Activity
Mon
Wed
Fri
Sun
Oct
Nov
Dec
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
Sep
What is this?
Less
More
CISSP Study Group

2.3k members • Free

61 contributions to CISSP Study Group
CISSP Practice Question (Domain 6: Security Assessment and Testing)
A cloud payroll vendor offers a SOC 2 Type I report dated 14 months ago to close a contract due Friday. HR wants to sign. What should the security manager do FIRST? A. Require a current SOC 2 Type II before signing B. Review the report's scope, period and exceptions against services used C. Sign with a contractual right to audit clause D. Commission an independent penetration test of the vendor (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
0 likes • 2h
B - Review provides a thorough understanding of the report before contractual commitments are made.
CISSP Practice Question (Domain 2: Asset Security)
A marketing team wants three years of customer support transcripts in an overseas AI analytics tool by month end. The transcripts were never classified and have no named owner. What should the security manager do FIRST? A. Approve the upload once the transcripts are anonymized B. Assign a data owner and classify the transcripts C. Require the provider to sign a data processing agreement D. Limit the upload to transcripts older than one year (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
0 likes • 5d
B - The Data Owner is accountable for the data and is responsible for making decisions regarding its classification, access, use, and protection in accordance with organizational policies, privacy requirements, and applicable laws and regulations.
CISSP Practice Question (Domain 3: Security Architecture and Engineering)
A hospital must move its imaging platform to a public cloud within 90 days; design approval is due next week. The architect proposes provider managed encryption at rest for every workload. What should the security manager do FIRST? A. Approve the design to protect the contract deadline B. Confirm data classification and the shared responsibility split C. Require customer managed keys in a hardware security module D. Schedule a penetration test of the platform before go live (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
2 likes • 7d
B - Confirming data classification and the shared responsibility split establishes the level of protection required and clearly defines who is responsible for providing that protection based on the data’s sensitivity and criticality.
CISSP Practice Question (Domain 5: Identity and Access Management (IAM))
An acquisition closes in 30 days, and the deal team wants the acquired staff in shared systems on day one. How that firm grants, reviews, and removes access is unknown. What should the CISO do FIRST? A. Federate both identity providers for day one sign-in B. Assess the acquired firm's identity governance and access lifecycle C. Issue temporary parent directory accounts to acquired staff D. Require multifactor authentication on acquired accounts before connecting (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 9d
B - In this scenario, assessment is the first task
CISSP Practice Question (Domain 1: Security and Risk Management)
A lender will embed a third party AI model in loan approvals, live in 90 days by board order. Nobody has set a risk appetite for AI decisions or named an owner. What should the CISO do FIRST? A. Draft an AI acceptable use policy for lenders B. Have the board set risk appetite and name an owner C. Commission due diligence on the model vendor D. Require bias and explainability testing before launch (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 10d
B - would be my first thing to do. I believe that establishing the level of risk the organization is willing to accept, along with clearly defining who is responsible for making those decisions, provides a strong foundation for effective escalation and accountability.
1-10 of 61
David Uchieng
3
24 points to level up
@david-uchieng-6550
Bachelor of Science in Information Technology

Active 2h ago
Joined Mar 9, 2026
Powered by