Activity
Mon
Wed
Fri
Sun
Sep
Oct
Nov
Dec
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
What is this?
Less
More
Poster Print on Demand

10.7k members • Free

CISSP Study Group

2.3k members • Free

30 contributions to CISSP Study Group
CISSP Practice Question (Domain 4: Communication and Network Security)
A business partner requires an always-on site-to-site tunnel into a shared application segment. Their security posture is unknown, and the contract is already signed. What should the network security manager do FIRST? A. Terminate the tunnel in a dedicated screened segment B. Assess the partner's security posture against connection requirements C. Route all partner traffic through the inspection stack D. Enforce mutual authentication and approved cipher policy (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 14d
Yep you have to assess before implementing controls - so B
CISSP Practice Question (Domain 1: Security and Risk Management)
A business unit deploys an AI agent that autonomously negotiates vendor contracts within predefined spend limits. The agent improves efficiency but occasionally commits the company to unfavorable terms. Executives want to continue using it. What is the MOST appropriate action for the security leader? A. Disable autonomous execution and require human approval for commitments B. Update the organization’s risk register to reflect agent decision authority C. Require explainability reports for every AI-driven contract decision D. Transfer contractual risk to vendors through revised legal language Come back for the answer tomorrow, or study more now!
1 like • Jan 27
B - the CISO is not able to override a business decision made by the C suite, so should document the risk decision made. IF the CISO disables the autonomous feature then the whole setup is cancelled for every commercial decision. Not a good look.
CISSP Practice Question (Domain 5: Identity and Access Management)
After a merger, two companies federate identity systems to allow cross access to shared applications. An incident later reveals one company’s disabled accounts remained active in the partner environment. Both sides claim the other owns deprovisioning. What is the MOST appropriate control to establish FIRST? A. Enforce shorter session timeouts across federated applications B. Implement continuous access monitoring with anomaly detection C. Define authoritative identity ownership and revocation responsibility D. Require periodic manual access recertification for all shared users Come back for the answer tomorrow, or study more now!
1 like • Jan 5
Great question - one I haven't seen in other test banks. Thanks for posting
🚨 Free Masterclass Access for Study Group Members (Again!) 🚨
If you missed it last time, May Brooks is graciously welcoming CISSP Study Group members back into her CISSP Masterclass! Completely free! This live session will be held on: Sunday, December 7th — 7:00 PM to 9:00 PM *Dubai time* (please check your time zone conversion) May is one of the most respected CISSP instructors worldwide. She’s an ISC2 Board Member, co-author of the Official CISSP Study Guide, a TEDx speaker, bestselling author (Scams, Hacking, and Cybersecurity). Having her open her masterclass to our group speaks volumes about the reputation you all have built here. Here’s what this means for you: 📚 Free Access to Mae’s Masterclass – If you’re serious about passing the CISSP, this is one of the most valuable sessions you can attend 💡 Ideal for All Levels – Whether you’re early in your studies or testing soon, Mae’s perspective will give you insights you won’t get anywhere else. 🤝 Community Recognition – May specifically wanted our study group to join because she believes in what you’re building here. See you there! Link & Access Info
Poll
41 members have voted
🚨 Free Masterclass Access for Study Group Members (Again!) 🚨
0 likes • Dec '25
When I realized it was Dubai time then it was out of my timeframe - ie 3am. On the login screen I tried to ask a question (which it seemed was a feature) and it tripped a server error. Would be great if there was a recording. TIA
Practice Question
The IT department is updating the budget for the following year, and they want to include enough money for a hardware refresh for some older systems. Unfortunately, there is a limited budget. Which of the following should be a top priority? A) Systems with an end-of-life (EOL) date that occurs in the following year B) Systems used for data loss prevention C) Systems used to process sensitive data D) Systems with an end-of-support (EOS) date that occurs in the following year
2 likes • May '25
D
1-10 of 30
Tro Vis
3
40 points to level up
@tro-vis-8559
Project Mgr for NIST/Essential 8 deployments

Active 8h ago
Joined May 8, 2024
Powered by