Activity
Mon
Wed
Fri
Sun
Sep
Oct
Nov
Dec
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
What is this?
Less
More

Memberships

CISSP Study Group

2.2k members • Free

46 contributions to CISSP Study Group
Provisionally passed CISSP Exam
I’ve officially passed my CISSP exam! A huge shoutout to this incredible community specially @Vincent Primiani , the cissp.app practice questions, and the insightful live group sessions for pushing me over the finish line. Appreciate all the support here! 🚀🎉
2 likes • 3d
Congratulations 🎉
CISSP Practice Question (Domain 4: Communication and Network Security)
A business partner requires an always-on site-to-site tunnel into a shared application segment. Their security posture is unknown, and the contract is already signed. What should the network security manager do FIRST? A. Terminate the tunnel in a dedicated screened segment B. Assess the partner's security posture against connection requirements C. Route all partner traffic through the inspection stack D. Enforce mutual authentication and approved cipher policy (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 4d
B - would evaluate whether a business partner's cybersecurity practices and controls meet organization's security requirements before allowing a connection to their systems or network.
CISSP Practice Question (Domain 3: Security Architecture and Engineering)
A multinational firm plans a single global data lake for cost efficiency. Regional teams process citizen data under differing privacy regimes, and design approval is due next week. What should the security architect do FIRST? A. Validate jurisdictional data sovereignty requirements before design approval B. Segment the lake to enforce regional residency boundaries C. Apply tokenization to sensitive fields before global replication D. Escalate the cost-versus-compliance conflict to the risk committee (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 5d
A - would be the first ideal option.
CISSP Practice Question (Domain 6: Security Assessment and Testing)
An internal audit team reporting directly to the CISO produces the assessment reports used for regulatory attestation. A regulator challenges the credibility of the results. What is the MOST appropriate action for executive management? A. Engage an independent third party to validate the disputed findings B. Restructure audit reporting lines to the board or audit committee C. Expand testing scope and increase assessment frequency D. Require management sign-off attestations on every audit report (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 8d
A - would confirm or dispute the credibility of the disputed results.
CISSP Practice Question (Domain 2: Asset Security)
A cloud migration reveals thousands of unlabeled legacy files containing mixed customer and internal data. The project sponsor wants to bulk-encrypt everything and proceed to meet the cutover date. What should the data governance lead do FIRST? A. Classify the data according to the organizational scheme B. Encrypt all files at the highest protection level C. Identify data owners to assign accountability D. Apply retention policies to purge obsolete records (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 18d
A - would help implementing appropriate security controls, comply with legal and regulatory requirements, and allocate security resources efficiently.
1-10 of 46
David Uchieng
3
39 points to level up
@david-uchieng-6550
Bachelor of Science in Information Technology

Active 1h ago
Joined Mar 9, 2026
Powered by