Activity
Mon
Wed
Fri
Sun
Oct
Nov
Dec
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
Sep
What is this?
Less
More
CISSP Study Group

2.3k members • Free

6 contributions to CISSP Study Group
CISSP Practice Question (Domain 5: Identity and Access Management (IAM))
A finance AI agent pays invoices through a shared service account with a static password. Audit is in six weeks and the CFO wants it running. What should the security manager do FIRST? A. Rotate the password and vault the credential B. Assess the account's access and assign an owner C. Replace it with per-workflow managed identities D. Have the CFO sign a risk acceptance (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 22h
A - Password rotation and vaulting is the first and foremost step.
CISSP Practice Question (Domain 1: Security and Risk Management)
A manufacturer buys a smaller rival in 30 days. The CEO wants its network joined to the corporate cloud on day one. Its security posture has never been reviewed. What should the security manager do FIRST? A. Connect it behind a restrictive firewall B. Require it to adopt corporate security policies C. Perform security due diligence on its environment D. Extend cyber insurance to cover its systems (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 2d
C - It is important to understand the network & do the due diligence first. You can't stop what you don't see. Since it is going to be a one corporate network, blocking everything in between the networks doesn't make any sense.
CISSP Practice Question (Domain 7: Security Operations)
A regulator audits disaster recovery in 45 days. The plan was rewritten after a cloud migration but never exercised. The infrastructure lead wants a full production failover next weekend as proof. What should the security operations manager do FIRST? A. Approve the failover so the audit gets real evidence B. Tabletop the revised plan with the business owners C. Verify the recovery site backups can be restored D. Ask the regulator for an extension until testing finishes (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 3d
B - Putting full production Infrastructure down for testing requires business leadership approval.
CISSP Practice Question (Domain 4: Communication and Network Security)
A retailer must move 200 stores to a cloud point of sale over internet links in 60 days. The network team proposes an encrypted overlay so stores cut over as circuits arrive. What should the security manager do FIRST? A. Approve the overlay to keep cutovers on schedule B. Identify the data flows and requirements the design must meet C. Require multifactor authentication on every store tunnel D. Commission a penetration test before the first cutover (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
0 likes • 3d
B - Since PoS belongs to financial data, the flow must be understood first.
CISSP Practice Question (Domain 2: Asset Security)
A marketing team wants three years of customer support transcripts in an overseas AI analytics tool by month end. The transcripts were never classified and have no named owner. What should the security manager do FIRST? A. Approve the upload once the transcripts are anonymized B. Assign a data owner and classify the transcripts C. Require the provider to sign a data processing agreement D. Limit the upload to transcripts older than one year (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
0 likes • 3d
B - Data owner & classification must be done first.
1-6 of 6
Md Ashraf Razi
1
1 point to level up
@md-ashraf-razi-9145
Senior Cybersecurity Engineer with 8+ years of experience in Security Engineering and Incident Response

Active 17h ago
Joined Sep 15, 2026
Powered by