Activity
Mon
Wed
Fri
Sun
Sep
Oct
Nov
Dec
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
What is this?
Less
More

Owned by Vincent

CISSP Study Group

2.3k members • Free

Share resources, get advice, and connect with peers studying cybersecurity. Join our CISSP study group and connect with fellow professionals today!

Skoolers

162.5k members • Free

818 contributions to CISSP Study Group
CISSP Practice Question (Domain 1: Security and Risk Management)
A security consultant discovers her client is knowingly misrepresenting remediation status to its customers after an assessment she performed. The client cites confidentiality clauses in her contract and directs her to stay silent. Under the ISC2 Code of Ethics, what is her PRIMARY obligation? A. Honor the confidentiality agreement with the client B. Act honorably and protect the public trust C. Report the misrepresentation to affected customers D. Withdraw from the engagement and document concerns (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
CISSP Practice Question (Domain 6: Security Assessment and Testing)
Leadership orders a penetration test of a customer-facing platform after a competitor's breach. Half the platform runs on a SaaS provider's infrastructure. The testing firm is contracted and ready to begin. What should the security manager confirm FIRST? A. Authorization and scope boundaries from the SaaS provider B. Rules of engagement defining escalation and stop conditions C. Backups of production data before intrusive testing begins D. Cyber liability coverage extends to testing activities (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
0 likes • 2d
@Kayode Alabi Correct Answer: A. Authorization and scope boundaries from the SaaS provider Explanation (CISSP logic): Half the target belongs to someone else. Penetration testing without the infrastructure owner's authorization is unauthorized access, no matter how legitimate your intent or how signed your contract with the testing firm. This is the legal-first trigger: third-party assets in scope mean third-party consent before anything else. Most cloud providers require explicit testing approval or restrict testing entirely, and their terms define what your testers may legally touch. Breakdown: A. ✅ Correct. Provider authorization establishes the legal boundary of the test. Without it, your contracted firm becomes an attacker with an invoice. B. The strong distractor, because rules of engagement are genuinely mandatory before testing starts. But ROE governs how you test what you're allowed to test. Authorization determines what you're allowed to test at all, and legality precedes procedure. C. Backups are prudent operational hygiene before intrusive testing, but they protect against damage from a test that isn't yet lawful to run. Right precaution, wrong step. D. Insurance coverage is worth confirming, but it's a financial backstop, not a permission. Coverage doesn't make unauthorized testing authorized; it just changes who pays for the fallout. Think like a manager: Your urgency doesn't extend your authority. In shared infrastructure, the scope of a test is set by every owner in it, not just the one paying for it.
CISSP Practice Question (Domain 1: Security and Risk Management)
During business continuity planning, the IT director assigns recovery time objectives based on system complexity and restoration effort. Several business units later dispute the recovery priorities. Who should the BCP coordinator ensure determines the RTOs? A. The IT director, who understands restoration capability B. Business process owners, based on impact analysis C. Executive management, to resolve the dispute with authority D. The BCP coordinator, to maintain plan consistency (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 4d
@Abdelaziz Aqel ✅ Correct Answer: B. Business process owners, based on impact analysis Explanation (CISSP logic): The dispute exists because the RTOs were derived from the wrong input. Recovery time objectives come out of the business impact analysis, which measures the cost of downtime to the business process, not the effort required to restore the system. Only the process owners can say what an hour of outage costs and how long the organization can survive without their function. IT then engineers to meet those targets, not the other way around. Breakdown: A. The IT director set RTOs by restoration effort, which inverts the model. That approach tells you what recovery is convenient, not what the business requires. Capability constrains the solution; it doesn't define the objective. B. ✅ Correct. Process owners set RTOs through the BIA because they own the impact. Requirements flow from the business to IT. C. The strong distractor because escalation feels managerial. But executive management resolves conflicts and approves risk decisions; they don't perform the impact analysis. Escalating skips the actual fix, which is running the BIA with the right people. D. The coordinator facilitates the process and keeps it consistent, but facilitation is not ownership. A coordinator who sets RTOs has the same legitimacy problem as the IT director. Think like a manager: The business defines what must survive; IT defines how. When recovery priorities come from restoration effort instead of business impact, you've let the tool set the requirement.
The CISSP Risk‑Based Mindset – A Prerequisite for the Exam
Adopting the CISSP mindset requires embracing the perspective of a strategic risk practitioner whose primary responsibility is to evaluate, communicate, and manage organizational risk. Rather than approaching security as a collection of technical tasks, the CISSP mindset centers on understanding how every decision influences the organization’s overall risk posture. This perspective positions the security leader as a trusted advisor who guides executives in making informed, risk‑aligned choices that support mission objectives. A risk‑based mindset begins with recognizing that security decisions must be evaluated through the dual lenses of business impact and risk tolerance. Human life and safety remain paramount, followed by the preservation of business continuity, critical assets, and organizational reputation. The goal is not to eliminate risk entirely—an unrealistic and cost‑prohibitive endeavor—but to reduce risk to levels that leadership deems acceptable. Achieving this requires the thoughtful integration of administrative, physical, and technical controls that are both effective and economically justified. This mindset also demands a holistic understanding of the organization’s operations, dependencies, and vulnerabilities. Security policies and controls must be proactive, grounded in risk assessments, and aligned with legal, regulatory, and contractual obligations. A CISSP practitioner recognizes that security is not an obstacle but a business enabler, ensuring that risk‑informed decisions support strategic objectives rather than hinder them. Ultimately, thinking like a CISSP means taking ownership of governance responsibilities, anticipating how security decisions ripple across the enterprise, and consistently advocating for defense‑in‑depth as a means of managing uncertainty. It reflects a disciplined commitment to evaluating threats, vulnerabilities, and impacts in a structured manner, ensuring that security practices remain aligned with organizational risk appetite throughout the entire enterprise lifecycle.
2 likes • 4d
you said it! "This mindset also demands a holistic understanding of the organization’s operations, dependencies, and vulnerabilities."
CISSP Practice Question (Domain 1: Security and Risk Management)
A new CISO inherits a mature control environment but finds no documented risk assessments supporting it. Leadership considers the controls sufficient and resists spending on analysis. What should the CISO do FIRST? A. Conduct a risk assessment to align controls with business risk B. Benchmark the control set against an industry framework C. Present leadership a business case for the assessment budget D. Continue operations while documenting controls retroactively (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 6d
@Aidah Nakyejwe Correct Answer: C. Present leadership a business case for the assessment budget Explanation (CISSP logic): This question flips the usual pattern on purpose. "Assess first" is the right instinct, but the scenario plants a constraint: leadership resists funding the analysis. Every security program rests on senior management support, and a CISO cannot execute an assessment leadership hasn't authorized or funded. When the blocker is management buy-in, obtaining that buy-in is Step 1. The business case translates security need into business language, which is the CISO's core job. Breakdown: A. The strong distractor, because it's our own mantra used against us. Assessment is the right destination, but conducting one over leadership's objection means running an unfunded, unsanctioned program. Authority precedes activity. B. Benchmarking against a framework proves conformity, not risk alignment. It's also the tempting shortcut for a resistant leadership team: "we match the framework" is compliance logic, and compliance is a snapshot, not a risk decision. C. ✅ Correct. Secure sponsorship and budget first. The business case gives leadership the information to fund the assessment, making everything downstream legitimate. D. Retroactive documentation is accepting the status quo and papering over it. Controls without risk linkage may be over-spent, under-scoped, or pointed at threats that no longer exist, and now that gap has your signature on it. Think like a manager: The CISO doesn't overrule the business; the CISO informs it. When leadership is the obstacle, persuasion is the first control you deploy.
1-10 of 818
Vincent Primiani
7
4,851 points to level up
Cybersecurity. The Study Group Guy.

Active 37m ago
Joined Apr 29, 2024
New York, NY
Powered by