Activity
Mon
Wed
Fri
Sun
Mar
Apr
May
Jun
Jul
Aug
Sep
Oct
Nov
Dec
Jan
Feb
What is this?
Less
More

Memberships

CISSP Study Group

1.9k members โ€ข Free

8 contributions to CISSP Study Group
CISSP Practice Question (Domain 1: Security and Risk Management)
Senior leadership wants to launch a new customer analytics platform that processes regulated personal data. The CISO identifies control gaps that exceed the organizationโ€™s stated risk appetite, but executives are pushing for speed to market. What is the MOST appropriate action for the CISO to take NEXT? A. Document the risk and accept it to support business objectives B. Implement compensating controls within the security team C. Escalate the risk to senior management for formal risk acceptance D. Delay the project until all identified risks are fully mitigated Come back for the answer tomorrow! Study more now at CISSP.app
1 like โ€ข Dec '25
C
CISSP Practice Question โ€“ Security Architecture & Engineering (Assurance & Design Principles)
A national intelligence agency is designing a new system to process both Top Secret and Unclassified data simultaneously. Engineers propose using a formally verified microkernel operating system that enforces strict separation between processes through hardware-based memory isolation. During review, an executive asks why the team insists on this complex design instead of using simpler software-based access controls at the application layer. Which concept BEST justifies the microkernel approach? A. Complete mediation โ€” ensuring every access request is validated against the security policy. B. Security kernel โ€” implementing reference monitor functions at the lowest level of the system. C. Layered defense โ€” using multiple, independent safeguards at different levels of abstraction. D. Economy of mechanism โ€” minimizing system complexity to reduce potential vulnerabilities.
0 likes โ€ข Nov '25
B
CISSP Practice Question
Which of the following organizations establishes the standards for Service Organization Control (SOC) audits? A: American Institute of Certified Public Accountants (AICPA) B: National Institute of Standards and Technology (NIST) C: International Organization for Standardization (ISO) D: International Electrotechnical Commission (IEC)
2 likes โ€ข Jul '25
A
Practice Question
Which of the following threats would be MOST likely mitigated by monitoring assets containing open source libraries for vulnerabilities? A. Distributed denial-of-service (DDoS) attack B. Zero-day attack C. Phishing attempt D. Advanced persistent threat (APT) attempt
1 like โ€ข Mar '25
B
CISSP did not pass
Hi all, Unfortunately, I didnโ€™t pass the CISSP exam. I did tons of prep questions on learnzapp but seems that Iโ€™m not well prepared yet. Could you please recommend some info (tips) to follow that can help me ? Thank you
CISSP did not pass
1 like โ€ข Mar '25
@Graziano Callegaro, the readiness score that I touched was 72 for all the questions (including all domains from learnZapp). So, now Iโ€™m preparing better. Can I ask you which official app are you referring ? Good luck!
1 like โ€ข Mar '25
@Graziano Callegaro, I would suggest you to prepare more. Iโ€™m speaking based on my experience. Good luck!
1-8 of 8
Alexandru Moise
2
8points to level up
@alexandru-moise-9629
Cybersecurity enthusiastic

Active 42d ago
Joined Feb 23, 2025
Powered by