Activity
Mon
Wed
Fri
Sun
Nov
Dec
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
Sep
What is this?
Less
More

Owned by Vincent

Share resources, get advice, and connect with peers studying cybersecurity. Join our CISSP study group and connect with fellow professionals today!

Skoolers
154.3k
Free
846 contributions to CISSP Study Group
CISSP Practice Question (Domain 5: Identity and Access Management (IAM))
Attackers twice reset executive passwords by phoning the outsourced help desk. The CIO wants phishing-resistant MFA purchased this month. No standard defines how callers prove identity. What should the security manager do FIRST? A. Deploy phishing-resistant MFA for all executives B. Require manager callback approval for every reset C. Retrain help desk staff on social engineering D. Assess the reset process and define identity proofing requirements (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
CISSP Practice Question (Domain 1: Security and Risk Management)
A cloud outage cost a retailer a day of online sales. The CFO has funded a second region and wants migration started this quarter. No business impact analysis exists. What should the security manager do FIRST? A. Design the second region with the cloud team B. Conduct a business impact analysis to set recovery targets C. Negotiate a stronger uptime commitment with the provider D. Buy business interruption insurance for cloud outages (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 11h
@Vishal Kumar Correct Answer: B. Conduct a business impact analysis to set recovery targets Explanation (CISSP logic): The clues are "a day of online sales", "funded a second region" and "no business impact analysis exists". Business continuity sits in Security and Risk Management because the business, not the cloud team, decides how much downtime and data loss each process can tolerate. The BIA turns that tolerance into recovery time and recovery point objectives, and every resilience spend, from a second region to an insurance premium, is sized against those numbers. Assess before you act: a funded project without targets is a guess with a budget. Breakdown: A. Designing the second region is the strong distractor because the money is approved, the CFO is waiting and a multi-region build may well be the right answer. But an architecture chosen before recovery targets exist can protect the wrong systems, over-engineer the cheap ones and still miss the process that actually cost the day of sales. B. ✅ Correct. The BIA identifies the critical processes, the cost of each hour they are down and the recovery time and point objectives the business will fund. With those in hand the second region becomes a justified control with a measurable target instead of a reaction to one bad day. C. A stronger uptime commitment moves some liability onto the provider and belongs in the contract review. It does not restore a single sale during the next outage, and without a BIA nobody knows what commitment to ask for or whether the credits would come close to the loss. D. Business interruption insurance is legitimate risk transfer and a finance decision worth making. Insurers price it from the very impact figures the BIA produces, and it pays out after the outage rather than shortening it, so it complements the analysis and cannot replace it. Think like a manager: Recovery targets come from the business impact, not the budget line. Know what an hour costs before you buy the hour back.
CISSP Practice Question (Domain 7: Security Operations)
HR suspects a departing engineer copied source code to a personal drive. The engineer leaves Friday and the CTO wants IT to search the laptop today. What should the security operations manager do FIRST? A. Have IT review the laptop's file history for proof B. Disable the engineer's accounts and seize the laptop now C. Preserve the device and logs under chain of custody with legal D. Report the suspected theft to law enforcement (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 4d
@Kayode Alabi Correct Answer: C. Preserve the device and logs under chain of custody with legal Explanation (CISSP logic): The clues are "HR suspects", "source code", "leaves Friday" and "search the laptop today". Suspected theft of intellectual property by an employee is a legal matter before it is a technical one, and anything the organization might later put in front of a court, a regulator or an arbitrator has to be collected in a way that survives challenge. Security Operations owns evidence handling: preserve first, under chain of custody, with legal and HR setting the boundaries of the investigation. Assess before you act: a search that starts before preservation can destroy the very proof it is looking for. Breakdown: A. Reviewing the file history sounds like the fastest way to confirm or clear the suspicion, and the CTO will get an answer today. But every file opened, every timestamp touched and every login by IT changes the evidence, and a finding produced without chain of custody is a story, not proof, that the engineer's lawyer will take apart. B. The strong distractor. Disabling accounts and taking the laptop feels like decisive containment and it does stop further copying. But the engineer is still employed, and revoking access and seizing property without HR and legal sign-off invites a wrongful treatment claim, tips off the suspect before evidence is secured and still leaves the device unpreserved in the hands of whoever grabbed it. C. ✅ Correct. Preserving the laptop, its image and the relevant logs under documented chain of custody keeps every option open: an internal HR outcome, a civil claim or a criminal referral. Legal decides what may be examined and by whom, HR handles the employee, and the forensic review that follows is admissible because it started right. D. Law enforcement may well be involved before this is over, and for some jurisdictions and contracts that referral is required. It is a decision for legal counsel with preserved evidence in hand, not the first move on a suspicion, and reporting before preservation hands investigators a case with no exhibits.
CISSP Practice Question (Domain 8: Software Development Security)
A sales team built a customer portal on a low-code platform without security involvement and wants it live Monday. It holds customer contracts and nobody owns its code or data. What should the security manager do FIRST? A. Schedule a penetration test before Monday B. Move the portal into the corporate development pipeline C. Assess the portal's data, risk and ownership before release D. Require secure coding training for the sales team (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
2 likes • 5d
@Vishal Kumar Correct Answer: C. Assess the portal's data, risk and ownership before release Explanation (CISSP logic): The clues are "without security involvement", "holds customer contracts" and "nobody owns its code or data". Low-code does not mean low risk; a portal that exposes contracts to customers is production software and belongs inside the secure development lifecycle whoever built it. Software Development Security starts with knowing what the application handles, what it must protect and who is accountable for it, because every later control, from testing to training, is sized from those answers. Assess before you act: classify the data, rate the exposure and name an owner, then decide what Monday needs. Breakdown: A. A penetration test before launch is a sensible gate and the portal will probably need one. But testing an application nobody has scoped or owns produces findings with no requirements to judge them against and no one obliged to fix them, and a clean result on Friday says nothing about the data the portal should never have held. B. Bringing the portal into the corporate pipeline is the right long-term home, with version control, reviews and release gates. It is a design and process decision made before anyone has established whether the portal is acceptable at all, and it can stall a business win on tooling while the real question, what data it exposes and who answers for it, stays open. C. ✅ Correct. A quick assessment tells the manager what the contracts contain, which customers and obligations they touch, how the platform stores and shares them and who the business owner is. With that in hand the manager can set the conditions for Monday, defer the launch on evidence, or accept the risk with a named owner, and the testing and pipeline work follow with a purpose. D. Secure coding training addresses the root cause of citizen development going unreviewed, and a program should follow. It is a preventive control for the next portal, not a decision about this one, and training does not change what is going live on Monday or who owns it.
CISSP Practice Question (Domain 4: Communication and Network Security)
A key customer wants a site-to-site link into the plant network in 30 days so its ordering system can read live inventory. The contract is signed and the customer's security posture is unknown. What should the security manager do FIRST? A. Build the tunnel, firewall rules limited to inventory B. Assess the risk and define the connection's requirements C. Require the customer's security assessment report first D. Publish inventory through an isolated extranet segment (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
0 likes • 6d
@Shemaiah E Correct Answer: B. Assess the risk and define the connection's requirements Explanation (CISSP logic): The clues are "the contract is signed", "30 days", "into the plant network" and "security posture is unknown". A third party connection is a trust boundary crossing, and the exposure it creates belongs to your organization whatever the contract says about the customer. Communication and Network Security starts by defining what the link must carry, what it must never reach and what assurance the other side must show before any tunnel, firewall rule or segment is designed. Assess before you act: scope the risk, then build to the requirements it produces. Breakdown: A. Building the tunnel with rules limited to the inventory system is a reasonable end state and keeps the 30 day promise. But it commits to a design before anyone has decided whether a permanent link is acceptable, which flows are actually needed or what the plant network can tolerate, and a firewall rule set is only as good as the requirement behind it. B. ✅ Correct. A risk assessment of the connection identifies the assets on the plant side, the data the customer really needs, the exposure a compromised partner would create and the controls, contractual and technical, the link must meet. Every other option is sized from that answer, and the deadline is met with a design you can defend. C. The strong distractor. Asking for the customer's security assessment is due diligence and it will be one of the requirements. But it is a single input demanded before you know what assurance level the link needs, and a clean report does not tell you what to expose or how to contain a partner whose posture changes after the ink dries. D. An isolated extranet segment is the architect's answer and it may be exactly where the design lands. But choosing the architecture before the assessment is design before requirements; you do not yet know whether the customer needs a network link at all, or whether an interface with no network adjacency serves them better.
1-10 of 846
Vincent Primiani
7
4,751 points to level up
Cybersecurity. The Study Group Guy.

Active 3h ago
Joined Apr 29, 2024
New York, NY
Powered by