Activity
Mon
Wed
Fri
Sun
Sep
Oct
Nov
Dec
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
What is this?
Less
More

Owned by Vincent

CISSP Study Group

2.3k members • Free

Share resources, get advice, and connect with peers studying cybersecurity. Join our CISSP study group and connect with fellow professionals today!

Skoolers

161.7k members • Free

811 contributions to CISSP Study Group
Introductions
Welcome to the group! Please share what you hope to gain from being here, and for fun, tell us the best piece of advice you've ever received!
0 likes • 3d
@Chiru Adapa that’s awesome ! Congratulations we are happy to have you
0 likes • 17h
@Silje Bjørknes welcome!
CISSP Practice Question (Domain 7: Security Operations)
During active ransomware containment, the operations team wants to immediately wipe and reimage infected servers to restore a critical service. Cyber insurance and law enforcement notifications are pending. What should the incident commander do FIRST? A. Preserve forensic images of affected systems before restoration B. Restore the service from the most recent clean backup C. Notify the cyber insurer to avoid violating policy conditions D. Isolate remaining unaffected segments to prevent spread (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
CISSP Practice Question (Domain 8: Software Development Security)
A development team adopts a widely used open source library that accelerates delivery of a revenue-critical release. The library has no active maintainer and no published vulnerability disclosure process. What should the security manager recommend FIRST? A. Add the library to the software bill of materials for monitoring B. Evaluate the component against secure acquisition and supply chain criteria C. Fork the library so the organization controls future patching D. Require compensating controls at the application perimeter (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
0 likes • 2d
@David Uchieng Correct Answer: B. Evaluate the component against secure acquisition and supply chain criteria Explanation (CISSP logic): An abandoned library with no disclosure process is a supply chain risk decision disguised as a technical one. CISSP treats third-party software acquisition the same way it treats vendor onboarding: you evaluate the component against defined criteria before it enters the SDLC, not after. The evaluation answers the only question that matters right now, which is whether this dependency is acceptable at all. Every other option assumes the answer is yes. Breakdown: A. Adding it to the SBOM is the strongest distractor because SBOM is exactly the right modern practice for this class of risk. But an SBOM is an inventory control. It tells you that you have an unmaintained library; it does not decide whether you should. It also delivers little value here, since monitoring for disclosed vulnerabilities is nearly useless when nobody is left to disclose them. B. ✅ Correct. Assess the component against acquisition criteria first. That evaluation determines whether you accept, remediate, or reject the dependency. C. Forking is a treatment option chosen before the risk is assessed. It also silently transfers ongoing maintenance and patching liability onto your team, which is a resourcing commitment leadership never agreed to. D. Perimeter compensating controls address exploitation of a flaw you haven't identified in code you haven't evaluated. That's mitigation without analysis. Think like a manager: Free code is not free of obligation. Every dependency you accept is a vendor you onboarded without a contract, so evaluate it like one.
CISSP Practice Question (Domain 4: Communication and Network Security)
A business partner requires an always-on site-to-site tunnel into a shared application segment. Their security posture is unknown, and the contract is already signed. What should the network security manager do FIRST? A. Terminate the tunnel in a dedicated screened segment B. Assess the partner's security posture against connection requirements C. Route all partner traffic through the inspection stack D. Enforce mutual authentication and approved cipher policy (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
0 likes • 7d
@Geir Johansen ✅ Correct Answer: B. Assess the partner's security posture against connection requirements Explanation (CISSP logic): A signed contract commits the business to the relationship, not to an unconditional network connection. "Security posture is unknown" is the clue: you are being asked to extend your trust boundary to an unmeasured party. Third-party connection due diligence comes before you design the connection. The assessment determines what controls the tunnel actually needs and whether the connection can be permitted at all. Breakdown: A. A screened segment is excellent architecture and the strongest distractor. But it's a design decision made before you know the threat you're isolating. Assessment tells you whether a DMZ termination is sufficient or whether this partner warrants far tighter restrictions. B. ✅ Correct. Assess first. Due diligence on the connecting party defines the requirements every other option is trying to satisfy. C. Full inspection is an operational control applied without knowing what you're inspecting for. It also assumes the connection is already approved, which is the question being skipped. D. Mutual authentication and cipher policy secure the tunnel itself. A perfectly encrypted pipe to a compromised partner delivers threats with excellent confidentiality. Think like a manager: A contract creates an obligation to do business, never an obligation to connect blindly. Assess the party before you build the path.
Hat trick for the Study Group!!
Three in one week, good job all, so proud to be a part of our community. and another congrats to @Kate Shairs @Devdutt Jha @James Bonner
Hat trick for the Study Group!!
1 like • 7d
@Ed Morawski I do want to make some Study Group swag for group leaders and graduates. Hats are just so expensive in a small run. I was thinking a keychain something like this
1-10 of 811
Vincent Primiani
7
4,867 points to level up
Cybersecurity. The Study Group Guy.

Active 12h ago
Joined Apr 29, 2024
New York, NY
Powered by