Activity
Mon
Wed
Fri
Sun
Sep
Oct
Nov
Dec
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
What is this?
Less
More

Owned by Vincent

CISSP Study Group

2.2k members • Free

Share resources, get advice, and connect with peers studying cybersecurity. Join our CISSP study group and connect with fellow professionals today!

Memberships

Skoolers

161.3k members • Free

807 contributions to CISSP Study Group
Hat trick for the Study Group!!
Three in one week, good job all, so proud to be a part of our community. and another congrats to @Kate Shairs @Devdutt Jha @James Bonner
Hat trick for the Study Group!!
Provisionally passed the CISSP exam
I just wanted to say thank you to this group and @Vincent Primiani. It has been a very helpful resource for the content of course, but also for the company and support in kind, like-minded people on the same journey. I wish every one of you nothing but success and hope to reconnect for the next challenge!
1 like • 2d
Congratulations!! Please think of us fondly and often.
CISSP Practice Question (Domain 4: Communication and Network Security)
A business partner requires an always-on site-to-site tunnel into a shared application segment. Their security posture is unknown, and the contract is already signed. What should the network security manager do FIRST? A. Terminate the tunnel in a dedicated screened segment B. Assess the partner's security posture against connection requirements C. Route all partner traffic through the inspection stack D. Enforce mutual authentication and approved cipher policy (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
CISSP Practice Question (Domain 3: Security Architecture and Engineering)
A multinational firm plans a single global data lake for cost efficiency. Regional teams process citizen data under differing privacy regimes, and design approval is due next week. What should the security architect do FIRST? A. Validate jurisdictional data sovereignty requirements before design approval B. Segment the lake to enforce regional residency boundaries C. Apply tokenization to sensitive fields before global replication D. Escalate the cost-versus-compliance conflict to the risk committee (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
0 likes • 5d
@Michael Samson-Metzger Correct Answer: A. Validate jurisdictional data sovereignty requirements before design approval Explanation (CISSP logic): "Citizen data under differing privacy regimes" is a legal-first trigger. Data sovereignty and residency obligations are external constraints imposed by law, not design preferences the architect gets to weigh against cost. Those requirements define the boundaries of the solution space, so they must be known before any architecture is approved. Assessment precedes design, and legal requirements are non-negotiable inputs to that assessment. Breakdown: B. Segmentation is the correct eventual design pattern, and that's what makes it dangerous. It's a solution selected before the requirements are confirmed. You may be segmenting to the wrong boundaries, or some jurisdictions may prohibit the data leaving the country at all, which segmentation alone won't satisfy. C. Tokenization is implementation-layer, and it's a common false comfort. Several regimes treat tokenized or pseudonymized data as still personal data, so replication may remain unlawful. A technical control cannot override a legal restriction. A. ✅ Correct. Confirm the legal constraints first. They dictate whether a single global lake is even a viable architecture. D. Escalation is the strongest distractor and feels appropriately managerial. But escalating now hands the risk committee a conflict with no facts attached. You escalate after you've quantified the requirements, so leadership can make an informed accept-or-redesign decision. Think like a manager: You cannot design around a law you haven't read. Requirements first, architecture second, and legal requirements are requirements, not risks to be traded.
CISSP Practice Question (Domain 6: Security Assessment and Testing)
An internal audit team reporting directly to the CISO produces the assessment reports used for regulatory attestation. A regulator challenges the credibility of the results. What is the MOST appropriate action for executive management? A. Engage an independent third party to validate the disputed findings B. Restructure audit reporting lines to the board or audit committee C. Expand testing scope and increase assessment frequency D. Require management sign-off attestations on every audit report (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
0 likes • 7d
Correct Answer: B. Restructure audit reporting lines to the board or audit committee Explanation (CISSP logic): The regulator isn't disputing the findings, they're disputing the independence of the function that produced them. An audit team reporting to the CISO is auditing its own boss's controls, which is a structural conflict of interest regardless of how good the testing is. CISSP governance treats independence as a prerequisite for assurance: results are only credible when the assessor has no stake in the outcome. Fix the structure, not the report. Breakdown: A. Third-party validation is the strongest distractor and a legitimate control, but it only cleanses this one set of disputed findings. Next quarter you have the same conflict and the same challenge. It treats the symptom, not the root cause. B. ✅ Correct. Moving audit reporting to the board or audit committee restores organizational independence and makes every future attestation defensible. C. More testing and more frequency amplifies output from a compromised structure. Volume is not credibility. D. Management sign-off actually makes it worse: it deepens the involvement of the very people whose controls are under review. Think like a manager: Assurance is a function of independence, not effort. If the auditor answers to the audited, the findings are an opinion, not evidence.
1-10 of 807
Vincent Primiani
7
4,879 points to level up
Cybersecurity. The Study Group Guy.

Active 10h ago
Joined Apr 29, 2024
New York, NY
Powered by