Activity
Mon
Wed
Fri
Sun
Oct
Nov
Dec
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
Sep
What is this?
Less
More
CyberMAYnia CAREER

592 members • Free

AI University (AIU)

108 members • Free

CISSP Study Group

2.3k members • Free

71 contributions to CISSP Study Group
CISSP Practice Question (Domain 1: Security and Risk Management)
A manufacturer buys a smaller rival in 30 days. The CEO wants its network joined to the corporate cloud on day one. Its security posture has never been reviewed. What should the security manager do FIRST? A. Connect it behind a restrictive firewall B. Require it to adopt corporate security policies C. Perform security due diligence on its environment D. Extend cyber insurance to cover its systems (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 2d
The security Manager of the Rival company or Manufacturer ? Either way, a security due diligence need to be done on both ends .. if the security assessment of the manufacturer is uptodate, a security assessment of the rival company is necessary! Final answer = C
CISSP Practice Question (Domain 8: Software Development Security)
A shipping app relies on an open source library whose only maintainer went silent a year ago. A critical flaw is now public and release is in two weeks. Developers want to fork and patch it. What should the security manager do FIRST? A. Approve the fork to keep the release on schedule B. Assess the library's exposure and the alternatives to forking C. Require a software bill of materials for the app D. Block the exploit at the gateway as a compensating control (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 4d
@James Dobbin I went for B but was on the fence about SBOM because getting that would show all dependencies but then again the maintainer is AWOL - Could you expound on why SBOM is completely useless in this case ? Thank you :)
CISSP Practice Question (Domain 4: Communication and Network Security)
A retailer must move 200 stores to a cloud point of sale over internet links in 60 days. The network team proposes an encrypted overlay so stores cut over as circuits arrive. What should the security manager do FIRST? A. Approve the overlay to keep cutovers on schedule B. Identify the data flows and requirements the design must meet C. Require multifactor authentication on every store tunnel D. Commission a penetration test before the first cutover (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 5d
Identify the data flows and requirements the design must meet .. Assess the situation before any implementation - B
CISSP Practice Question (Domain 3: Security Architecture and Engineering)
A hospital must move its imaging platform to a public cloud within 90 days; design approval is due next week. The architect proposes provider managed encryption at rest for every workload. What should the security manager do FIRST? A. Approve the design to protect the contract deadline B. Confirm data classification and the shared responsibility split C. Require customer managed keys in a hardware security module D. Schedule a penetration test of the platform before go live (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
2 likes • 7d
B - Confirm data classification and the shared responsibility split … Then for a better security, require customer managed Keys in a hardware security Module.
CISSP Practice Question (Domain 1: Security and Risk Management)
A lender will embed a third party AI model in loan approvals, live in 90 days by board order. Nobody has set a risk appetite for AI decisions or named an owner. What should the CISO do FIRST? A. Draft an AI acceptable use policy for lenders B. Have the board set risk appetite and name an owner C. Commission due diligence on the model vendor D. Require bias and explainability testing before launch (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 8d
Talk to the Board first .. understand the risk appetite and name an owner .. this makes Risk assessment easier .
1-10 of 71
Idris Onimole
4
75 points to level up
@idris-onimole-7612
CS Incident Responder - Love learn and share knowledge, find a mentor towards being a Security consultant / Infosec manager. Taking CISSP soon.

Active 19h ago
Joined Sep 14, 2025
ENTP
Prague
Powered by