Activity
Mon
Wed
Fri
Sun
Sep
Oct
Nov
Dec
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
What is this?
Less
More

Memberships

The Cyber Community

9.5k members • Free

CyberMAYnia CAREER

568 members • Free

CISSP Study Group

2.2k members • Free

121 contributions to CISSP Study Group
CISSP Practice Question (Domain 4: Communication and Network Security)
A business partner requires an always-on site-to-site tunnel into a shared application segment. Their security posture is unknown, and the contract is already signed. What should the network security manager do FIRST? A. Terminate the tunnel in a dedicated screened segment B. Assess the partner's security posture against connection requirements C. Route all partner traffic through the inspection stack D. Enforce mutual authentication and approved cipher policy (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 5d
B looks appropriate to assess partner security posture
CISSP Practice Question (Domain 3: Security Architecture and Engineering)
A multinational firm plans a single global data lake for cost efficiency. Regional teams process citizen data under differing privacy regimes, and design approval is due next week. What should the security architect do FIRST? A. Validate jurisdictional data sovereignty requirements before design approval B. Segment the lake to enforce regional residency boundaries C. Apply tokenization to sensitive fields before global replication D. Escalate the cost-versus-compliance conflict to the risk committee (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 7d
A should be appropriate with juridisical data validation
CISSP Practice Question (Domain 6: Security Assessment and Testing)
An internal audit team reporting directly to the CISO produces the assessment reports used for regulatory attestation. A regulator challenges the credibility of the results. What is the MOST appropriate action for executive management? A. Engage an independent third party to validate the disputed findings B. Restructure audit reporting lines to the board or audit committee C. Expand testing scope and increase assessment frequency D. Require management sign-off attestations on every audit report (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 9d
A appears appropriate with 3rd party validation
CISSP Practice Question (Domain 2: Asset Security)
A cloud migration reveals thousands of unlabeled legacy files containing mixed customer and internal data. The project sponsor wants to bulk-encrypt everything and proceed to meet the cutover date. What should the data governance lead do FIRST? A. Classify the data according to the organizational scheme B. Encrypt all files at the highest protection level C. Identify data owners to assign accountability D. Apply retention policies to purge obsolete records (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 20d
A is appropriate as data classification first activity
CISSP Practice Question (Domain 5: Identity and Access Management)
After a merger, employees from the acquired company need immediate access to shared systems. The integration team proposes duplicating accounts into the parent directory to meet a hard business deadline. What is the MOST appropriate action for the security manager? A. Approve duplication with mandatory password resets B. Establish federated trust between the two identity providers C. Require role definitions and access reviews before provisioning D. Grant temporary elevated access until integration completes Come back for the answer tomorrow, or study more now!
2 likes • 21d
B appear appropriate with federated trust
1-10 of 121
Dj Sahoo
5
350 points to level up
@dj-sahoo-9937
Dj

Active 2d ago
Joined Dec 12, 2025
Powered by