Activity
Mon
Wed
Fri
Sun
Nov
Dec
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
Sep
Oct
What is this?
Less
More
3 contributions to CISSP Study Group
CISSP Practice Question (Domain 1: Security and Risk Management)
A new CISO inherits a mature control environment but finds no documented risk assessments supporting it. Leadership considers the controls sufficient and resists spending on analysis. What should the CISO do FIRST? A. Conduct a risk assessment to align controls with business risk B. Benchmark the control set against an industry framework C. Present leadership a business case for the assessment budget D. Continue operations while documenting controls retroactively (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
0 likes • Aug 20
C
CISSP Practice Question (Domain 6: Security Assessment and Testing)
An internal audit team reporting directly to the CISO produces the assessment reports used for regulatory attestation. A regulator challenges the credibility of the results. What is the MOST appropriate action for executive management? A. Engage an independent third party to validate the disputed findings B. Restructure audit reporting lines to the board or audit committee C. Expand testing scope and increase assessment frequency D. Require management sign-off attestations on every audit report (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
0 likes • Jul 27
A
CISSP Practice Question (Domain 2: Asset Security)
A cloud migration reveals thousands of unlabeled legacy files containing mixed customer and internal data. The project sponsor wants to bulk-encrypt everything and proceed to meet the cutover date. What should the data governance lead do FIRST? A. Classify the data according to the organizational scheme B. Encrypt all files at the highest protection level C. Identify data owners to assign accountability D. Apply retention policies to purge obsolete records (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • Jul 18
I believe “c” is the correct answer. “A” seams correct but only the data owner can accurately classify the data, not the project sponsor.
1-3 of 3
Dan Ronco
1
4 points to level up
@dan-ronco-5982
Security Architecture professional with 15 years in the IT/Security space

Active 3h ago
Joined Jul 9, 2026
North Carolina
Powered by