Activity
Mon
Wed
Fri
Sun
Oct
Nov
Dec
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
Sep
What is this?
Less
More
CISSP Study Group

2.3k members • Free

4 contributions to CISSP Study Group
CISSP Practice Question (Domain 6: Security Assessment and Testing)
A cloud payroll vendor offers a SOC 2 Type I report dated 14 months ago to close a contract due Friday. HR wants to sign. What should the security manager do FIRST? A. Require a current SOC 2 Type II before signing B. Review the report's scope, period and exceptions against services used C. Sign with a contractual right to audit clause D. Commission an independent penetration test of the vendor (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
0 likes • 1h
A : latest and recent SoC2 type II reports are beneficial for review that has the controls tested and any exceptions found.
CISSP Practice Question (Domain 5: Identity and Access Management (IAM))
A finance AI agent pays invoices through a shared service account with a static password. Audit is in six weeks and the CFO wants it running. What should the security manager do FIRST? A. Rotate the password and vault the credential B. Assess the account's access and assign an owner C. Replace it with per-workflow managed identities D. Have the CFO sign a risk acceptance (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 23h
B We need to assess first and then apply control what right to be done.
CISSP Practice Question (Domain 8: Software Development Security)
A shipping app relies on an open source library whose only maintainer went silent a year ago. A critical flaw is now public and release is in two weeks. Developers want to fork and patch it. What should the security manager do FIRST? A. Approve the fork to keep the release on schedule B. Assess the library's exposure and the alternatives to forking C. Require a software bill of materials for the app D. Block the exploit at the gateway as a compensating control (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 3d
B per standard approach, Manager should assess and validate the vulnerability for its app.
Group Mock Exam Day, Today!. Let's all sit it together.
Saturday September 19 is our first Group Mock Exam Day, and I want the whole group in on it. Here is the plan. On September 19, cissp.app is open to everyone, free, no subscription needed. Midnight to midnight Eastern you can sit a real adaptive CISSP mock exam, 100 to 150 questions, up to 3 hours, the same engine paying members use, and get a domain-by-domain breakdown at the end. You will be working from a new curated question bank built for the day: 500 questions across all eight CISSP domains, 100 easy, 250 medium and 150 hard, updated for ISC2's official AI exam guidance published September 1. It stays in cissp.app after the event. Kickoff, Saturday 3:00pm Eastern. We will host a live kickoff on Google Meet, the link is in your enrollment confirmation. Log in together, last-minute questions, then everyone goes and sits the exam. If you cannot make 3:00pm, you can start any time that day. Everyone who signs up goes on the public board at cissp.app/mock-exam-day, and as the day goes on it shows who has started and who has finished. Real names or a handle, up to you. No scores on the board, just who showed up and who finished, which is the part that matters. Afterwards. Take your weakest two or three domains to a study group session the week after, while it is all still fresh. Bring someone! The day is open to everyone, so send cissp.app/mock-exam-day to anyone you know who is studying for the CISSP. No subscription needed, and they will not be sitting it alone. Sign up now at cissp.app/mock-exam-day so your access is ready when the day starts. Then comment below with "I'm in" so we can see who is coming! If you have been putting off finding out where you actually stand, this is the day we can all do it together.
Group Mock Exam Day, Today!. Let's all sit it together.
0 likes • 5d
Awesome
1-4 of 4
Vishal Kumar
1
3 points to level up
@vishal-kumar-2187
Cyber Security Professional

Online now
Joined Sep 14, 2026
Chicago
Powered by