Activity
Mon
Wed
Fri
Sun
Oct
Nov
Dec
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
Sep
What is this?
Less
More
11 contributions to CISSP Study Group
CISSP Practice Question (Domain 1: Security and Risk Management)
A manufacturer buys a smaller rival in 30 days. The CEO wants its network joined to the corporate cloud on day one. Its security posture has never been reviewed. What should the security manager do FIRST? A. Connect it behind a restrictive firewall B. Require it to adopt corporate security policies C. Perform security due diligence on its environment D. Extend cyber insurance to cover its systems (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
0 likes • 6d
C
CISSP Practice Question (Domain 4: Communication and Network Security)
A retailer must move 200 stores to a cloud point of sale over internet links in 60 days. The network team proposes an encrypted overlay so stores cut over as circuits arrive. What should the security manager do FIRST? A. Approve the overlay to keep cutovers on schedule B. Identify the data flows and requirements the design must meet C. Require multifactor authentication on every store tunnel D. Commission a penetration test before the first cutover (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
0 likes • 10d
B
I can't believe I passed :)😁😃
I am so excited to share that I provisionally passed my CISSP exam, on Saturday September 5th. I want to thank Vincent Primiani for creating and managing this CISSP study group community and special thanks to my fellow study group learners in my study group (Ed, Ricardo, Enrico, Victor, Thomas, Mike, Matthew, Pavithra and many more.) See the attached resources I used in my CISSP prep journey. Wishing you Good Luck if you are planning to appear for the exam soon.
1 like • 10d
Congratulations @Srini Pl Glad you made it!
CISSP Practice Question (Domain 2: Asset Security)
A marketing team wants three years of customer support transcripts in an overseas AI analytics tool by month end. The transcripts were never classified and have no named owner. What should the security manager do FIRST? A. Approve the upload once the transcripts are anonymized B. Assign a data owner and classify the transcripts C. Require the provider to sign a data processing agreement D. Limit the upload to transcripts older than one year (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
2 likes • 11d
B- Assigning a specific data owner and classifying the transcripts FIRST will enable the security manager to apply appropriate protection to transcripts based on their classifications.
CISSP Practice Question (Domain 6: Security Assessment and Testing)
A retailer's payment platform needs a penetration test before a regulator's deadline in six weeks. The platform team offers to test it themselves. What is the MOST appropriate response from the security manager? A. Accept the offer and review the resulting report yourself B. Engage an independent tester and agree scope and rules of engagement C. Run a vulnerability scan first to fix known defects D. Postpone testing until open platform findings are remediated (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
2 likes • 13d
B- Application developers may not produce the best test results against themselves, so an Independent Pen Tester should be shipped in to do the work.
1-10 of 11
Aidah Nakyejwe
2
13 points to level up
@aidah-nakyejwe-8112
CyberSec Engineer

Active 7h ago
Joined Apr 23, 2026
Powered by