Activity
Mon
Wed
Fri
Sun
Nov
Dec
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
Sep
What is this?
Less
More
38 contributions to CISSP Study Group
CISSP Practice Question (Domain 5: Identity and Access Management (IAM))
Attackers twice reset executive passwords by phoning the outsourced help desk. The CIO wants phishing-resistant MFA purchased this month. No standard defines how callers prove identity. What should the security manager do FIRST? A. Deploy phishing-resistant MFA for all executives B. Require manager callback approval for every reset C. Retrain help desk staff on social engineering D. Assess the reset process and define identity proofing requirements (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
0 likes • 9h
D
CISSP Practice Question (Domain 7: Security Operations)
HR suspects a departing engineer copied source code to a personal drive. The engineer leaves Friday and the CTO wants IT to search the laptop today. What should the security operations manager do FIRST? A. Have IT review the laptop's file history for proof B. Disable the engineer's accounts and seize the laptop now C. Preserve the device and logs under chain of custody with legal D. Report the suspected theft to law enforcement (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 5d
@Christian Er. Not if they were reviewing file history via audit logs. So long as the files themselves are not touched. Also they may have been touched since the suspected exfiltration by the user so there is no guarantee they are accurate.
1 like • 5d
@Christian Er. Do you mean keyword as in the ability to search? That can be done remotely usually via some form of endpoint management, although that is not mentioned and so is an assumption on my part which is a fair point sir.
CISSP Practice Question (Domain 8: Software Development Security)
A sales team built a customer portal on a low-code platform without security involvement and wants it live Monday. It holds customer contracts and nobody owns its code or data. What should the security manager do FIRST? A. Schedule a penetration test before Monday B. Move the portal into the corporate development pipeline C. Assess the portal's data, risk and ownership before release D. Require secure coding training for the sales team (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
0 likes • 5d
C
CISSP Practice Question (Domain 2: Asset Security)
Finance wants a server holding ten years of contracts retired by quarter end to cut costs. No retention schedule exists and two vendor disputes are open. What should the security manager do FIRST? A. Archive everything to cloud storage, then wipe the server B. Confirm retention and legal hold needs with legal and records owners C. Have records owners delete anything older than seven years D. Cryptographically erase the drives after a verified backup (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 7d
B. There is no retention schedule for this data yet so we need to work with the business to determine the requirements. This will inform us on whether we do A, C or D next. Policy and legal requirements beats going straight to technical solutions first.
CISSP Practice Question (Domain 3: Security Architecture and Engineering)
A logistics firm's new warehouse robotics design puts robots, cameras and the ERP link in one trust zone to hit go-live. Design sign-off is next week. What should the security architect do FIRST? A. Require segmentation between robots, cameras and the ERP link B. Threat model the design against requirements and risk appetite C. Approve it with compensating monitoring until segmentation is funded D. Mandate zero trust device authentication before go-live (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
0 likes • 8d
B
1-10 of 38
James Dobbin
3
18 points to level up
@james-dobbin-9355
20+ as a jack of all trades years in I.T systems administration. Moving my career to I.T security

Active 8h ago
Joined Feb 18, 2026
Powered by