Udemy
    •  
    •  
    •  
    •  
    •  
    •  
    •  
    •  
Turn what you know into an opportunity and reach millions around the world.
Learn More
Your cart is empty.
Keep shopping
CISSP 2026: Full Exam Prep + CMMC & NIST 800-171
Hot & New
New
Rating: 5.0 out of 5(2 ratings)
104 students

CISSP 2026: Full Exam Prep + CMMC & NIST 800-171

Master all 8 CISSP domains and go deeper into CMMC, CUI, DFARS, FedRAMP, and NIST 800-171 Rev 3
Last updated 7/2026
English
English [Auto],

What you'll learn

  • CISSP Domain 1: Security & Risk Management (16%)
  • CISSP Domain 2: Asset Security (10%)
  • CISSP Domain 3: Security Architecture & Engineering
  • CISSP Domain 4: Communication & Network Security (13%)
  • CISSP Domain 5: Identity & Access Management (13%)
  • CISSP Domain 6: Security Assessment & Testing (12%)
  • CISSP Domain 7: Security Operations (13%)
  • CISSP Domain 8: Software Development Security (10%)
  • The GRC & Compliance Mega Section ( Additional Content)
  • CISSP Topics Deep Dive ( Additional content)
  • The Anatomy of NIST SP 800-171r3 ( Additional Content)

Course content

14 sections84 lectures11h 3m total length
  • who I am, why I built this course, who it's for, how the CISSP exam works7:40

    Welcome to CISSP A–Z (2026)

    This is your complete, all-in-one path from zero to CISSP-ready — and then further than any other course takes you.

    What to expect: I walk you through all eight CISSP domains, aligned to the current ISC2 exam outline (effective April 15, 2024, current through 2026), with AI and machine-learning risk woven in exactly the way the exam now tests it. Every lesson is tagged by level, so newcomers get the fundamentals in plain English and seasoned pros get advanced depth they won't find elsewhere.

    How it's built: Each topic comes as a short, focused video lesson paired with a downloadable student study guide for that session — read it, highlight it, make it yours. On top of that, you get a comprehensive master study guide covering the entire course, plus a full test bank of exam-style practice questions to drill your readiness. Watch, read, review, and test yourself all the way to exam day. You'll also get exam tips, common traps to avoid, real-world war stories from my assessment work, and knowledge-check questions to lock it in.

    The bonus that sets us apart: A full GRC and compliance deep-dive — CUI, CMMC, DFARS, the FAR, FedRAMP, and a control-family-by-family walkthrough of NIST SP 800-171 Rev 3 — taught by someone who assesses these environments for a living.

    Follow the sections in order, or jump to what you need. You'll leave exam-ready and job-ready.

    — Dr. Dwayne Hodges, CISSP

  • CISSP Exam Preparation10:27

    Explore a practical CISSP exam prep roadmap covering the eight domains, adaptive testing, passing criteria, the ISC2 common body of knowledge, and the endorsement path to earn the credential.

Requirements

  • No prior cybersecurity experience is required. This course is built A–Z. Foundation lessons assume zero background and define every term in plain English, so career changers and students can start here cold. Basic computer and internet literacy. If you can navigate a computer, use a browser, and follow along with slides, you're ready. A willingness to learn the vocabulary. Security has a language of its own. I introduce every concept in everyday terms first, then attach the official term — you just need to show up and engage. No textbook or paid materials to buy. Everything is taught from authoritative primary sources (NIST, ISC2, the CFR, FedRAMP, Cyber AB). You don't need to purchase anything extra to follow the course. Helpful but not required: general IT or networking familiarity will let you move faster through the core domains. Seasoned pros can skip the foundation on-ramps and go straight to the core and advanced material. One important note about the credential itself: This course prepares you to pass the CISSP exam. To become fully CISSP-certified, ISC2 requires five years of cumulative, paid work experience across two or more of the eight domains. If you don't have that experience yet, you can still sit the exam and become an Associate of ISC2 while you build toward it. I'll explain exactly how that path works inside the course.

Description

This course contains the use of artificial intelligence.

Over 11 hours and 83 video lectures, a student study guide for every domain, and a full test bank of  over 1000 exam-style practice questions — everything you need to go from zero to CISSP-ready

If you want a CISSP course that treats you like an adult and prepares you for the job — not just the test — you're in the right place.

I built CISSP A–Z to be the only CISSP course you'll need, and then I built a second course on top of it. First, you get complete, current coverage of all eight CISSP domains, aligned to the ISC2 exam outline in effect for 2026. I teach it in plain English from the ground up, so a career changer never feels lost — and I push into real depth so a twenty-year veteran still learns something. Every lesson is tagged by level, so you always know whether you're building a foundation, drilling exam-core material, or going advanced.

Then comes the part no other course gives you: a governance, risk, and compliance deep-dive into the regulatory machinery that's actually driving cybersecurity hiring right now. CMMC. CUI protection. DFARS and the FAR. FedRAMP. And a plain-English, control-family-by-control-family walkthrough of NIST SP 800-171 Rev 3 that you won't find anywhere else on this platform. That's the difference between passing a test and becoming the person in the room who understands how the rules really work.

I've lived both sides of this. I spent a career building security programs as a U.S. Army cybersecurity officer, and today I assess and advise Defense Industrial Base companies as a CMMC-certified assessor. I teach the way I wish someone had taught me: hard things broken into bite-size pieces, real war stories instead of dry theory, exam tips that reflect how ISC2 actually thinks, and the honest truth about what matters on test day versus what matters on the job.

Everything is built from authoritative primary sources — NIST, ISC2, the Code of Federal Regulations, Cyber AB, FedRAMP — and I keep the fast-moving compliance details current. Whenever exam content and real-world compliance diverge, I tell you exactly which is which.

What's inside — course topics

Welcome & Orientation

  • Instructor introduction and the promise of this course

  • Who this course is for and how to use it

  • How the CISSP exam actually works: CAT delivery, the eight domains, weighting, and scoring

  • The crawl-walk-run study path and how lessons are tagged by level

Domain 1 — Security & Risk Management (16%)

  • Security governance, the CIA triad, and core principles

  • Risk management concepts, treatment, and frameworks

  • Compliance, legal and regulatory issues, and the ISC2 Code of Ethics

  • Business continuity, personnel security, and security awareness

  • AI governance and integrating ML/LLM risk into the enterprise (advanced thread)

Domain 2 — Asset Security (10%)

  • Information and asset classification and ownership

  • Data lifecycle, handling, retention, and destruction

  • Data states and protection methods

  • Classifying and protecting AI assets: datasets, models, and model weights (advanced thread)

Domain 3 — Security Architecture & Engineering (13%)

  • Secure design principles and security models

  • Cryptography fundamentals, PKI, and applied crypto

  • Security capabilities of systems and vulnerabilities across platforms

  • Physical security for facilities and infrastructure

  • Prompt injection, adversarial ML, and secure AI compute (advanced thread)

Domain 4 — Communication & Network Security (13%)

  • Secure network architecture and the OSI/TCP-IP models

  • Secure network components and communication channels

  • Wireless, cellular, and modern network defense

  • Zero Trust and securing AI workloads (advanced thread)

Domain 5 — Identity & Access Management (13%)

  • Identity, authentication, and the access control lifecycle

  • Access control models and federated identity

  • Provisioning, credential management, and IAM in the cloud

Domain 6 — Security Assessment & Testing (12%)

  • Assessment and test strategies

  • Security control testing, vulnerability assessment, and penetration testing

  • Logging, monitoring, and reporting

  • Audits: internal, external, and third-party

Domain 7 — Security Operations (13%)

  • Investigations, evidence, and digital forensics

  • Detective and preventive measures; SIEM and SOC operations

  • Incident management, disaster recovery, and business continuity execution

  • Patch, change, and configuration management

  • AI for defensive automation (advanced thread)

Domain 8 — Software Development Security (10%)

  • Security in the software development lifecycle

  • Secure coding, OWASP, and application security controls

  • Software supply chain and third-party software risk

  • Assessing software security effectiveness

GRC Mega-Section — The differentiator ( Additional content)

  • The compliance landscape: FCI vs. CUI, the DFARS/FAR/CMMC relationship, and why 2026 is the demand catalyst

  • NIST foundations: 800-53 Rev 5 baselines and the Risk Management Framework

  • CMMC program deep dive: levels, scoping, assessment types, SPRS, POA&Ms, flow-down, and the ecosystem

  • DFARS, 32 CFR, 48 CFR, and the FAR — the clauses that drive real-world demand

  • FedRAMP requirements for cloud that stores, processes, or transmits CUI

  • The Anatomy Section: a plain-English, family-by-family walkthrough of all control families in NIST SP 800-171 Rev 3

  • NIST AI Risk Management Framework as the bridge between AI risk and compliance

Whether you're changing careers, finishing a degree, leading a team, or a seasoned pro finally adding the credential — I'll meet you where you are and get you CISSP-ready. Let's get to work

Dr. Dwayne Hodges, USA ( Ret.), CISSP ,CCISO, LCCA, CCP, CHP. CNDA, CEH, ITIL, SEC +,  ECES


Who this course is for:

  • CISSP candidates preparing for the exam — you want complete, current coverage of all eight domains aligned to the 2024 ISC2 outline, taught by a CISSP who knows how the exam thinks. Career changers and complete newcomers — you're coming in with little or no security background. The Foundation lessons define every term in plain English and build you up from the ground, so you're never lost. Undergraduate and graduate students in cybersecurity, IT, and technology programs — you want a structured, authoritative walkthrough that connects classroom theory to how the field actually works. Security and IT leaders who need the full picture — governance, risk, architecture, and operations in one place — to lead programs and make defensible decisions. Experienced practitioners formalizing the credential — you already do the work; the Advanced lessons respect your time, push into nuance and edge cases, and get you exam-ready fast. Professionals working in or entering the Defense Industrial Base — you need the GRC deep-dive: CUI, CMMC, DFARS, FedRAMP, and a control-family-by-family walkthrough of NIST SP 800-171 Rev 3 that you won't find in any other CISSP course. Anyone who wants both the certification and the compliance knowledge that most certified professionals never learn — the exam gets you the badge; this course gets you the badge and the real-world command of the regulatory landscape driving hiring in 2026.
  • What you'll learn Master all eight domains of the CISSP Common Body of Knowledge, aligned to the current ISC2 exam outline (effective April 15, 2024, current through 2026) Walk into the CISSP exam knowing how ISC2 thinks — with exam tips, common traps, and memory aids built into every lesson Understand core security principles from the ground up in plain English, whether you're a career changer or a seasoned pro formalizing the credential Apply the CIA triad, risk management, governance, and security frameworks to real-world decisions, not just exam questions Design and evaluate secure architectures, network security, cryptography, and identity and access management systems Run security assessments and testing, and lead security operations, incident response, and recovery with confidence Build security into the software development lifecycle and evaluate the security of applications and code Recognize and secure AI and machine-learning risks — governance, adversarial ML, prompt injection, data poisoning, and model protection — the way the 2026 exam weaves them across all eight domains Navigate the real GRC and compliance landscape: FCI vs. CUI, CMMC, DFARS, 32 CFR, 48 CFR, the FAR, and FedRAMP Understand the CMMC program end to end — levels, scoping, assessment types, SPRS, POA&Ms, flow-down, and the assessor ecosystem Walk through NIST SP 800-171 Rev 3 family by family — what each control family protects, how it looks in a real environment, and how it's assessed Know exactly which Rev 2 vs. Rev 3 distinctions matter and why, so you're never caught out by outdated compliance information
  • CMMC & Compliance Managers , Security and Compliance Staff, Leadership and Management