Activity
Mon
Wed
Fri
Sun
Nov
Dec
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
Sep
Oct
What is this?
Less
More
17 contributions to CISSP Study Group
CISSP Practice Question (Domain 4: Communication and Network Security)
A hospital wing opens in 45 days. Clinical devices from six vendors will join the flat network and each vendor wants remote support access. No network requirements exist for them. What should the security manager do FIRST? A. Isolate every device on its own VLAN B. Set segmentation and remote access requirements by device risk C. Route all vendor support through one monitored jump host D. Scan each device for vulnerabilities before go-live (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
0 likes • 16h
B should the answer.
CISSP Practice Question (Domain 2: Asset Security)
A leasing firm wants 400 laptops back in two weeks. IT plans a quick format before shipping. No sanitization standard exists and the laptops held regulated client data. What should the security manager do FIRST? A. Quick format each laptop and keep signed return manifests B. Define sanitization requirements from the data classification held C. Physically destroy every drive before the laptops ship D. Negotiate an extension to allow full disk wiping (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 1d
My choice would be D --
CISSP Practice Question (Domain 3: Security Architecture and Engineering)
An insurer wants an AI assistant to answer questions from policyholder records. To meet a quarter-end demo, the architect puts it inside the application trust zone. No threat model exists for the new flows. What should the security architect do FIRST? A. Segment the assistant into its own zone B. Threat model the new flows and set trust boundaries C. Encrypt every record the assistant can read D. Limit the assistant to read-only access (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 4d
Believe B would my first choice...
CISSP Practice Question (Domain 6: Security Assessment and Testing)
A fintech board wants a bug bounty live before a funding round in 30 days. No vulnerability disclosure policy exists and internet-facing assets were never inventoried. What should the security manager do FIRST? A. Launch a private bounty limited to the main web application B. Run an authenticated vulnerability scan of all production systems C. Define the disclosure policy and scope the assets in play D. Hire an external firm to penetration test before launch (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 6d
C - should be done first
CISSP Practice Question (Domain 5: Identity and Access Management (IAM))
Attackers twice reset executive passwords by phoning the outsourced help desk. The CIO wants phishing-resistant MFA purchased this month. No standard defines how callers prove identity. What should the security manager do FIRST? A. Deploy phishing-resistant MFA for all executives B. Require manager callback approval for every reset C. Retrain help desk staff on social engineering D. Assess the reset process and define identity proofing requirements (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
0 likes • 8d
D
1-10 of 17
Bill T.
2
15 points to level up
@bill-t-1088
Over 35+ year in Information Technology. Now working toward getting my CISSP. ... Love skiing and hiking/walking around...

Active 13h ago
Joined Sep 15, 2026
Powered by