Activity
Mon
Wed
Fri
Sun
Apr
May
Jun
Jul
Aug
Sep
Oct
Nov
Dec
Jan
Feb
Mar
What is this?
Less
More

Memberships

CISSP Study Group

2k members • Free

60 contributions to CISSP Study Group
CISSP Practice Question (Domain 1: Security and Risk Management)
During a third-party risk assessment, you discover a critical SaaS vendor stores customer data in a jurisdiction that conflicts with your organization's data residency requirements. The vendor scores well on every other security benchmark. The contract renewal deadline is in two weeks. What should you do FIRST? A. Require the vendor to migrate data to a compliant region before renewal B. Engage legal counsel to assess regulatory exposure and contractual options C. Renew the contract with an addendum requiring future data residency compliance D. Begin evaluating alternative vendors that meet data residency requirements Come back for the answer tomorrow, or study more now!
0 likes • 2d
B
CISSP Practice Question (Domain 1: Security and Risk Management)
Your organization's risk register is maintained by a single senior analyst who built custom scoring formulas undocumented outside his workstation. He announces his resignation with two weeks notice. The next quarterly risk review is in three weeks. What should you do FIRST? A. Hire a replacement analyst before the departing employee's last day B. Conduct an immediate knowledge transfer to document the scoring methodology C. Postpone the quarterly risk review until a replacement is onboarded D. Assign the risk register to the internal audit team as an interim measure Come back for the answer tomorrow, or study more now!
1 like • 9d
B is the best option.
0 likes • 3d
B
2 likes • 4d
I am sorry to hear the news @Alton Butler . DO NOT GIVE UP! This will just make you stronger when you attack the exam again. I know that for the longest time you know the material and have proven that in our classes. You may have to find a different way to attack the exam. It just may be something simple that you are missing. Let me know how I can help you.
CISSP Practice Question (Domain 8: Software Development Security)
A developer commits API credentials into a public repository and immediately deletes the commit. The security team discovers the credentials are still visible in the repository's commit history. The API provides read access to customer records. What should you do FIRST? A. Purge the commit history to remove the exposed credentials from the repository B. Revoke and rotate the compromised API credentials immediately C. Scan customer records for evidence of unauthorized access using the exposed keys D. Implement pre-commit hooks to prevent future credential exposure in repositories Come back for the answer tomorrow, or study more now!
0 likes • 5d
B
CISSP Practice Question (Domain 8: Software Development Security)
A development team integrates a third-party open-source library that processes customer PII. Six months later, a critical vulnerability is disclosed in that library. The vendor has not released a patch. Business stakeholders resist removing the library because it powers a revenue-generating feature. What is the MOST appropriate action? A. Implement compensating controls around the vulnerable component and document the accepted risk B. Fork the library and develop an internal patch C. Escalate to the risk owner for a formal risk acceptance decision D. Immediately remove the library and disable the affected feature Come back for the answer tomorrow, or study more now!
2 likes • 5d
I think C is the BEST approach. A The data owner has to accept the risk before any steps are taken. B Forking the library may complicate and cause errors in the functionality of the library. D Is destructive to the revenue stream.
1-10 of 60
Ed Morawski
3
18points to level up
@ed-morawski-4430
Ed

Active 1m ago
Joined Nov 21, 2025
Powered by