Activity
Mon
Wed
Fri
Sun
Sep
Oct
Nov
Dec
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
What is this?
Less
More
CISSP Study Group

2.3k members • Free

CISSP Study Group+

12 members • $99/m

317 contributions to CISSP Study Group
1 like • Jul 15
@Hassan Na You are welcome😍
2 likes • Jul 15
@Tariq Islam You are most welcome
An Executive Guide to Passing the CISSP
The goal is to help Group members think like a CISSP professional (Think Like a Manager) by understanding governance, risk management, business alignment, and executive decision making. I hope you all enjoy reading it
Question: Domain 1 (Security and Risk Management)
A multinational organization is migrating its data to a third-party cloud provider. The Chief Information Security Officer (CISO) is concerned about maintaining compliance with various international privacy regulations. What is the BEST way to ensure the cloud provider meets the organization’s security requirements? - A. Conduct a point-in-time vulnerability scan of the provider’s infrastructure. - B. Include "right-to-audit" clauses and Require Service Level Agreements (SLAs). - C. Review the provider’s SOC 2 Type II report and audit results. - D. Implement a Cloud Access Security Broker (CASB) to monitor traffic.
CISSP Practice Question (Domain 2: Asset Security / Data Governance)
An enterprise deploys agentic AI systems that autonomously collect data from internal systems and external sources to answer executive queries. Over time, agents begin retaining intermediate data and derived insights to improve future performance. Legal cannot determine what regulated data is being stored or reused. Leadership wants minimal friction. What is the MOST appropriate action to take FIRST? A. Encrypt all agent retained data using enterprise key management B. Perform a data inventory and classification of agent memory and outputs C. Restrict agents to real time queries with no local persistence D. Update contracts with AI vendors to address derived data ownership Come back for the answer tomorrow, or study more now!
2 likes • Jan 8
B. Perform a data inventory and classification of agent memory and outputs Option B allows the AI to continue functioning while Legal and Security get the visibility they need to make informed decisions.
Risk Assessment Best Practices
To ace the CISSP exam, especially concerning Risk Assessment, here's a breakdown of best practices you should master: 1. Understand Core Risk Management Concepts: - Risk Triad: Thoroughly grasp the relationship between threats, vulnerabilities, and assets. Remember: Threat x Vulnerability = Risk. - Confidentiality, Integrity, and Availability (CIA Triad): Understand how risk assessment aims to protect these fundamental security principles. - Risk Management Process: Familiarize yourself with the cyclical process: Identification: Recognizing assets, threats, and vulnerabilities. Analysis: Evaluating the likelihood and impact of risks. Evaluation: Prioritizing risks based on their severity. Treatment: Selecting and implementing controls (mitigate, accept, avoid, transfer). Monitoring and Review: Continuously tracking risks and the effectiveness of controls. 2. Master Risk Assessment Methodologies: - Qualitative Risk Assessment: Understand how to use descriptive scales (high, medium, low) to assess likelihood and impact. Be familiar with tools like probability/impact matrices. - Quantitative Risk Assessment: Know how to calculate potential financial losses using metrics like: Asset Value (AV) Exposure Factor (EF) Single Loss Expectancy (SLE = AV * EF) Annualized Rate of Occurrence (ARO) Annualized Loss Expectancy (ALE = SLE * ARO)   - Hybrid Approaches: Recognize that many real-world risk assessments combine qualitative and quantitative methods. 3. Know How to Identify and Value Assets: - Tangible vs. Intangible Assets: Understand the difference and how to value both (e.g., data, reputation, intellectual property). - Asset Classification: Be familiar with categorizing assets based on sensitivity and criticality to the business. Inaccurate valuation leads to ineffective controls. 4. Understand Threat and Vulnerability Analysis: - Threat Modeling: Learn techniques like STRIDE (Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, Elevation of Privilege) to identify potential threats.   - Vulnerability Assessments and Penetration Testing: Understand their purpose in identifying weaknesses. - Threat Intelligence: Recognize the importance of staying informed about current and emerging threats.
0 likes • Jul '25
@Benson Lucas You are welcome😊
0 likes • Jul '25
@Vincent Primiani Thank you my friend 😊
1-10 of 317
Fouad Ahmed
6
1,172 points to level up
@fouad-ahmed-2832
Passionate about simplifying security concepts and fostering collaborative learning to help others succeed in their CISSP certification journey

Active 30d ago
Joined Mar 15, 2026
Boston, MA
Powered by