Activity
Mon
Wed
Fri
Sun
Oct
Nov
Dec
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
Sep
What is this?
Less
More
CISSP Study Group

2.3k members • Free

162 contributions to CISSP Study Group
CISSP Practice Question (Domain 4: Communication and Network Security)
A retailer must move 200 stores to a cloud point of sale over internet links in 60 days. The network team proposes an encrypted overlay so stores cut over as circuits arrive. What should the security manager do FIRST? A. Approve the overlay to keep cutovers on schedule B. Identify the data flows and requirements the design must meet C. Require multifactor authentication on every store tunnel D. Commission a penetration test before the first cutover (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
0 likes • 3d
B. Identifying the data flow and requirements is FIRST option when you have PoS and have to cut over circuits are key.
CISSP Practice Question (Domain 7: Security Operations)
Ransomware hits a file server mid product launch, and the sales VP wants last night's backup restored within the hour. Nobody has invoked the incident response plan. What should the security operations manager do FIRST? A. Restore the server from backup to protect the launch B. Isolate the server and preserve volatile evidence C. Declare the incident and activate the response plan D. Scan neighboring hosts to gauge how far it spread (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 9d
C. This one seems rather easy. The incident has to be declared first.
CISSP Practice Question (Domain 2: Asset Security)
A SaaS contract ends and the vendor confirms customer records were deleted from production. Retention for those records has expired, and legal wants proof before signing the closure letter. What should the data owner require FIRST? A. Certificate of destruction covering backups and replicas B. Cryptographic erasure of the vendor's data encryption keys C. Signed attestation from the vendor's compliance officer D. Independent audit of the vendor's deletion procedures (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 11d
A is the FIRST option.
I can't believe I passed :)😁😃
I am so excited to share that I provisionally passed my CISSP exam, on Saturday September 5th. I want to thank Vincent Primiani for creating and managing this CISSP study group community and special thanks to my fellow study group learners in my study group (Ed, Ricardo, Enrico, Victor, Thomas, Mike, Matthew, Pavithra and many more.) See the attached resources I used in my CISSP prep journey. Wishing you Good Luck if you are planning to appear for the exam soon.
1 like • 11d
@Srini Pl Congratulations! I am glad I could assist in your journey.
CISSP Practice Question (Domain 1: Security and Risk Management)
A security consultant discovers her client is knowingly misrepresenting remediation status to its customers after an assessment she performed. The client cites confidentiality clauses in her contract and directs her to stay silent. Under the ISC2 Code of Ethics, what is her PRIMARY obligation? A. Honor the confidentiality agreement with the client B. Act honorably and protect the public trust C. Report the misrepresentation to affected customers D. Withdraw from the engagement and document concerns (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 24d
B is the most honorable.
1-10 of 162
Ed Morawski
5
330 points to level up
@ed-morawski-4430
Ed

Active 13h ago
Joined Nov 21, 2025
Powered by