Activity
Mon
Wed
Fri
Sun
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
Sep
Oct
Nov
Dec
What is this?
Less
More

Memberships

CISSP Study Group

1.8k members • Free

4 contributions to CISSP Study Group
Passed CISSP Exam!
I am excited to share that I have provisionally passed the CISSP yesterday; 100Qs, 1st attempt. 3 months of study, effort, time and discipline paid off, I took a winded path to the CISSP, took the CC in October, then SSCP in November and CISSP this December. Many thanks to this Community, couldn’t have done it without you’ll, the study sessions, the May Brooks strategies; came in clutch!Thanks for putting this together @Vincent Primiani. I’ll certainly be lurking around this community and help out where I can. Preciate you all!
0 likes • 1d
Congratulations!!
CISSP Practice Question (Domain 6: Security Assessment & Testing / Penetration Testing Governance)
A penetration test identifies a critical vulnerability in a customer-facing application, but exploitation would require downtime during peak business hours. The business requests delaying remediation until the next quarterly release. What should the security manager do FIRST? A. Accept the risk and document the delay as requested B. Perform a risk assessment and present impact analysis to business leadership C. Immediately remediate the vulnerability despite business objections D. Disable the affected application until remediation is complete
2 likes • 1d
B. My reasoning is that senior leadership needs to know first and the decision to accept risks is on them.
CISSP Practice Question (Domain 1: Security & Risk Management / Risk Acceptance)
A business unit requests an exception to bypass multifactor authentication for a legacy system that cannot support it without a costly upgrade. The system processes sensitive but non-regulated data, and no active exploits are known. What should the security manager do FIRST? A. Deny the request and mandate immediate MFA implementation B. Perform a risk assessment and formally document risk acceptance C. Approve the exception indefinitely due to technical limitations D. Compensate by increasing network monitoring without documentation
2 likes • 3d
B. because A is hands-on, and you need to document the risk so that eliminates D.
Introductions
Welcome to the group! Please share what you hope to gain from being here, and for fun, tell us the best piece of advice you've ever received!
2 likes • Nov 9
Hello everyone! I look forward to studying with a group, as I have tried to study myself and failed the exam twice so far. That’s why I’m here, I’m not going to give up and take it until I pass! I’m hoping that we can all share knowledge and help each other pass! Thank you for having me!
1-4 of 4
Christopher Hall
2
14points to level up
@christopher-hall-5715
Cybersecurity Specialist since 2008

Active 1h ago
Joined Oct 28, 2025
Powered by