Activity
Mon
Wed
Fri
Sun
Sep
Oct
Nov
Dec
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
What is this?
Less
More
CISSP Study Group

2.3k members • Free

23 contributions to CISSP Study Group
CISSP Practice Question (Domain 1: Security and Risk Management)
A security consultant discovers her client is knowingly misrepresenting remediation status to its customers after an assessment she performed. The client cites confidentiality clauses in her contract and directs her to stay silent. Under the ISC2 Code of Ethics, what is her PRIMARY obligation? A. Honor the confidentiality agreement with the client B. Act honorably and protect the public trust C. Report the misrepresentation to affected customers D. Withdraw from the engagement and document concerns (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
0 likes • 1d
B - So even though the client cites confidentiality clauses, those cannot override your duty to act honorably and prevent harm to the public.
CISSP Practice Question (Domain 6: Security Assessment and Testing)
Leadership orders a penetration test of a customer-facing platform after a competitor's breach. Half the platform runs on a SaaS provider's infrastructure. The testing firm is contracted and ready to begin. What should the security manager confirm FIRST? A. Authorization and scope boundaries from the SaaS provider B. Rules of engagement defining escalation and stop conditions C. Backups of production data before intrusive testing begins D. Cyber liability coverage extends to testing activities (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
0 likes • 5d
A is correct: Penetration testing without explicit, documented authorization from the infrastructure owner (in this case, the SaaS provider) can constitute unauthorized access under laws like the Computer Fraud and Abuse Act (CFAA), regardless of whether your company is paying for the service. SaaS platforms typically host multi-tenant environments; unauthorized testing risks disrupting other tenants or violating cloud Terms of Service (ToS) / Service Level Agreements (SLAs).
The CISSP Risk‑Based Mindset – A Prerequisite for the Exam
Adopting the CISSP mindset requires embracing the perspective of a strategic risk practitioner whose primary responsibility is to evaluate, communicate, and manage organizational risk. Rather than approaching security as a collection of technical tasks, the CISSP mindset centers on understanding how every decision influences the organization’s overall risk posture. This perspective positions the security leader as a trusted advisor who guides executives in making informed, risk‑aligned choices that support mission objectives. A risk‑based mindset begins with recognizing that security decisions must be evaluated through the dual lenses of business impact and risk tolerance. Human life and safety remain paramount, followed by the preservation of business continuity, critical assets, and organizational reputation. The goal is not to eliminate risk entirely—an unrealistic and cost‑prohibitive endeavor—but to reduce risk to levels that leadership deems acceptable. Achieving this requires the thoughtful integration of administrative, physical, and technical controls that are both effective and economically justified. This mindset also demands a holistic understanding of the organization’s operations, dependencies, and vulnerabilities. Security policies and controls must be proactive, grounded in risk assessments, and aligned with legal, regulatory, and contractual obligations. A CISSP practitioner recognizes that security is not an obstacle but a business enabler, ensuring that risk‑informed decisions support strategic objectives rather than hinder them. Ultimately, thinking like a CISSP means taking ownership of governance responsibilities, anticipating how security decisions ripple across the enterprise, and consistently advocating for defense‑in‑depth as a means of managing uncertainty. It reflects a disciplined commitment to evaluating threats, vulnerabilities, and impacts in a structured manner, ensuring that security practices remain aligned with organizational risk appetite throughout the entire enterprise lifecycle.
CISSP Practice Question (Domain 1: Security and Risk Management)
A new CISO inherits a mature control environment but finds no documented risk assessments supporting it. Leadership considers the controls sufficient and resists spending on analysis. What should the CISO do FIRST? A. Conduct a risk assessment to align controls with business risk B. Benchmark the control set against an industry framework C. Present leadership a business case for the assessment budget D. Continue operations while documenting controls retroactively (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 8d
The correct FIRST action is A — Conduct a risk assessment to align controls with business risk.The CISO has inherited a mature control environment with no documented risk basis. That means: - Controls exist - But no one knows why they exist - Or whether they match actual business risk - Or whether they are excessive, insufficient, or misaligned In CISSP logic, controls must always map to risk, and risk must always map to business impact. So, the FIRST step is to perform a risk assessment, even if leadership resists. You cannot benchmark, justify budget, or document controls until you know what risks they are supposed to address. This is foundational governance.
🧠The CISSP Mindset - Pre-requisite for the exam
The CISSP mindset is fundamentally that of a strategic risk manager and trusted advisor, not a hands-on technical firefighter. It requires evaluating every security decision through the dual lenses of business alignment and risk management—prioritizing human life and safety above all else, followed closely by business continuity and asset protection. Rather than aiming for absolute, cost-prohibitive security, a CISSP practitioner seeks to reduce risk to an acceptable level through balanced, cost-effective administrative, physical, and technical controls. This mindset demands a holistic view of the organization, ensuring security policies are proactive rather than reactive, compliance and legal requirements are met, and security functions as an enabler of business goals rather than a bottleneck. Ultimately, thinking like a CISSP means taking accountability for governance, understanding the broader operational impact of security decisions, and constantly advocating for defense-in-depth across the entire enterprise lifecycle.
1 like • 16d
@Ed Morawski you're correct, technical questions are bait. The real test is whether you return to manager mode immediately afterward.
0 likes • 8d
@Karizma Hanshaw CISSP isn’t measuring how technical you are — you already have that down. It’s measuring whether you can think like the person who owns the risk, not the person who fixes the system.
1-10 of 23
James Bonner
3
13 points to level up
@james-bonner-1546
My name is James D. Bonner, and I am a Senior Systems Analyst III with experience spanning cybersecurity, operations, and software testing. Hello all.

Active 1d ago
Joined Apr 14, 2026
Powered by