Activity
Mon
Wed
Fri
Sun
Oct
Nov
Dec
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
Sep
What is this?
Less
More
CISSP Study Group

2.3k members • Free

4 contributions to CISSP Study Group
CISSP Practice Question (Domain 6: Security Assessment and Testing)
A retailer's payment platform needs a penetration test before a regulator's deadline in six weeks. The platform team offers to test it themselves. What is the MOST appropriate response from the security manager? A. Accept the offer and review the resulting report yourself B. Engage an independent tester and agree scope and rules of engagement C. Run a vulnerability scan first to fix known defects D. Postpone testing until open platform findings are remediated (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
0 likes • 5h
B
CISSP Practice Question (Domain 7: Security Operations)
A regulator audits disaster recovery in 45 days. The plan was rewritten after a cloud migration but never exercised. The infrastructure lead wants a full production failover next weekend as proof. What should the security operations manager do FIRST? A. Approve the failover so the audit gets real evidence B. Tabletop the revised plan with the business owners C. Verify the recovery site backups can be restored D. Ask the regulator for an extension until testing finishes (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
0 likes • 5h
B
CISSP Practice Question (Domain 1: Security and Risk Management)
A manufacturer buys a smaller rival in 30 days. The CEO wants its network joined to the corporate cloud on day one. Its security posture has never been reviewed. What should the security manager do FIRST? A. Connect it behind a restrictive firewall B. Require it to adopt corporate security policies C. Perform security due diligence on its environment D. Extend cyber insurance to cover its systems (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
0 likes • 5h
C
CISSP Practice Question (Domain 6: Security Assessment and Testing)
A cloud payroll vendor offers a SOC 2 Type I report dated 14 months ago to close a contract due Friday. HR wants to sign. What should the security manager do FIRST? A. Require a current SOC 2 Type II before signing B. Review the report's scope, period and exceptions against services used C. Sign with a contractual right to audit clause D. Commission an independent penetration test of the vendor (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
0 likes • 5h
B
1-4 of 4
Olaide Azeez
1
5 points to level up
@olaide-azeez-4076
Security is Everyone’s Responsibility

Active 5h ago
Joined Mar 20, 2026
Powered by