Activity
Mon
Wed
Fri
Sun
Sep
Oct
Nov
Dec
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
What is this?
Less
More

Memberships

CISSP Study Group

2.2k members • Free

15 contributions to CISSP Study Group
CISSP Practice Question (Domain 8: Software Development Security)
A development team adopts a widely used open source library that accelerates delivery of a revenue-critical release. The library has no active maintainer and no published vulnerability disclosure process. What should the security manager recommend FIRST? A. Add the library to the software bill of materials for monitoring B. Evaluate the component against secure acquisition and supply chain criteria C. Fork the library so the organization controls future patching D. Require compensating controls at the application perimeter (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
2 likes • 2d
B. Evaluate the component against secure acquisition and supply chain criteria When you adopt a third‑party component, especially one that is unmaintained and lacks a vulnerability disclosure process. The FIRST step is not to monitor it, patch it, or wrap it in compensating controls. The FIRST step is to assess its risk.
Mission Accomplished
I provisionally passed the CISSP! Let me get a "Roll Tide" 🤣
2 likes • 10d
@Hassan Na Thank you
0 likes • 8d
Thanks
CISSP Practice Question (Domain 2: Asset Security)
A business unit requests permanent retention of all customer transaction records "in case we ever need them." Legal has not issued a hold, and the current retention schedule requires deletion after seven years. As the data owner's advisor, what is the BEST response? A. Honor the request since longer retention reduces legal discovery risk B. Enforce the existing retention schedule and require a formal exception with risk acceptance C. Migrate the records to cold storage to balance cost and accessibility D. Defer to Legal before taking any action on the records Come back for the answer tomorrow, or study more now!
0 likes • May 5
B
CISSP Practice Question (Domain 4: Communication and Network Security)
Your organization is migrating critical workloads to a hybrid cloud. The network team proposes extending the existing flat internal VLAN into the cloud VPC to simplify routing and accelerate the cutover. As the security architect, what is the BEST response? A. Approve, provided IPsec tunnels encrypt all inter-site traffic B. Require micro segmentation aligned to a Zero Trust reference architecture C. Mandate east-west IDS sensors before the migration begins D. Defer until a cloud access security broker (CASB) is deployed Come back for the answer tomorrow, or study more now!
2 likes • May 1
B, The CISSP mindset is always: Fix the architecture before adding tools. Microsegmentation is the only answer that prevents lateral movement and aligns with Zero Trust — the modern standard for hybrid cloud security.🍵
CISSP Practice Question (Domain 3: Security Architecture - AI/ML Systems)
Your firm is procuring a third-party LLM to summarize client contracts containing privileged legal data. The vendor's standard agreement permits using customer inputs to improve their model. What should the security architect recommend FIRST? A. Negotiate a contract addendum prohibiting input use for model training B. Conduct a data flow and risk assessment to classify exposure boundaries C. Require the vendor to deploy a tenant-isolated model instance D. Implement DLP controls to redact privileged content before submission Come back for the answer tomorrow, or study more now!
0 likes • Apr 27
B
1-10 of 15
James Bonner
3
29 points to level up
@james-bonner-1546
My name is James D. Bonner, and I am a Senior Systems Analyst III with experience spanning cybersecurity, operations, and software testing. Hello all.

Active 2h ago
Joined Apr 14, 2026
Powered by