Activity
Mon
Wed
Fri
Sun
Nov
Dec
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
Sep
What is this?
Less
More
74 contributions to CISSP Study Group
CISSP Practice Question (Domain 1: Security and Risk Management)
A cloud outage cost a retailer a day of online sales. The CFO has funded a second region and wants migration started this quarter. No business impact analysis exists. What should the security manager do FIRST? A. Design the second region with the cloud team B. Conduct a business impact analysis to set recovery targets C. Negotiate a stronger uptime commitment with the provider D. Buy business interruption insurance for cloud outages (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 2d
Conduct a BIA to set recovery time
CISSP Practice Question (Domain 4: Communication and Network Security)
A key customer wants a site-to-site link into the plant network in 30 days so its ordering system can read live inventory. The contract is signed and the customer's security posture is unknown. What should the security manager do FIRST? A. Build the tunnel, firewall rules limited to inventory B. Assess the risk and define the connection's requirements C. Require the customer's security assessment report first D. Publish inventory through an isolated extranet segment (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 6d
The customer’s security posture is already known so the next step is assessing the specific risk making that connection pose and then defining the connection requirements. - B
CISSP Practice Question (Domain 6: Security Assessment and Testing)
A cloud payroll vendor offers a SOC 2 Type I report dated 14 months ago to close a contract due Friday. HR wants to sign. What should the security manager do FIRST? A. Require a current SOC 2 Type II before signing B. Review the report's scope, period and exceptions against services used C. Sign with a contractual right to audit clause D. Commission an independent penetration test of the vendor (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 8d
A quick read says A is more appropriate … An up-to-date report against a SOC 2 Type 1 (14months ago) makes a more sense.
CISSP Practice Question (Domain 1: Security and Risk Management)
A manufacturer buys a smaller rival in 30 days. The CEO wants its network joined to the corporate cloud on day one. Its security posture has never been reviewed. What should the security manager do FIRST? A. Connect it behind a restrictive firewall B. Require it to adopt corporate security policies C. Perform security due diligence on its environment D. Extend cyber insurance to cover its systems (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 11d
The security Manager of the Rival company or Manufacturer ? Either way, a security due diligence need to be done on both ends .. if the security assessment of the manufacturer is uptodate, a security assessment of the rival company is necessary! Final answer = C
CISSP Practice Question (Domain 8: Software Development Security)
A shipping app relies on an open source library whose only maintainer went silent a year ago. A critical flaw is now public and release is in two weeks. Developers want to fork and patch it. What should the security manager do FIRST? A. Approve the fork to keep the release on schedule B. Assess the library's exposure and the alternatives to forking C. Require a software bill of materials for the app D. Block the exploit at the gateway as a compensating control (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 13d
@James Dobbin I went for B but was on the fence about SBOM because getting that would show all dependencies but then again the maintainer is AWOL - Could you expound on why SBOM is completely useless in this case ? Thank you :)
1-10 of 74
Idris Onimole
4
72 points to level up
@idris-onimole-7612
CS Incident Responder - Love learn and share knowledge, find a mentor towards being a Security consultant / Infosec manager. Taking CISSP soon.

Active 2d ago
Joined Sep 14, 2025
ENTP
Prague
Powered by