Activity
Mon
Wed
Fri
Sun
Nov
Dec
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
Sep
What is this?
Less
More
10 contributions to CISSP Study Group
🎉 CISSP Exam Passed! (First Attempt at 100 Questions!)
Hi everyone, I am thrilled to share that I officially cleared the CISSP exam yesterday at the 100-question mark on my first attempt! To give a bit of background, I started my CISSP preparation right after passing my CCSP 6 weeks ago. Here is what my preparation looked like: - Core Study Material: Studied the Official Study Guide (OSG) 10th Edition cover-to-cover, using AI tools (Gemini and Claude) to deep-dive into areas where the OSG lacked a bit of depth and to effectively cover that delta. - Visual Learning: Utilized Destination Certification's mind map videos to solidify concepts. - Practice Assessments: Leveraged the Destination Certification app practice tests, alongside the Skool "CISSP, CCSP & CISM Practice Exams | Expert-Calibrated Questions — cissp.app" practice and full-length tests, to benchmark my readiness. - Final Refresher: Used The CISSP Field Manual by Clearance to Wealth as a fantastic quick refresher right before the exam. - Collaborative Learning: Participated actively in classes alongside a diverse group of talented professionals. The interactive sessions fostered a healthy and professional environment where we could analyze questions from multiple angles. Hearing different viewpoints on scenario-based reasoning provided valuable insights into why a choice is correct or incorrect, significantly sharpening my exam mindset. I want to extend a huge thank you to everyone who made this journey a success: - Vincent: For initializing and running this amazing CISSP Skool community. - The Facilitators: For exposing us to a rich variety of challenging questions through the classes. - My Study Group: A heartfelt thank you to Ed, Ricardo, Enrico, Victor, Matthew, Pavithra, Emma, Aidah, Vishal, David and many more for your incredible support and camaraderie. Thank you all again. On to the next chapter!
1 like • 15h
Congrats @Chiru Adapa
CISSP Practice Question (Domain 1: Security and Risk Management)
A security consultant discovers her client is knowingly misrepresenting remediation status to its customers after an assessment she performed. The client cites confidentiality clauses in her contract and directs her to stay silent. Under the ISC2 Code of Ethics, what is her PRIMARY obligation? A. Honor the confidentiality agreement with the client B. Act honorably and protect the public trust C. Report the misrepresentation to affected customers D. Withdraw from the engagement and document concerns (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
0 likes • 29d
B
CISSP Practice Question (Domain 4: Communication and Network Security - Zero Trust)
Your company adopts Zero Trust and replaces the legacy VPN with identity-based access for remote workers. Six weeks in, helpdesk tickets spike: users complain that access to internal apps breaks unpredictably throughout the day. What is the MOST likely root cause? A. Insufficient bandwidth at the identity provider B. Continuous authentication is re-evaluating trust signals and revoking sessions C. DNS resolution failures between the client and the policy enforcement point D. Certificate pinning conflicts with the new SSO provider Come back for the answer tomorrow, or study more now!
1 like • Apr 26
B
CISSP Practice Question (Domain 1: Security and Risk Management)
Your organization acquires a competitor and inherits their customer database containing PII subject to GDPR. The integration team wants to merge both databases immediately to eliminate duplicate customer records. The acquired company's privacy notices did not disclose data sharing with third parties. What should you do FIRST? A. Obtain updated consent from the acquired company's customers before merging B. Conduct a data protection impact assessment on the proposed database merge C. Proceed with the merge using the acquiring company's existing privacy framework D. Engage the DPO to determine whether a lawful basis for processing exists under the new entity Come back for the answer tomorrow, or study more now!
1 like • Mar 30
D
CISSP Practice Question (Domain 6: Security Assessment and Testing)
Your organization passes its annual SOC 2 Type II audit with no findings. Two months later, a penetration test reveals a critical vulnerability in a customer-facing application that has existed for over a year. The board questions why the audit missed it. What is the BEST explanation? A. The penetration testing firm used more advanced techniques than the SOC 2 auditors B. SOC 2 evaluates control design and operating effectiveness, not technical vulnerability discovery C. The audit scope was improperly defined and should have included application testing D. The auditors failed to meet professional due diligence standards Come back for the answer tomorrow, or study more now!
1 like • Mar 29
B
1-10 of 10
Mark Brown
2
14 points to level up
@mark-brown-2374
Studying CISSP

Active 5h ago
Joined Mar 3, 2026
Powered by