Activity
Mon
Wed
Fri
Sun
Nov
Dec
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
Sep
What is this?
Less
More
13 contributions to CISSP Study Group
CISSP Practice Question (Domain 5: Identity and Access Management (IAM))
Attackers twice reset executive passwords by phoning the outsourced help desk. The CIO wants phishing-resistant MFA purchased this month. No standard defines how callers prove identity. What should the security manager do FIRST? A. Deploy phishing-resistant MFA for all executives B. Require manager callback approval for every reset C. Retrain help desk staff on social engineering D. Assess the reset process and define identity proofing requirements (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
0 likes • 9h
D
CISSP Practice Question (Domain 1: Security and Risk Management)
A cloud outage cost a retailer a day of online sales. The CFO has funded a second region and wants migration started this quarter. No business impact analysis exists. What should the security manager do FIRST? A. Design the second region with the cloud team B. Conduct a business impact analysis to set recovery targets C. Negotiate a stronger uptime commitment with the provider D. Buy business interruption insurance for cloud outages (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
0 likes • 9h
B
CISSP Practice Question (Domain 7: Security Operations)
HR suspects a departing engineer copied source code to a personal drive. The engineer leaves Friday and the CTO wants IT to search the laptop today. What should the security operations manager do FIRST? A. Have IT review the laptop's file history for proof B. Disable the engineer's accounts and seize the laptop now C. Preserve the device and logs under chain of custody with legal D. Report the suspected theft to law enforcement (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
0 likes • 9h
I believe the choice would be C
CISSP Practice Question (Domain 8: Software Development Security)
A sales team built a customer portal on a low-code platform without security involvement and wants it live Monday. It holds customer contracts and nobody owns its code or data. What should the security manager do FIRST? A. Schedule a penetration test before Monday B. Move the portal into the corporate development pipeline C. Assess the portal's data, risk and ownership before release D. Require secure coding training for the sales team (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
0 likes • 5d
C
STUDY GROUP GUIDELINES
I have noticed a huge number of community members haven't read this. It is simple enough to follow!
STUDY GROUP GUIDELINES
0 likes • 6d
👍
1-10 of 13
Bill T.
1
4 points to level up
@bill-t-1088
Over 35+ year in Information Technology. Now working toward getting my CISSP. ... Love skiing and hiking/walking around...

Active 8h ago
Joined Sep 15, 2026
Powered by