Activity
Mon
Wed
Fri
Sun
Oct
Nov
Dec
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
Sep
What is this?
Less
More
CISSP Study Group

2.3k members • Free

31 contributions to CISSP Study Group
CISSP Practice Question (Domain 1: Security and Risk Management)
During business continuity planning, the IT director assigns recovery time objectives based on system complexity and restoration effort. Several business units later dispute the recovery priorities. Who should the BCP coordinator ensure determines the RTOs? A. The IT director, who understands restoration capability B. Business process owners, based on impact analysis C. Executive management, to resolve the dispute with authority D. The BCP coordinator, to maintain plan consistency (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
B
CISSP Practice Question (Domain 1: Security and Risk Management)
A security consultant discovers her client is knowingly misrepresenting remediation status to its customers after an assessment she performed. The client cites confidentiality clauses in her contract and directs her to stay silent. Under the ISC2 Code of Ethics, what is her PRIMARY obligation? A. Honor the confidentiality agreement with the client B. Act honorably and protect the public trust C. Report the misrepresentation to affected customers D. Withdraw from the engagement and document concerns (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
B
CISSP Practice Question (Domain 6: Security Assessment and Testing)
Leadership orders a penetration test of a customer-facing platform after a competitor's breach. Half the platform runs on a SaaS provider's infrastructure. The testing firm is contracted and ready to begin. What should the security manager confirm FIRST? A. Authorization and scope boundaries from the SaaS provider B. Rules of engagement defining escalation and stop conditions C. Backups of production data before intrusive testing begins D. Cyber liability coverage extends to testing activities (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
c?
Provisionally passed the CISSP exam
Hello All, I am so happy to share that I provisionally passed my CISSP exam today :). I want to take this opportunity to thank this community and everyone who were part of the study groups that I was part of. Learned a lot from our discussions, tips and tricks and recommendations that you all shared. I am not sure how I would have passed it today without this community support! You all are awesome :). Completed the test in 100 questions in roughly 2hours and 10mins. Cleared in first attempt (had purchased peace of mind option but now wont have to use it). 11 weeks of preparation. I believe there are many ways/paths/strategies to reach the goal. Below are some of the things that worked for me, maybe you find something that works for you (most of the below ideas I copied from others success stories :)). Learning tips: - Made a broad study plan into 3 phases. Phase 1 and 2 is to complete all 8 domains. Phase 3 is rework and lots of tests. - Each week made a weekly plan of what has to be achieved in the following week. Week starts on Monday and ends on Sunday. Review date is Thursday/Friday to see what is on track and obstacles.  - Took study holiday to catch up on/focused learning sessions. Took 4 days in total (1 each in week 2, 3 and 2 days before the exam day) - After each learning session, took 5-10mins to summarize what was learnt. Without looking. During the session wrote down the key words or headings and then fill it in at the end of the training session. Took quite a few pictures from the training sessions and was a good refresher to go through all the notes and pictures in last few days of the exam. - Learn every day. Take practice questions every day. - Used AI to deep dive and learn about the topic which I could not answer in the mock test. - Took mock tests from different sources/question banks. Taking from one source/question bank can create a bias to getting familiar with the pattern. Idea is to go beyond pattern recognition. - Built a rhythm/routine in the last few days. Repeated the same set of activities. My exam was in the afternoon, so for the last 5 days I did the same routine: Study for 1 hour, followed by morning run for 1 hour, short nap and post lunch full mock test for 2-3 hours! 
@Shahanaj Begum thanks
@Lai Ya Min Chit thanks
CISSP Practice Question
A multinational organization discovers that a critical third-party SaaS provider processes sensitive customer data. During a routine review, the security team learns that the provider does not support MFA for privileged administrative accounts.The organization’s security policy requires MFA for privileged access, but the SaaS contract does not explicitly require the provider to implement it. The business owner argues that replacing the provider would be expensive and could disrupt operations. What should the security manager do FIRST? A. Require the provider to implement MFA immediately as a condition of continued service. B. Perform a risk assessment to determine whether the provider's control gap exceeds the organization's risk appetite. C. Terminate the provider because it violates the organization's security policy. D. Negotiate a contractual amendment requiring MFA and periodic compliance audits.
B
1-10 of 31
Sunilkumar Prasanchand
3
23 points to level up
@sunilkumar-prasanchand-8248
Automotive Cybsersecurity System Architect

Active 4d ago
Joined May 27, 2026
Powered by