Activity
Mon
Wed
Fri
Sun
Sep
Oct
Nov
Dec
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
What is this?
Less
More
CyberMAYnia CAREER

572 members • Free

CISSP Study Group

2.3k members • Free

185 contributions to CISSP Study Group
CISSP Practice Question (Domain 5: Identity and Access Management - AI Exam Guidance)
An autonomous AI agent needs credentials to query production databases and invoke internal APIs on a recurring schedule. The automation team proposes reusing a departed developer's service account to launch quickly. What should the IAM manager require FIRST? A. Rotate the credentials and transfer the account to the automation team B. Register the agent as a distinct non-human identity with a defined owner C. Scope the account's permissions to only the required datasets D. Enable enhanced logging on all agent-initiated transactions (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
0 likes • 5h
A. Rotate the credentials and transfer the account to the automation team ( credential rotation is best practice for IAM security, however, it will be after B) B. Register the agent as a distinct non-human identity with a defined owner ( registraton and ownership assignment is the first 'governanace' requirement is IAM for IAAA). C. Scope the account's permissions to only the required datasets ( principle of least privilege 'PoLP' is best for secure IAM but it will come after A) D. Enable enhanced logging on all agent-initiated transactions ( logging is detective control for effective accountability / monitoring but will come at the end ). The autonomous agent requires a unique identity and accountable owner FIRST. Once identified, authentication credentials can be established, authorization can be scoped according to least privilege, and activities can be logged and audited. Therefore B → A → C → D
CISSP Practice Question (Domain 7: Security Operations)
During active ransomware containment, the operations team wants to immediately wipe and reimage infected servers to restore a critical service. Cyber insurance and law enforcement notifications are pending. What should the incident commander do FIRST? A. Preserve forensic images of affected systems before restoration B. Restore the service from the most recent clean backup C. Notify the cyber insurer to avoid violating policy conditions D. Isolate remaining unaffected segments to prevent spread (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 3d
A. Preserve forensic images of affected systems before restoration ( A will be followed by D, stop the bleed 'D' is the first option in emergency cases , x-ray and bandage are next step). B. Restore the service from the most recent clean backup ( restoration will come last after all three other options D → A → C → B). C. Notify the cyber insurer to avoid violating policy conditions ( it will come after A) D. Isolate remaining unaffected segments to prevent spread (During active ransomware containment phase, isolation is first immediate step to contain the incident spread to other systems). 🩸 Stop the bleeding → 🔬 Preserve evidence → 📞 Notify stakeholders → 🩹 Restore
Provisionally passed the cissp exam
Thank you @Vincent Primiani and everyone in the group.
1 like • 7d
Congratulations @Anthony Knapkin
CISSP Practice Question (Domain 8: Software Development Security)
A development team adopts a widely used open source library that accelerates delivery of a revenue-critical release. The library has no active maintainer and no published vulnerability disclosure process. What should the security manager recommend FIRST? A. Add the library to the software bill of materials for monitoring B. Evaluate the component against secure acquisition and supply chain criteria C. Fork the library so the organization controls future patching D. Require compensating controls at the application perimeter (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 8d
A. Add the library to the software bill of materials for monitoring (detective technical control of operational nature without evaluation and risk analysis) B. Evaluate the component against secure acquisition and supply chain criteria ( best first action recommendation as stretigic governance level decision and due diligence) C. Fork the library so the organization controls future patching ( forking is a possible long-term mitigation but is premature. The organization should first evaluate whether assuming maintenance responsibility aligns with its secure acquisition and software supply chain risk management policies.) D. Require compensating controls at the application perimeter ( compemsating control is considered last resort and only applied if primary control are not applicable)
Hat trick for the Study Group!!
Three in one week, good job all, so proud to be a part of our community. and another congrats to @Kate Shairs @Devdutt Jha @James Bonner
Hat trick for the Study Group!!
2 likes • 12d
Congratulations Kate, Devdutt and James
1-10 of 185
Hassan Na
5
213 points to level up
@hassan-hassan-4557
CISSP, CC

Active 3h ago
Joined Dec 7, 2025
Powered by