Activity
Mon
Wed
Fri
Sun
Nov
Dec
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
Sep
What is this?
Less
More
12 contributions to CISSP Study Group
Sample Question I came across
A pharmaceutical company must share confidential research reports with an external partner. Management requires that the company can revoke access to the reports at any time, even after the files have been downloaded to the partner's systems, and that printing be blocked. Which control BEST meets these requirements?
Poll
3 members have voted
CISSP Practice Question (Domain 1: Security and Risk Management)
A cloud outage cost a retailer a day of online sales. The CFO has funded a second region and wants migration started this quarter. No business impact analysis exists. What should the security manager do FIRST? A. Design the second region with the cloud team B. Conduct a business impact analysis to set recovery targets C. Negotiate a stronger uptime commitment with the provider D. Buy business interruption insurance for cloud outages (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
0 likes • 2d
B: Conducting BIA is rightful thing to do, Identify and priortize the critical assets/services are key to make decision what to migrate.
🎉 CISSP Exam Passed! (First Attempt at 100 Questions!)
Hi everyone, I am thrilled to share that I officially cleared the CISSP exam yesterday at the 100-question mark on my first attempt! To give a bit of background, I started my CISSP preparation right after passing my CCSP 6 weeks ago. Here is what my preparation looked like: - Core Study Material: Studied the Official Study Guide (OSG) 10th Edition cover-to-cover, using AI tools (Gemini and Claude) to deep-dive into areas where the OSG lacked a bit of depth and to effectively cover that delta. - Visual Learning: Utilized Destination Certification's mind map videos to solidify concepts. - Practice Assessments: Leveraged the Destination Certification app practice tests, alongside the Skool "CISSP, CCSP & CISM Practice Exams | Expert-Calibrated Questions — cissp.app" practice and full-length tests, to benchmark my readiness. - Final Refresher: Used The CISSP Field Manual by Clearance to Wealth as a fantastic quick refresher right before the exam. - Collaborative Learning: Participated actively in classes alongside a diverse group of talented professionals. The interactive sessions fostered a healthy and professional environment where we could analyze questions from multiple angles. Hearing different viewpoints on scenario-based reasoning provided valuable insights into why a choice is correct or incorrect, significantly sharpening my exam mindset. I want to extend a huge thank you to everyone who made this journey a success: - Vincent: For initializing and running this amazing CISSP Skool community. - The Facilitators: For exposing us to a rich variety of challenging questions through the classes. - My Study Group: A heartfelt thank you to Ed, Ricardo, Enrico, Victor, Matthew, Pavithra, Emma, Aidah, Vishal, David and many more for your incredible support and camaraderie. Thank you all again. On to the next chapter!
1 like • 2d
@Chiru Adapa That is an amazing achievement 👏, following right on the heels of your CCSP! What an inspiring journey. 🙌 Your hard work and dedication in reaching this CISSP milestone truly deserve recognition. Wishing you continued success in your future certifications 🏆 and may you keep inspiring others and giving back to the community 🙂
CISSP Practice Question (Domain 7: Security Operations)
HR suspects a departing engineer copied source code to a personal drive. The engineer leaves Friday and the CTO wants IT to search the laptop today. What should the security operations manager do FIRST? A. Have IT review the laptop's file history for proof B. Disable the engineer's accounts and seize the laptop now C. Preserve the device and logs under chain of custody with legal D. Report the suspected theft to law enforcement (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 4d
C: Preserve the device so as to IT team will validate and cofirm (option A) because HR only suspected not confirmed it.
CISSP Practice Question (Domain 8: Software Development Security)
A sales team built a customer portal on a low-code platform without security involvement and wants it live Monday. It holds customer contracts and nobody owns its code or data. What should the security manager do FIRST? A. Schedule a penetration test before Monday B. Move the portal into the corporate development pipeline C. Assess the portal's data, risk and ownership before release D. Require secure coding training for the sales team (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
2 likes • 5d
C: As the data involves customer contracts and risk of confidentiality, As a Security Manager, this needs to be assessed the data types and have ownership assigned so it can be properly classified and required controls applied.
1-10 of 12
Vishal Kumar
2
8 points to level up
@vishal-kumar-2187
Cyber Security Professional

Active 8h ago
Joined Sep 14, 2026
Chicago
Powered by