Activity
Mon
Wed
Fri
Sun
Nov
Dec
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
Sep
What is this?
Less
More
14 contributions to CISSP Study Group
CISSP Practice Question (Domain 5: Identity and Access Management (IAM))
Attackers twice reset executive passwords by phoning the outsourced help desk. The CIO wants phishing-resistant MFA purchased this month. No standard defines how callers prove identity. What should the security manager do FIRST? A. Deploy phishing-resistant MFA for all executives B. Require manager callback approval for every reset C. Retrain help desk staff on social engineering D. Assess the reset process and define identity proofing requirements (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
0 likes • 3h
D
CISSP Practice Question (Domain 7: Security Operations)
HR suspects a departing engineer copied source code to a personal drive. The engineer leaves Friday and the CTO wants IT to search the laptop today. What should the security operations manager do FIRST? A. Have IT review the laptop's file history for proof B. Disable the engineer's accounts and seize the laptop now C. Preserve the device and logs under chain of custody with legal D. Report the suspected theft to law enforcement (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 4d
C- Logs preservation will help taking up the case legally. That will be done FIRST
CISSP Practice Question (Domain 4: Communication and Network Security)
A key customer wants a site-to-site link into the plant network in 30 days so its ordering system can read live inventory. The contract is signed and the customer's security posture is unknown. What should the security manager do FIRST? A. Build the tunnel, firewall rules limited to inventory B. Assess the risk and define the connection's requirements C. Require the customer's security assessment report first D. Publish inventory through an isolated extranet segment (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 6d
B - Risk Assessment is the FIRST thing to do, if the connection requirements aren't that much, asking for security posture assessment report is not required.
STUDY GROUP GUIDELINES
I have noticed a huge number of community members haven't read this. It is simple enough to follow!
STUDY GROUP GUIDELINES
0 likes • 7d
👍
CISSP Practice Question (Domain 2: Asset Security)
Finance wants a server holding ten years of contracts retired by quarter end to cut costs. No retention schedule exists and two vendor disputes are open. What should the security manager do FIRST? A. Archive everything to cloud storage, then wipe the server B. Confirm retention and legal hold needs with legal and records owners C. Have records owners delete anything older than seven years D. Cryptographically erase the drives after a verified backup (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 7d
B makes most sense, since historical records are part of legal requirements, and retention should be confirmed FIRST from the respective record owners, in order to come to a decision to either move them to Cloud, or to get rid of them. No one wants to store stuffs in Cloud which are not required anymore as the storage also comes with some costs. After confirmation from the record owners, even if those records are needed, it will be easier to categorize which type of cloud storage tier is needed, Hot tier, cold tier, cool or archive tier.
1-10 of 14
Md Ashraf Razi
2
9 points to level up
@md-ashraf-razi-9145
Senior Cybersecurity Engineer with 8+ years of experience in Security Engineering and Incident Response

Active 3h ago
Joined Sep 15, 2026
Powered by