Activity
Mon
Wed
Fri
Sun
Nov
Dec
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
Sep
What is this?
Less
More
221 contributions to CISSP Study Group
Passed at 100Q
Passed today at 100q with about 25 mins left. Thank you to everyone for the advice and resources you've shared. The exam was not exactly easy but also not nearly as hard as I thought it would be. I felt I was doing okay through most of it. There were a handful of questions that I truly didn't know from the CBK. And a handful that were very difficult, but mostly it was applying analytical thinking to the scenarios. One approach that really helped me is to ask myself what the end game is. What is the true outcome the question is asking for. Framing it that way helped me answer a lot of questions correctly. Here are the resources I used and my study journey: I started about a year ago reading the OSG but found it too dense and boring. I then moved onto the Destination Cert guide, which I highly recommend. After completing the Dest Cert I started with the official Wiley test questions but those were too literal and technical. Then I started with QE. I also later bought the Boson exams (good but slightly too technical) and joined the CISSP Study Group on skool.com. I started doing learning sessions through that group which I found really helpful and motivating. A big shout out to everyone who participated. I also started using https://cissp.app which has an excellent question base. One more test bank I want to mention is really excellent, especially when prepping close to the exam are the questions at the end of Andrew Ramdayal's Udemy course: https://www.udemy.com/course/cisspcertification/?couponCode=MT260928G1A The first set, 50 hard questions, are free on YouTube: https://www.youtube.com/watch?v=qbVY0Cg8Ntw Many of you will already know of them. But it was totally worth getting the additional 100 exam questions which accompany his course. In my opinion these were the closest to the actual exam. (I probably used too many test banks and know that others won't choose that path. But I found that each test bank seems to gravitate towards its own favourite topics so overall it was very helpful to train on a number of them. But everyone is different and some people have passed just using one or two test banks.)
1 like • 8h
Congratulations @Naashon Zal
CISSP Practice Question (Domain 5: Identity and Access Management (IAM))
Attackers twice reset executive passwords by phoning the outsourced help desk. The CIO wants phishing-resistant MFA purchased this month. No standard defines how callers prove identity. What should the security manager do FIRST? A. Deploy phishing-resistant MFA for all executives B. Require manager callback approval for every reset C. Retrain help desk staff on social engineering D. Assess the reset process and define identity proofing requirements (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
0 likes • 1d
A- MFA is strong authentication, can be by passed if strong identification is not adopted. B- Manager callback approval for every reset is extra security layer, however, mannul and overburdon. C . Training is best for security awareness against social engineering , not fully effective without identity proofing assessment for standard adaptation. D. Assessing the password-reset process and defining appropriate identity-proofing requirements should be the first step, supported by Identity and Access Management (IdM) due diligence and security governance.
Sample Question I came across
A pharmaceutical company must share confidential research reports with an external partner. Management requires that the company can revoke access to the reports at any time, even after the files have been downloaded to the partner's systems, and that printing be blocked. Which control BEST meets these requirements?
Poll
5 members have voted
0 likes • 1d
Digital watermarking embedded in each report - will track unauthorised copies and printing of the document. DLP on the company,s network egress point - will stop leakage / ex-filtration of document by unauthorised / authorised user if DLP policy not allow the outward transmission of report. Persistent protection ... - best meets the requirement to control downloaded report access,printing and copying. Digital Rights Management (DRM) can enforce access through persistent policy and key/authorisation mechanisms, rather than assuming every DRM implementation literally contacts the owner for a decryption key each time. Transmitting the report over TLS ... - will protect the document from eavesdropping during transmission and strong authentication will stop unauthorised access.
CISSP Practice Question (Domain 1: Security and Risk Management)
A cloud outage cost a retailer a day of online sales. The CFO has funded a second region and wants migration started this quarter. No business impact analysis exists. What should the security manager do FIRST? A. Design the second region with the cloud team B. Conduct a business impact analysis to set recovery targets C. Negotiate a stronger uptime commitment with the provider D. Buy business interruption insurance for cloud outages (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 4d
B
2 likes • 4d
A. Design the second region with the cloud team ( organisation is making a continuity investment, but has no defined business recovery requirements. Therefore, conduct the BIA first to establish those requirements before selecting the technical or contractual solution). B. Conduct a business impact analysis to set recovery targets ( BIA is first step to take decision for taking further measures). C. Negotiate a stronger uptime commitment with the provider ( apparently best choice to negotiate with existing service provider for high availability through SLA, however, conducting first BIA will be m,ore informed decision). D. Buy business interruption insurance for cloud outages ( Insurance can provide risk transfer better in case of high risk and low probability incidents but will not solve the root cause / constant problem of outages).
🎉 CISSP Exam Passed! (First Attempt at 100 Questions!)
Hi everyone, I am thrilled to share that I officially cleared the CISSP exam yesterday at the 100-question mark on my first attempt! To give a bit of background, I started my CISSP preparation right after passing my CCSP 6 weeks ago. Here is what my preparation looked like: - Core Study Material: Studied the Official Study Guide (OSG) 10th Edition cover-to-cover, using AI tools (Gemini and Claude) to deep-dive into areas where the OSG lacked a bit of depth and to effectively cover that delta. - Visual Learning: Utilized Destination Certification's mind map videos to solidify concepts. - Practice Assessments: Leveraged the Destination Certification app practice tests, alongside the Skool "CISSP, CCSP & CISM Practice Exams | Expert-Calibrated Questions — cissp.app" practice and full-length tests, to benchmark my readiness. - Final Refresher: Used The CISSP Field Manual by Clearance to Wealth as a fantastic quick refresher right before the exam. - Collaborative Learning: Participated actively in classes alongside a diverse group of talented professionals. The interactive sessions fostered a healthy and professional environment where we could analyze questions from multiple angles. Hearing different viewpoints on scenario-based reasoning provided valuable insights into why a choice is correct or incorrect, significantly sharpening my exam mindset. I want to extend a huge thank you to everyone who made this journey a success: - Vincent: For initializing and running this amazing CISSP Skool community. - The Facilitators: For exposing us to a rich variety of challenging questions through the classes. - My Study Group: A heartfelt thank you to Ed, Ricardo, Enrico, Victor, Matthew, Pavithra, Emma, Aidah, Vishal, David and many more for your incredible support and camaraderie. Thank you all again. On to the next chapter!
2 likes • 4d
Many congrats @Chiru Adapa , same group and all of them were very helpful for me as well which enabled me to clear the exam at first attempt.
1-10 of 221
Hassan Na
5
170 points to level up
@hassan-hassan-4557
CISSP, CC

Active 3h ago
Joined Dec 7, 2025
Powered by