Activity
Mon
Wed
Fri
Sun
Sep
Oct
Nov
Dec
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
What is this?
Less
More
The Cyber Community

9.7k members • Free

CyberMAYnia CAREER

571 members • Free

CISSP Study Group

2.3k members • Free

123 contributions to CISSP Study Group
CISSP Practice Question (Domain 7: Security Operations)
During active ransomware containment, the operations team wants to immediately wipe and reimage infected servers to restore a critical service. Cyber insurance and law enforcement notifications are pending. What should the incident commander do FIRST? A. Preserve forensic images of affected systems before restoration B. Restore the service from the most recent clean backup C. Notify the cyber insurer to avoid violating policy conditions D. Isolate remaining unaffected segments to prevent spread (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 2d
A appropriate to keep evidence
CISSP Practice Question (Domain 8: Software Development Security)
A development team adopts a widely used open source library that accelerates delivery of a revenue-critical release. The library has no active maintainer and no published vulnerability disclosure process. What should the security manager recommend FIRST? A. Add the library to the software bill of materials for monitoring B. Evaluate the component against secure acquisition and supply chain criteria C. Fork the library so the organization controls future patching D. Require compensating controls at the application perimeter (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
2 likes • 7d
B should be appropriate to evaluate first
CISSP Practice Question (Domain 4: Communication and Network Security)
A business partner requires an always-on site-to-site tunnel into a shared application segment. Their security posture is unknown, and the contract is already signed. What should the network security manager do FIRST? A. Terminate the tunnel in a dedicated screened segment B. Assess the partner's security posture against connection requirements C. Route all partner traffic through the inspection stack D. Enforce mutual authentication and approved cipher policy (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 14d
B looks appropriate to assess partner security posture
CISSP Practice Question (Domain 3: Security Architecture and Engineering)
A multinational firm plans a single global data lake for cost efficiency. Regional teams process citizen data under differing privacy regimes, and design approval is due next week. What should the security architect do FIRST? A. Validate jurisdictional data sovereignty requirements before design approval B. Segment the lake to enforce regional residency boundaries C. Apply tokenization to sensitive fields before global replication D. Escalate the cost-versus-compliance conflict to the risk committee (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 16d
A should be appropriate with juridisical data validation
CISSP Practice Question (Domain 6: Security Assessment and Testing)
An internal audit team reporting directly to the CISO produces the assessment reports used for regulatory attestation. A regulator challenges the credibility of the results. What is the MOST appropriate action for executive management? A. Engage an independent third party to validate the disputed findings B. Restructure audit reporting lines to the board or audit committee C. Expand testing scope and increase assessment frequency D. Require management sign-off attestations on every audit report (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 18d
A appears appropriate with 3rd party validation
1-10 of 123
Dj Sahoo
5
347 points to level up
@dj-sahoo-9937
Dj

Active 7h ago
Joined Dec 12, 2025
Powered by