Activity
Mon
Wed
Fri
Sun
Sep
Oct
Nov
Dec
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
What is this?
Less
More
CISSP Study Group

2.3k members • Free

48 contributions to CISSP Study Group
CISSP Practice Question (Domain 7: Security Operations)
During active ransomware containment, the operations team wants to immediately wipe and reimage infected servers to restore a critical service. Cyber insurance and law enforcement notifications are pending. What should the incident commander do FIRST? A. Preserve forensic images of affected systems before restoration B. Restore the service from the most recent clean backup C. Notify the cyber insurer to avoid violating policy conditions D. Isolate remaining unaffected segments to prevent spread (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 2d
A - would preserve the evidence to prevent alteration or destruction before restoration.
CISSP Practice Question (Domain 8: Software Development Security)
A development team adopts a widely used open source library that accelerates delivery of a revenue-critical release. The library has no active maintainer and no published vulnerability disclosure process. What should the security manager recommend FIRST? A. Add the library to the software bill of materials for monitoring B. Evaluate the component against secure acquisition and supply chain criteria C. Fork the library so the organization controls future patching D. Require compensating controls at the application perimeter (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 7d
B - would determine whether the component satisfies the secure acquisition and supply chain criteria by assessing its quality, security, functionality, performance, compatibility, and compliance with requirements.
Provisionally passed CISSP Exam
I’ve officially passed my CISSP exam! A huge shoutout to this incredible community specially @Vincent Primiani , the cissp.app practice questions, and the insightful live group sessions for pushing me over the finish line. Appreciate all the support here! 🚀🎉
2 likes • 13d
Congratulations 🎉
CISSP Practice Question (Domain 4: Communication and Network Security)
A business partner requires an always-on site-to-site tunnel into a shared application segment. Their security posture is unknown, and the contract is already signed. What should the network security manager do FIRST? A. Terminate the tunnel in a dedicated screened segment B. Assess the partner's security posture against connection requirements C. Route all partner traffic through the inspection stack D. Enforce mutual authentication and approved cipher policy (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 13d
B - would evaluate whether a business partner's cybersecurity practices and controls meet organization's security requirements before allowing a connection to their systems or network.
CISSP Practice Question (Domain 3: Security Architecture and Engineering)
A multinational firm plans a single global data lake for cost efficiency. Regional teams process citizen data under differing privacy regimes, and design approval is due next week. What should the security architect do FIRST? A. Validate jurisdictional data sovereignty requirements before design approval B. Segment the lake to enforce regional residency boundaries C. Apply tokenization to sensitive fields before global replication D. Escalate the cost-versus-compliance conflict to the risk committee (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 15d
A - would be the first ideal option.
1-10 of 48
David Uchieng
3
37 points to level up
@david-uchieng-6550
Bachelor of Science in Information Technology

Active 6h ago
Joined Mar 9, 2026
Powered by