Activity
Mon
Wed
Fri
Sun
Nov
Dec
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
Sep
Oct
What is this?
Less
More
19 contributions to CISSP Study Group
CISSP Practice Question (Domain 2: Asset Security)
A SaaS contract ends and the vendor confirms customer records were deleted from production. Retention for those records has expired, and legal wants proof before signing the closure letter. What should the data owner require FIRST? A. Certificate of destruction covering backups and replicas B. Cryptographic erasure of the vendor's data encryption keys C. Signed attestation from the vendor's compliance officer D. Independent audit of the vendor's deletion procedures (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
0 likes • 26d
A
CISSP Practice Question (Domain 4: Communication and Network Security)
A hospital wants new internet-connected infusion pumps on the existing user VLAN to hit a ward opening date. The pumps cannot run endpoint agents and are patched quarterly. What should the network security manager require FIRST? A. Dedicated network zone for the pumps with controlled ingress B. Risk assessment of the pumps against clinical network requirements C. Network intrusion detection covering the user VLAN D. Vendor commitment to a faster patch cadence (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 26d
B - FIRST - Assess
CISSP Practice Question (Domain 7: Security Operations)
Ransomware hits a file server mid product launch, and the sales VP wants last night's backup restored within the hour. Nobody has invoked the incident response plan. What should the security operations manager do FIRST? A. Restore the server from backup to protect the launch B. Isolate the server and preserve volatile evidence C. Declare the incident and activate the response plan D. Scan neighboring hosts to gauge how far it spread (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 26d
C. Key hint - FIRST - Have to declare the incident to kick off remediation
CISSP Practice Question (Domain 1: Security and Risk Management)
A lender will embed a third party AI model in loan approvals, live in 90 days by board order. Nobody has set a risk appetite for AI decisions or named an owner. What should the CISO do FIRST? A. Draft an AI acceptable use policy for lenders B. Have the board set risk appetite and name an owner C. Commission due diligence on the model vendor D. Require bias and explainability testing before launch (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 26d
B - Governance - Board has to set risk appetite and set an owner (Responsible)
CISSP Practice Question (Domain 5: Identity and Access Management (IAM))
An acquisition closes in 30 days, and the deal team wants the acquired staff in shared systems on day one. How that firm grants, reviews, and removes access is unknown. What should the CISO do FIRST? A. Federate both identity providers for day one sign-in B. Assess the acquired firm's identity governance and access lifecycle C. Issue temporary parent directory accounts to acquired staff D. Require multifactor authentication on acquired accounts before connecting (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 26d
B. - Assess should be the FIRST before action
1-10 of 19
Ray Allen
2
9 points to level up
@ray-allen-3565
Starting my CISSIP Journey

Active 3h ago
Joined Dec 8, 2025
Powered by