Activity
Mon
Wed
Fri
Sun
Oct
Nov
Dec
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
Sep
What is this?
Less
More
CyberMAYnia CAREER

592 members • Free

CISSP Study Group

2.3k members • Free

80 contributions to CISSP Study Group
CISSP Practice Question (Domain 1: Security and Risk Management)
A manufacturer buys a smaller rival in 30 days. The CEO wants its network joined to the corporate cloud on day one. Its security posture has never been reviewed. What should the security manager do FIRST? A. Connect it behind a restrictive firewall B. Require it to adopt corporate security policies C. Perform security due diligence on its environment D. Extend cyber insurance to cover its systems (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 2d
C - due diligence first
CISSP Practice Question (Domain 7: Security Operations)
A regulator audits disaster recovery in 45 days. The plan was rewritten after a cloud migration but never exercised. The infrastructure lead wants a full production failover next weekend as proof. What should the security operations manager do FIRST? A. Approve the failover so the audit gets real evidence B. Tabletop the revised plan with the business owners C. Verify the recovery site backups can be restored D. Ask the regulator for an extension until testing finishes (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 2d
b seems the best compromise
CISSP Practice Question (Domain 7: Security Operations)
Ransomware hits a file server mid product launch, and the sales VP wants last night's backup restored within the hour. Nobody has invoked the incident response plan. What should the security operations manager do FIRST? A. Restore the server from backup to protect the launch B. Isolate the server and preserve volatile evidence C. Declare the incident and activate the response plan D. Scan neighboring hosts to gauge how far it spread (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
0 likes • 5d
c- follow the plan
CISSP Practice Question (Domain 8: Software Development Security)
A product team used an AI coding assistant to build a payment feature and wants it in Friday's release. Nobody threat modeled the code, and the pipeline only runs unit tests. What should the application security manager require FIRST? A. Static and dynamic scanning gates in the pipeline B. Threat model of the feature's payment data flows C. Senior developer review of the generated code D. Feature flag and rollback plan for the release (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
0 likes • 5d
B threat modelling comes first
CISSP Practice Question (Domain 4: Communication and Network Security)
A hospital wants new internet-connected infusion pumps on the existing user VLAN to hit a ward opening date. The pumps cannot run endpoint agents and are patched quarterly. What should the network security manager require FIRST? A. Dedicated network zone for the pumps with controlled ingress B. Risk assessment of the pumps against clinical network requirements C. Network intrusion detection covering the user VLAN D. Vendor commitment to a faster patch cadence (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
0 likes • 5d
b - asses first
1-10 of 80
Naashon Zalk
3
35 points to level up
@naashon-zalk-2309
Cyber Security Consultant (GRC) | ISO 27001 Lead Implementer |

Active 2d ago
Joined Jan 26, 2026
Powered by