Activity
Mon
Wed
Fri
Sun
Nov
Dec
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
Sep
What is this?
Less
More

Owned by Vincent

Share resources, get advice, and connect with peers studying cybersecurity. Join our CISSP study group and connect with fellow professionals today!

Skoolers
154.1k
Free
848 contributions to CISSP Study Group
CISSP Practice Question (Domain 6: Security Assessment and Testing)
A fintech board wants a bug bounty live before a funding round in 30 days. No vulnerability disclosure policy exists and internet-facing assets were never inventoried. What should the security manager do FIRST? A. Launch a private bounty limited to the main web application B. Run an authenticated vulnerability scan of all production systems C. Define the disclosure policy and scope the assets in play D. Hire an external firm to penetration test before launch (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
CISSP Practice Question (Domain 5: Identity and Access Management (IAM))
Attackers twice reset executive passwords by phoning the outsourced help desk. The CIO wants phishing-resistant MFA purchased this month. No standard defines how callers prove identity. What should the security manager do FIRST? A. Deploy phishing-resistant MFA for all executives B. Require manager callback approval for every reset C. Retrain help desk staff on social engineering D. Assess the reset process and define identity proofing requirements (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
0 likes • 8h
@Ronald Zierikzee Correct Answer: D. Assess the reset process and define identity proofing requirements Explanation (CISSP logic): The clues are "phoning the outsourced help desk", "purchased this month" and "no standard defines how callers prove identity". Identity and Access Management starts with identity proofing: an authenticator is only as strong as the process that issues and resets it, and here the reset path is the door the attackers used twice. Nobody has written down what proof a caller must give, so every control on the table is being chosen without a requirement to meet. Assess before you act: map how resets really happen, then set the proofing standard the help desk contract and the tools must satisfy. Breakdown: A. Phishing-resistant MFA is the strong distractor because it is modern, funded and almost certainly part of the end state. But the attackers did not phish anyone, they talked the help desk into a reset, and a stronger authenticator that the same desk can re-enroll or bypass on a phone call leaves the door exactly where it was. B. A manager callback is a sensible out-of-band check and may well appear in the final procedure. It is one control picked before the requirement exists, it fails when the manager is unreachable or is the one being impersonated, and applied to every reset it trades availability for a safeguard nobody has sized. C. Retraining addresses the human weakness and awareness belongs in the program. But staff cannot be trained to follow a standard that does not exist, and with an outsourced desk the obligation has to live in the process and the contract, not in the memory of whoever takes the next call. D. ✅ Correct. Assessing the reset process shows how callers are verified today, where the two attacks got through and what the provider is contractually bound to do. The proofing requirements that come out of it tell you which resets need stronger evidence, and the MFA purchase, the callback and the training are then chosen to meet them.
Passed at 100Q
Passed today at 100q with about 25 mins left. Thank you to everyone for the advice and resources you've shared. The exam was not exactly easy but also not nearly as hard as I thought it would be. I felt I was doing okay through most of it. There were a handful of questions that I truly didn't know from the CBK. And a handful that were very difficult, but mostly it was applying analytical thinking to the scenarios. One approach that really helped me is to ask myself what the end game is. What is the true outcome the question is asking for. Framing it that way helped me answer a lot of questions correctly. Here are the resources I used and my study journey: I started about a year ago reading the OSG but found it too dense and boring. I then moved onto the Destination Cert guide, which I highly recommend. After completing the Dest Cert I started with the official Wiley test questions but those were too literal and technical. Then I started with QE. I also later bought the Boson exams (good but slightly too technical) and joined the CISSP Study Group on skool.com. I started doing learning sessions through that group which I found really helpful and motivating. A big shout out to everyone who participated. I also started using https://cissp.app which has an excellent question base. One more test bank I want to mention is really excellent, especially when prepping close to the exam are the questions at the end of Andrew Ramdayal's Udemy course: https://www.udemy.com/course/cisspcertification/?couponCode=MT260928G1A The first set, 50 hard questions, are free on YouTube: https://www.youtube.com/watch?v=qbVY0Cg8Ntw Many of you will already know of them. But it was totally worth getting the additional 100 exam questions which accompany his course. In my opinion these were the closest to the actual exam. (I probably used too many test banks and know that others won't choose that path. But I found that each test bank seems to gravitate towards its own favourite topics so overall it was very helpful to train on a number of them. But everyone is different and some people have passed just using one or two test banks.)
1 like • 1d
CONGRATS!!
CISSP Practice Question (Domain 1: Security and Risk Management)
A cloud outage cost a retailer a day of online sales. The CFO has funded a second region and wants migration started this quarter. No business impact analysis exists. What should the security manager do FIRST? A. Design the second region with the cloud team B. Conduct a business impact analysis to set recovery targets C. Negotiate a stronger uptime commitment with the provider D. Buy business interruption insurance for cloud outages (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 2d
@Vishal Kumar Correct Answer: B. Conduct a business impact analysis to set recovery targets Explanation (CISSP logic): The clues are "a day of online sales", "funded a second region" and "no business impact analysis exists". Business continuity sits in Security and Risk Management because the business, not the cloud team, decides how much downtime and data loss each process can tolerate. The BIA turns that tolerance into recovery time and recovery point objectives, and every resilience spend, from a second region to an insurance premium, is sized against those numbers. Assess before you act: a funded project without targets is a guess with a budget. Breakdown: A. Designing the second region is the strong distractor because the money is approved, the CFO is waiting and a multi-region build may well be the right answer. But an architecture chosen before recovery targets exist can protect the wrong systems, over-engineer the cheap ones and still miss the process that actually cost the day of sales. B. ✅ Correct. The BIA identifies the critical processes, the cost of each hour they are down and the recovery time and point objectives the business will fund. With those in hand the second region becomes a justified control with a measurable target instead of a reaction to one bad day. C. A stronger uptime commitment moves some liability onto the provider and belongs in the contract review. It does not restore a single sale during the next outage, and without a BIA nobody knows what commitment to ask for or whether the credits would come close to the loss. D. Business interruption insurance is legitimate risk transfer and a finance decision worth making. Insurers price it from the very impact figures the BIA produces, and it pays out after the outage rather than shortening it, so it complements the analysis and cannot replace it. Think like a manager: Recovery targets come from the business impact, not the budget line. Know what an hour costs before you buy the hour back.
CISSP Practice Question (Domain 7: Security Operations)
HR suspects a departing engineer copied source code to a personal drive. The engineer leaves Friday and the CTO wants IT to search the laptop today. What should the security operations manager do FIRST? A. Have IT review the laptop's file history for proof B. Disable the engineer's accounts and seize the laptop now C. Preserve the device and logs under chain of custody with legal D. Report the suspected theft to law enforcement (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 5d
@Kayode Alabi Correct Answer: C. Preserve the device and logs under chain of custody with legal Explanation (CISSP logic): The clues are "HR suspects", "source code", "leaves Friday" and "search the laptop today". Suspected theft of intellectual property by an employee is a legal matter before it is a technical one, and anything the organization might later put in front of a court, a regulator or an arbitrator has to be collected in a way that survives challenge. Security Operations owns evidence handling: preserve first, under chain of custody, with legal and HR setting the boundaries of the investigation. Assess before you act: a search that starts before preservation can destroy the very proof it is looking for. Breakdown: A. Reviewing the file history sounds like the fastest way to confirm or clear the suspicion, and the CTO will get an answer today. But every file opened, every timestamp touched and every login by IT changes the evidence, and a finding produced without chain of custody is a story, not proof, that the engineer's lawyer will take apart. B. The strong distractor. Disabling accounts and taking the laptop feels like decisive containment and it does stop further copying. But the engineer is still employed, and revoking access and seizing property without HR and legal sign-off invites a wrongful treatment claim, tips off the suspect before evidence is secured and still leaves the device unpreserved in the hands of whoever grabbed it. C. ✅ Correct. Preserving the laptop, its image and the relevant logs under documented chain of custody keeps every option open: an internal HR outcome, a civil claim or a criminal referral. Legal decides what may be examined and by whom, HR handles the employee, and the forensic review that follows is admissible because it started right. D. Law enforcement may well be involved before this is over, and for some jurisdictions and contracts that referral is required. It is a decision for legal counsel with preserved evidence in hand, not the first move on a suspicion, and reporting before preservation hands investigators a case with no exhibits.
1-10 of 848
Vincent Primiani
7
4,750 points to level up
Cybersecurity. The Study Group Guy.

Active 2h ago
Joined Apr 29, 2024
New York, NY
Powered by