Activity
Mon
Wed
Fri
Sun
Jul
Aug
Sep
Oct
Nov
Dec
Jan
Feb
Mar
Apr
May
What is this?
Less
More

Memberships

CISSP Study Group

2.1k members • Free

16 contributions to CISSP Study Group
Belled the CAT. Passed @ 100 Questions 🎉
Passed the CISSP Yesterday, 26 May! 🎉 Passed @ 100 questions with 58 minutes left to go, it's my first attempt. Huge shoutout to this CISSP Study Group (especially @Vincent Primiani & @Ed Morawski ) and all community members, you were the fuel on days when the tank was empty. Answered the daily quiz questions and few days community quiz sessions 💪😄 No bootcamps, no classroom. After work self-study for 2.5 months, coffee, and stubbornness. Thanks for the support guys and all the best for fellow mates💪
CISSP Practice Question (Domain 3: Security Architecture and Engineering - AI Exam Guidance)
Your organization is deploying a customer-facing chatbot powered by a third-party LLM. The product team wants to connect it directly to the order management database to answer real-time inventory questions. As the security architect, what is the BEST design control? A. Implement input validation to block prompt injection attempts B. Place an API gateway with strict allow-listed queries between the LLM and the database C. Require TLS 1.3 for all traffic between the chatbot and backend systems D. Deploy a WAF tuned for LLM-specific attack signatures Come back for the answer tomorrow, or study more now!
0 likes • 4d
B
CISSP Practice Question (Domain 8: Software Development Security)
A development team adopts a CI/CD pipeline that auto-deploys to production upon passing unit tests. Security testing currently runs weekly in a separate environment. A recent release introduced a SQL injection flaw that reached production. As the application security lead, what is the BEST corrective action? A. Block all deployments until weekly security testing completes B. Integrate SAST and dependency scanning as gating checks within the pipeline C. Require manual security review before each production release D. Shift security testing to a post-deployment runtime monitoring tool Come back for the answer tomorrow, or study more now!
0 likes • 5d
B
CISSP Practice Question (Domain 7: Security Operations)
During a ransomware incident, the IR team contains affected systems and begins recovery from backups. Mid-recovery, the CFO authorizes paying the ransom to accelerate restoration. As the incident commander, what should you do FIRST? A. Comply with the CFO's directive and coordinate the payment through counsel B. Halt recovery and escalate to the executive crisis team and legal for a documented decision C. Continue recovery from backups and refuse the payment on policy grounds D. Engage law enforcement to evaluate the legality of the ransom payment Come back for the answer tomorrow, or study more now!
0 likes • 5d
B
CISSP Practice Question (Domain 2: Asset Security - AI Exam Guidance)
Your data science team plans to fine-tune a large language model using historical customer support transcripts containing PII. The business wants the model deployed organization-wide for internal use. As the CISO, what is the MOST appropriate action BEFORE training begins? A. Encrypt the training dataset at rest and restrict access to data scientists B. Apply data minimization and de-identification techniques to the training corpus C. Require model output filtering to prevent PII disclosure in responses D. Obtain renewed customer consent for the new processing purpose Come back for the answer tomorrow, or study more now!
0 likes • 6d
B
1-10 of 16
Deepak Nv
2
6points to level up
@deepak-nv-1516
I am an average joe with interest in Cyber Security. I am here to learn the best practises for enabling safe professional environment.

Active 3d ago
Joined Feb 27, 2026
Powered by