Activity
Mon
Wed
Fri
Sun
Oct
Nov
Dec
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
Sep
What is this?
Less
More
CISSP Study Group

2.3k members • Free

4 contributions to CISSP Study Group
CISSP Practice Question (Domain 4: Communication and Network Security)
A hospital wants new internet-connected infusion pumps on the existing user VLAN to hit a ward opening date. The pumps cannot run endpoint agents and are patched quarterly. What should the network security manager require FIRST? A. Dedicated network zone for the pumps with controlled ingress B. Risk assessment of the pumps against clinical network requirements C. Network intrusion detection covering the user VLAN D. Vendor commitment to a faster patch cadence (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
2 likes • 13d
B. Always assess/evaluate the risk prior to implementing the security control.
CISSP Practice Question (Domain 1: Security and Risk Management)
During business continuity planning, the IT director assigns recovery time objectives based on system complexity and restoration effort. Several business units later dispute the recovery priorities. Who should the BCP coordinator ensure determines the RTOs? A. The IT director, who understands restoration capability B. Business process owners, based on impact analysis C. Executive management, to resolve the dispute with authority D. The BCP coordinator, to maintain plan consistency (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
0 likes • 29d
B
CISSP Practice Question (Domain 7: Security Operations)
During active ransomware containment, the operations team wants to immediately wipe and reimage infected servers to restore a critical service. Cyber insurance and law enforcement notifications are pending. What should the incident commander do FIRST? A. Preserve forensic images of affected systems before restoration B. Restore the service from the most recent clean backup C. Notify the cyber insurer to avoid violating policy conditions D. Isolate remaining unaffected segments to prevent spread (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
0 likes • Aug 11
A
CISSP Practice Question (Domain#3)
A financial services company is designing a system to securely transmit large volumes of transaction data between two data centers in near real-time. The security team requires that the solution provide confidentiality for the data in transit while minimizing computational overhead, since asymmetric encryption of the full data stream would introduce unacceptable latency. Which approach BEST meets this requirement? A. Encrypt the entire data stream using RSA with a 4096-bit key to maximize confidentiality B. Use a symmetric algorithm such as AES for the data stream, with an asymmetric algorithm used only to securely exchange the symmetric session key C. Use a hashing algorithm such as SHA-256 to protect the confidentiality of the transaction data D. Use asymmetric encryption for the data stream, but reduce the key size to 1024 bits to improve performance
1 like • Jul 22
B
1-4 of 4
Dupe Omotosho
1
2 points to level up
@dupe-omotosho-6962
Cybersecurity Architect

Active 11m ago
Joined Jul 22, 2026
Powered by