limited.
ISSAP candidates are almost never first-time security professionals. Two paths qualify you: hold an active CISSP plus two years of cumulative experience in one or more of the four domains, or — since ISSAP became a standalone credential in October 2023 — accumulate seven years of experience across two or more domains without ever sitting the CISSP. In practice, most candidates are solution architects, security architects moving from a hands-on engineering role into a design-authority role, or senior consultants who need the credential to bid on government or enterprise architecture contracts that list ISSAP as a named requirement. It's rare to see someone attempt this without several years of actual infrastructure or identity design work behind them, because the scenario questions assume you've already lived through the trade-offs.
The official ISSAP exam runs 125 multiple-choice questions (a mix of single-answer and multiple-answer items) over 3 hours, delivered at a Pearson VUE test center or via remote proctoring. Unlike the CISSP itself, ISSAP is not computer-adaptive — you get the full 125 questions regardless of how you're performing, so pacing matters differently. A passing scaled score is 700 out of 1000.
The most common time-pressure trap: multiple-answer questions ("select all that apply" or "select two") take noticeably longer to reason through than single-answer ones, and Domain 3's cryptography and cloud-deployment scenarios tend to cluster several of these together. Candidates who pace themselves for 125 single-answer questions often find themselves rushing the last 20–25 questions.
Don't drill Domain 3 and Domain 4 in isolation and treat GRC (Domain 1) as an afterthought — a meaningful share of scenario questions blend domains, asking you to justify an infrastructure decision using a governance or risk-treatment rationale. When you miss a practice question, don't just re-read the correct answer; ask which of the four architectural approaches (mitigate, transfer, accept, avoid; or which framework, TOGAF vs. SABSA) the question was actually testing your ability to choose between, since ISSAP repeatedly tests judgment between two defensible-sounding options rather than one obviously wrong answer among distractors.
The most frequent failure pattern is answering from a pure engineering mindset instead of an architecture mindset — picking the technically strongest control instead of the one that best satisfies the stated business, risk, or compliance constraint in the scenario. A close second: treating cloud security (folded into Domain 3 under the current outline) as a separate specialty to cram at the last minute, when it's now woven directly into the infrastructure domain alongside on-prem and OT/ICS content. Candidates who studied from a pre-2025 ISSAP guide also frequently misjudge domain weight, because the old six-domain breakdown no longer maps cleanly onto the current four.
Read the full Domain 3 outline line by line before you touch practice questions — it covers physical security, platform, network, storage, cloud, OT, and cryptography all in one domain, and candidates consistently underestimate how much of the exam lives there. For Domain 4, don't just memorize what SAML or OAuth do; be ready to justify when you'd architect around one authentication protocol versus another given a stated trust boundary or federation requirement, since that's the level the questions operate at. If your professional experience is concentrated in one domain (say, you've spent years in IAM but never touched OT/ICS architecture), budget disproportionate study time for your weakest domain rather than your strongest, since ISSAP doesn't let a strong domain offset a weak one the way a purely additive score might suggest.
Work through the domain-by-domain practice sets below, starting with Domain 3 given its weight, then check your results against the current four-domain outline rather than any older six-domain study guide you may already have.
Last updated on Sep, 1 2026