Activity
Mon
Wed
Fri
Sun
Sep
Oct
Nov
Dec
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
What is this?
Less
More
CyberMAYnia CAREER

571 members • Free

CISSP Study Group

2.3k members • Free

63 contributions to CISSP Study Group
CISSP Practice Question (Domain 7: Security Operations)
During active ransomware containment, the operations team wants to immediately wipe and reimage infected servers to restore a critical service. Cyber insurance and law enforcement notifications are pending. What should the incident commander do FIRST? A. Preserve forensic images of affected systems before restoration B. Restore the service from the most recent clean backup C. Notify the cyber insurer to avoid violating policy conditions D. Isolate remaining unaffected segments to prevent spread (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 2d
D. We’re still in the containment phase
CISSP Practice Question (Domain 5: Identity and Access Management)
After a merger, employees from the acquired company need immediate access to shared systems. The integration team proposes duplicating accounts into the parent directory to meet a hard business deadline. What is the MOST appropriate action for the security manager? A. Approve duplication with mandatory password resets B. Establish federated trust between the two identity providers C. Require role definitions and access reviews before provisioning D. Grant temporary elevated access until integration completes Come back for the answer tomorrow, or study more now!
0 likes • 6d
C
CISSP Practice Question (Domain 1: Security and Risk Management - AI Exam Guidance)
Your company plans to adopt a third-party AI vendor to process regulated customer data. The vendor offers strong contractual indemnification but declines to share model documentation. What should the security leader do FIRST? A. Negotiate stronger audit rights into the contract B. Perform a vendor risk assessment against organizational risk appetite C. Require the vendor to obtain independent AI certification D. Pilot the tool with anonymized data to evaluate performance
0 likes • 6d
B
CISSP Practice Question (Domain 2: Asset Security)
A cloud migration reveals thousands of unlabeled legacy files containing mixed customer and internal data. The project sponsor wants to bulk-encrypt everything and proceed to meet the cutover date. What should the data governance lead do FIRST? A. Classify the data according to the organizational scheme B. Encrypt all files at the highest protection level C. Identify data owners to assign accountability D. Apply retention policies to purge obsolete records (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
0 likes • 6d
C-need to identify owner first
CISSP Practice Question (Domain 3: Security Architecture and Engineering)
A multinational firm plans a single global data lake for cost efficiency. Regional teams process citizen data under differing privacy regimes, and design approval is due next week. What should the security architect do FIRST? A. Validate jurisdictional data sovereignty requirements before design approval B. Segment the lake to enforce regional residency boundaries C. Apply tokenization to sensitive fields before global replication D. Escalate the cost-versus-compliance conflict to the risk committee (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
0 likes • 6d
A
1-10 of 63
Naashon Zalk
3
42 points to level up
@naashon-zalk-2309
Cyber Security Consultant (GRC) | ISO 27001 Lead Implementer |

Active 2d ago
Joined Jan 26, 2026
Powered by