Activity
Mon
Wed
Fri
Sun
Nov
Dec
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
Sep
What is this?
Less
More
13 contributions to CISSP Study Group
Study Partner
Anyone sitting for exam in next 2 months and looking for a study partner?
0 likes • 5d
Yes
CISSP Practice Question (Domain 7: Security Operations)
Ransomware hits a file server mid product launch, and the sales VP wants last night's backup restored within the hour. Nobody has invoked the incident response plan. What should the security operations manager do FIRST? A. Restore the server from backup to protect the launch B. Isolate the server and preserve volatile evidence C. Declare the incident and activate the response plan D. Scan neighboring hosts to gauge how far it spread (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
0 likes • 20d
B
CISSP Practice Question
A multinational organization discovers that a critical third-party SaaS provider processes sensitive customer data. During a routine review, the security team learns that the provider does not support MFA for privileged administrative accounts.The organization’s security policy requires MFA for privileged access, but the SaaS contract does not explicitly require the provider to implement it. The business owner argues that replacing the provider would be expensive and could disrupt operations. What should the security manager do FIRST? A. Require the provider to implement MFA immediately as a condition of continued service. B. Perform a risk assessment to determine whether the provider's control gap exceeds the organization's risk appetite. C. Terminate the provider because it violates the organization's security policy. D. Negotiate a contractual amendment requiring MFA and periodic compliance audits.
0 likes • 24d
B
CISSP Question
Which of the following assurance mechanism’s is most likely to provide continuous feedback about how well the access control systems are working? a) Vulnerability Review b) Penetration Testing c) Security Policy Review d) Intrusion Detection System
0 likes • Aug 24
D
CISSP Practice Question (Domain 3: Security Architecture and Engineering)
A multinational firm plans a single global data lake for cost efficiency. Regional teams process citizen data under differing privacy regimes, and design approval is due next week. What should the security architect do FIRST? A. Validate jurisdictional data sovereignty requirements before design approval B. Segment the lake to enforce regional residency boundaries C. Apply tokenization to sensitive fields before global replication D. Escalate the cost-versus-compliance conflict to the risk committee (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
0 likes • Aug 20
A
1-10 of 13
Parvesh K
1
2 points to level up
@parvesh-k-8838
Cyber security,

Active 6h ago
Joined Oct 2, 2025
Powered by