Activity
Mon
Wed
Fri
Sun
Oct
Nov
Dec
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
Sep
What is this?
Less
More
CISSP Study Group

2.3k members • Free

32 contributions to CISSP Study Group
CISSP Practice Question (Domain 1: Security and Risk Management)
A manufacturer buys a smaller rival in 30 days. The CEO wants its network joined to the corporate cloud on day one. Its security posture has never been reviewed. What should the security manager do FIRST? A. Connect it behind a restrictive firewall B. Require it to adopt corporate security policies C. Perform security due diligence on its environment D. Extend cyber insurance to cover its systems (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 2d
C. The key is the security's posture has never been security reviewed. Performing security due diligence is key to understanding the risks and decide on technical controls that are required.
CISSP Practice Question (Domain 8: Software Development Security)
A shipping app relies on an open source library whose only maintainer went silent a year ago. A critical flaw is now public and release is in two weeks. Developers want to fork and patch it. What should the security manager do FIRST? A. Approve the fork to keep the release on schedule B. Assess the library's exposure and the alternatives to forking C. Require a software bill of materials for the app D. Block the exploit at the gateway as a compensating control (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
2 likes • 4d
B. The key item here is that the flaw is now public greatly increasing the risk. A. is an option but still requires B before it is considered although it has residual risk in that it is not known if they will be able to patch and what testing can be done in the limited window to provide assurance. C is pointless given the situation and D might well break the application and is a technical control that shouldn’t be considered at this stage.
2 likes • 4d
@Idris Onimole yeah I get were you’re coming from. My logic was that it is likely an individual volunteer maintainer and so it was unlikely to have an SBOM
CISSP Practice Question (Domain 4: Communication and Network Security)
A retailer must move 200 stores to a cloud point of sale over internet links in 60 days. The network team proposes an encrypted overlay so stores cut over as circuits arrive. What should the security manager do FIRST? A. Approve the overlay to keep cutovers on schedule B. Identify the data flows and requirements the design must meet C. Require multifactor authentication on every store tunnel D. Commission a penetration test before the first cutover (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 5d
B. Understanding what data will flow and the design of the proposed overlay will ensure that only the required data traverse the links and that the appropriate encryption methods are used to secure the data in transit.
CISSP Practice Question (Domain 2: Asset Security)
A marketing team wants three years of customer support transcripts in an overseas AI analytics tool by month end. The transcripts were never classified and have no named owner. What should the security manager do FIRST? A. Approve the upload once the transcripts are anonymized B. Assign a data owner and classify the transcripts C. Require the provider to sign a data processing agreement D. Limit the upload to transcripts older than one year (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
0 likes • 5d
B.
CISSP Practice Question (Domain 6: Security Assessment and Testing)
A retailer's payment platform needs a penetration test before a regulator's deadline in six weeks. The platform team offers to test it themselves. What is the MOST appropriate response from the security manager? A. Accept the offer and review the resulting report yourself B. Engage an independent tester and agree scope and rules of engagement C. Run a vulnerability scan first to fix known defects D. Postpone testing until open platform findings are remediated (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 8d
B. The test performed by the platform team can’t be considered as unbiased or valid if they aren’t qualified to perform it. An independent test by a qualified vendor is the most appropriate action.
1-10 of 32
James Dobbin
3
23 points to level up
@james-dobbin-9355
20+ as a jack of all trades years in I.T systems administration. Moving my career to I.T security

Active 19h ago
Joined Feb 18, 2026
Powered by