Activity
Mon
Wed
Fri
Sun
Sep
Oct
Nov
Dec
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
What is this?
Less
More
CISSP Study Group

2.3k members • Free

42 contributions to CISSP Study Group
CISSP Practice Question (Domain 7: Security Operations)
During active ransomware containment, the operations team wants to immediately wipe and reimage infected servers to restore a critical service. Cyber insurance and law enforcement notifications are pending. What should the incident commander do FIRST? A. Preserve forensic images of affected systems before restoration B. Restore the service from the most recent clean backup C. Notify the cyber insurer to avoid violating policy conditions D. Isolate remaining unaffected segments to prevent spread (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
2 likes • 2d
D followed very quickly by A. Incident Commander's Priority Order 1. Contain the incident (isolate infected and at-risk systems) 2. Preserve forensic evidence/images 3. Notify cyber insurer, legal, and law enforcement as required 4. Eradicate and recover services from clean backups
CISSP Practice Question (Domain 5: Identity and Access Management)
After a merger, employees from the acquired company need immediate access to shared systems. The integration team proposes duplicating accounts into the parent directory to meet a hard business deadline. What is the MOST appropriate action for the security manager? A. Approve duplication with mandatory password resets B. Establish federated trust between the two identity providers C. Require role definitions and access reviews before provisioning D. Grant temporary elevated access until integration completes Come back for the answer tomorrow, or study more now!
1 like • 30d
I'm thinking IAM - Merger = Federation / Trust Relationship / SAML / OIDC before creating new accounts. CISSP generally favors centralized identity control and reduced credential sprawl over quick administrative workarounds. So I chose B!😁
CISSP Practice Question (Domain 1: Security and Risk Management)
Your organization is expanding into a country that requires all citizen data to be stored within its borders. The legal team recommends immediate compliance, but the existing cloud architecture uses a single global tenant. What should you do FIRST? A. Negotiate a regulatory exception with the host country's data authority B. Conduct a data sovereignty impact assessment against current architecture C. Migrate all citizen data to an in-country data center immediately D. Update the privacy policy to disclose cross-border data transfers Come back for the answer tomorrow, or study more now!
3 likes • Feb 9
You need to understand what data is impacted, where it currently resides/flows, which systems/processes touch it, and which regulatory controls apply before making architectural or policy changes. - B.
CISSP Practice Question (Domain 5: Identity and Access Management)
A global enterprise implements a zero-trust architecture requiring continuous authentication and authorization. During an incident investigation, security analysts discover that a compromised service account with high privileges has been making API calls from multiple geographic locations simultaneously. The account uses certificate-based authentication with a valid certificate that won't expire for 18 months. What is the MOST effective immediate containment action? A. Revoke the certificate through the Certificate Authority's Certificate Revocation List (CRL) B. Disable the service account in the identity provider C. Implement IP-based geo-fencing to block requests from unauthorized locations D. Rotate the account credentials and force re-authentication Come back for the answer tomorrow, or study more now!
0 likes • Feb 3
B is the fastest kill switch, effective regardless of the scope and honors the zero-trust assumed compromise position. Cut access quickly and THEN restore with clean creds, and least privilege. Right? A takes too long to propagate, C allows attackers to picot to unblocked locations, D. requires too much coordination and leaves the window of exposure open for too long. RIGHT??
CISSP Practice Question (Domain 1: Security and Risk Management)
A global organization adopts a cloud service to accelerate operations, despite unresolved concerns about data residency and regulatory exposure. Senior leadership accepts the business risk to meet market pressure. As the security leader, what is the MOST appropriate next action? A. Document the risk acceptance decision and associated residual risk B. Implement compensating technical controls to reduce exposure C. Transfer the risk through expanded cyber insurance coverage D. Escalate the decision to regulators for formal guidance Study more now!
4 likes • Jan 20
As the Fonz (Happy Days) used to say, "Aaaaay!" A THEN B.
1-10 of 42
Martin Joplin
3
24 points to level up
@martin-joplin-1962
I have 35+ years of IT experience with more than 15 years in IT management. Within the past 2 years I decided that I enjoyed Cybersecurity & ...

Active 2d ago
Joined Sep 3, 2024
Powered by