GISP logo
Focused certification exam prep
Start practice

GISP Cheat Sheet 2026: One-Page Review of Must-Know Facts

TL;DR
  • GISP is 150 questions, 4 hours, 70% to pass, delivered via ProctorU or Pearson VUE.
  • An attempt costs $999; retakes are $899; extensions are $479.
  • You get 120 days from activation to sit the exam once registered.
  • Printed books and notes are allowed open book; digital references are not.

Exam Snapshot: The Numbers You Need Cold

Before diving into domain content, memorize the mechanics. GISP is a single web-based exam, proctored remotely through ProctorU or in person at a Pearson VUE center. It contains 150 questions that must be completed in 4 hours, and you need 70% correct to pass. These numbers rarely change year to year, but treating them as an afterthought is a common mistake covered in more depth in our GISP Passing Score 2026 guide.

Unlike many vendor certifications that test narrow product knowledge, GISP mirrors the eight domains used by ISC2 for the CISSP exam. That means the question pool draws from a genuinely broad security management curriculum rather than a single technical stack. If you want the full difficulty picture before committing, read How Hard Is the GISP Exam? for context on how the breadth affects study time.

Quick Reference: 150 questions, 4-hour limit, 70% passing threshold, 120-day exam window, four-year certification validity, 36 CPEs to renew. Write these six numbers on an index card before you start studying.

Registration and Fee Mechanics

GISP pricing is straightforward but easy to misjudge if you assume it works like other vendor exams. Current published pricing is:

  • $999 for a standard exam attempt
  • $899 for a retake
  • $479 for an attempt extension (more time on your 120-day window)
  • $399 for an official practice exam
  • $499 for certification renewal

All figures are before applicable tax. Because a retake is nearly as expensive as the original attempt, most candidates find it cheaper to delay scheduling until they're genuinely ready rather than banking on a second try. For a line-by-line breakdown of what each fee covers and when it applies, see GISP Certification Cost 2026: Complete Pricing Breakdown.

One detail candidates frequently miss: the 120-day clock starts at activation, not purchase. If you buy early and don't activate, you preserve flexibility. Once activated, the countdown is fixed unless you purchase an extension. Scheduling logistics, including how testing windows and deadlines interact with this clock, are covered in GISP Exam Dates 2026.

Key Takeaway

Don't activate your GISP exam attempt until your study plan is essentially finished - the 120-day window is generous but not infinite, and an extension costs nearly half of a full retake.

The Eight Domains at a Glance

GISP's content map is identical in structure to the CISSP's eight domains, but expect the depth and phrasing of questions to differ. Below is a compressed reference; for full topic lists and weighting discussion, use GISP Exam Domains 2026: Complete Guide to All 8 Content Areas alongside this sheet.

Domain 1: Security and Risk Management

Foundational governance, legal/regulatory concepts, and risk frameworks.

  • Know CIA triad application, policy hierarchy, and risk assessment methodologies cold

Domain 2: Asset Security

Classification, ownership, and handling requirements across the data lifecycle.

  • Be able to map data classification levels to handling and retention controls

Domain 3: Security Architecture and Engineering

Secure design principles, cryptography, and system architecture models.

  • Distinguish symmetric vs. asymmetric use cases and common architecture pitfalls

Domain 4: Communication and Network Security

Network architecture, protocols, and secure communication channels.

  • Expect scenario questions on OSI-layer attacks and segmentation strategy

Domain 5: Identity and Access Management (IAM)

Authentication, authorization, and identity lifecycle management.

  • Know access control models (RBAC, ABAC, MAC/DAC) and federation concepts

Domain 6: Security Assessment and Testing

Audit strategies, testing methodologies, and vulnerability management.

  • Understand the difference between assessment, testing, and audit deliverables

Domain 7: Security Operations

Incident response, forensics, and day-to-day operational security.

  • Memorize incident response phases and evidence-handling requirements

Domain 8: Software Development Security

Secure SDLC practices and application security controls.

  • Know where security gates belong in each SDLC phase and common OWASP categories

These eight domains aren't weighted evenly on every candidate's exam form, and GIAC does not publish a fixed percentage split for GISP the way some other exams do. Rather than guess at weighting, build competence across all eight and use practice questions to find your personal weak spots - a strategy detailed further in our GISP Study Guide 2026.

Open Book Rules: What You Can Actually Bring

GISP is part of the GIAC practitioner family, and like other GIAC exams it is open book - but the definition is narrower than many candidates expect.

  • Allowed: printed books, printed notes, printed study guides, and physical index materials
  • Not allowed: digital references, laptops, tablets, phones, or any electronic lookup tool

This distinction changes how you should prepare your materials. Instead of relying on a searchable PDF, build a printed, tabbed binder organized by domain so you can flip to the right section in seconds during the 4-hour window. Many candidates print condensed summary sheets for each of the eight domains and keep them at the front of the binder for fast lookups on Domain 4 network diagrams or Domain 5 access control matrices.

Reminder: Because references are physical only, an index becomes as important as the content itself. A well-organized binder can save 15-20 minutes over the course of the exam compared to flipping through unmarked pages.

Scoring, Timing, and the 120-Day Clock

With 150 questions in 4 hours, you have an average of 96 seconds per question - generous compared to many certification exams, but tight if you plan to look up every answer in your printed materials. A workable approach: answer everything you know outright first, flag reference-dependent questions, and use remaining time for lookups. This pacing matters more on GISP than on closed-book exams because the temptation to over-consult your binder can eat the clock quickly.

The 70% passing score applies uniformly; there's no domain-by-domain minimum published, so a strong Domain 1 or Domain 7 score can offset a weaker Domain 8 area, in theory. Still, don't plan around trade-offs - treat all eight domains as pass/fail contributors and study accordingly. Our GISP Pass Rate 2026 analysis discusses how candidates who spread preparation evenly across domains tend to fare better than those who cram one or two areas.

Remember the 120-day activation window. This is not a testing "season" like some certifications use - it's an individual countdown that starts the moment you activate your specific attempt. Missing it means forfeiting the attempt unless you've purchased an extension in advance.

A Domain-Aware Final Review Schedule

If you're in the final stretch before your GISP attempt, don't just review randomly - sequence your last weeks around domains that are historically dense or unfamiliar to security generalists.

Week 1

Governance-heavy domains

  • Domain 1 (Security and Risk Management) and Domain 2 (Asset Security) - these lean conceptual and reward memorization of frameworks and classification schemes
Week 2

Technical architecture

  • Domain 3 (Security Architecture and Engineering) and Domain 4 (Communication and Network Security) - allocate extra time here if your background isn't network-heavy
Week 3

Access and assessment

  • Domain 5 (IAM) and Domain 6 (Security Assessment and Testing) - practice distinguishing overlapping terminology between assessment types
Week 4

Operations and development, then full review

  • Domain 7 (Security Operations) and Domain 8 (Software Development Security), followed by a full-length practice exam and binder finalization

This is one of the few places where general study techniques apply directly: spaced repetition on flashcards for the acronym-heavy domains (5, 6, and 8 especially) tends to outperform passive re-reading. Beyond that, keep your prep GISP-specific rather than generic - the exam rewards recognizing scenario-based phrasing unique to GIAC's question style, which you can practice on our GISP practice test platform.

Certification Life Span and Renewal

Once earned, GISP stays active for four years. Renewal requires 36 CPEs and a $499 fee - considerably cheaper than a fresh attempt, which is why maintaining CPE records throughout your certification period matters more than scrambling at year four.

ItemCostNotes
Exam Attempt$999Includes 120-day activation window
Retake$899Required after a failed attempt
Attempt Extension$479Extends the activation window
Practice Exam$399Official GIAC practice option
Renewal (every 4 years)$499Requires 36 CPEs

Comparing these figures against the value of the credential is a common question among prospective candidates. If you're still deciding whether to invest, Is the GISP Certification Worth It? Complete ROI Analysis 2026 weighs the cost against career outcomes without relying on invented statistics.

Who Actually Hires GISP Holders

Because GISP maps to the same eight domains used for the CISSP, it's frequently pursued by security professionals who want broad managerial and technical credibility without committing to CISSP's experience-heavy prerequisites - though it's worth confirming your own eligibility path, which is covered in GISP Requirements 2026: Eligibility, Prerequisites & How to Qualify.

Typical roles associated with the credential include security analysts, security engineers, compliance and risk specialists, and IT auditors moving into broader security management functions. Government and defense-adjacent employers, in particular, often recognize GIAC certifications alongside or in place of ISC2 credentials for DoD 8570/8140-aligned positions. For a closer look at role types and postings that reference the credential directly, see GISP Jobs.

If you're earlier in your research and still mapping out what the letters mean and how the certification fits into a broader career plan, our foundational pieces - What Is GISP?, GISP Meaning, and What Does GISP Stand For? - cover the basics before you commit to a study plan. For salary context tied to real data rather than assumptions, review the GISP Salary Guide 2026.

Formal Training Note: GIAC exams don't require a specific training course, but structured preparation reduces wasted study time across eight broad domains. See GISP Training for options, and browse the full practice test library to test domain readiness before exam day.

FAQ

How many questions are on the GISP exam and how much time do I get?

The GISP exam has 150 questions, and you're given 4 hours to complete it. You need to score at least 70% to pass.

Can I use my phone or a PDF during the GISP exam?

No. GISP is open book for printed materials only - physical books, notes, and study guides. Digital references, including PDFs on a laptop or phone, are not permitted.

What happens if I don't pass on my first attempt?

You can register for a retake at $899. Given the cost, most candidates use full-length practice exams to confirm readiness before scheduling a second attempt.

How long do I have to schedule and take the exam after registering?

You have 120 days from activation to complete the exam. If you need more time, an attempt extension is available for $479.

How often do I need to renew GISP, and what does renewal require?

GISP certification is valid for four years. Renewal requires 36 continuing professional education (CPE) credits and a $499 renewal fee.

Ready to pass your GISP exam?

Put this into practice with free GISP questions across every exam domain.