Activity
Mon
Wed
Fri
Sun
Nov
Dec
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
Sep
Oct
What is this?
Less
More
31 contributions to CISSP Study Group
CISSP Practice Question (Domain 4: Communication and Network Security)
A hospital wing opens in 45 days. Clinical devices from six vendors will join the flat network and each vendor wants remote support access. No network requirements exist for them. What should the security manager do FIRST? A. Isolate every device on its own VLAN B. Set segmentation and remote access requirements by device risk C. Route all vendor support through one monitored jump host D. Scan each device for vulnerabilities before go-live (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 2d
B - based on the device risk, set segmentation and remote access
CISSP Practice Question (Domain 2: Asset Security)
A leasing firm wants 400 laptops back in two weeks. IT plans a quick format before shipping. No sanitization standard exists and the laptops held regulated client data. What should the security manager do FIRST? A. Quick format each laptop and keep signed return manifests B. Define sanitization requirements from the data classification held C. Physically destroy every drive before the laptops ship D. Negotiate an extension to allow full disk wiping (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 6d
B- need to define sanitisation requirements based on the data classification so that relevant sanitisation methods can be used to clear, wipe or purge the client data.
CISSP Practice Question (Domain 3: Security Architecture and Engineering)
An insurer wants an AI assistant to answer questions from policyholder records. To meet a quarter-end demo, the architect puts it inside the application trust zone. No threat model exists for the new flows. What should the security architect do FIRST? A. Segment the assistant into its own zone B. Threat model the new flows and set trust boundaries C. Encrypt every record the assistant can read D. Limit the assistant to read-only access (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 7d
B- threat modelling is the first step for new flows
🎉 CISSP Exam Passed! (First Attempt at 100 Questions!)
Hi everyone, I am thrilled to share that I officially cleared the CISSP exam yesterday at the 100-question mark on my first attempt! To give a bit of background, I started my CISSP preparation right after passing my CCSP 6 weeks ago. Here is what my preparation looked like: - Core Study Material: Studied the Official Study Guide (OSG) 10th Edition cover-to-cover, using AI tools (Gemini and Claude) to deep-dive into areas where the OSG lacked a bit of depth and to effectively cover that delta. - Visual Learning: Utilized Destination Certification's mind map videos to solidify concepts. - Practice Assessments: Leveraged the Destination Certification app practice tests, alongside the Skool "CISSP, CCSP & CISM Practice Exams | Expert-Calibrated Questions — cissp.app" practice and full-length tests, to benchmark my readiness. - Final Refresher: Used The CISSP Field Manual by Clearance to Wealth as a fantastic quick refresher right before the exam. - Collaborative Learning: Participated actively in classes alongside a diverse group of talented professionals. The interactive sessions fostered a healthy and professional environment where we could analyze questions from multiple angles. Hearing different viewpoints on scenario-based reasoning provided valuable insights into why a choice is correct or incorrect, significantly sharpening my exam mindset. I want to extend a huge thank you to everyone who made this journey a success: - Vincent: For initializing and running this amazing CISSP Skool community. - The Facilitators: For exposing us to a rich variety of challenging questions through the classes. - My Study Group: A heartfelt thank you to Ed, Ricardo, Enrico, Victor, Matthew, Pavithra, Emma, Aidah, Vishal, David and many more for your incredible support and camaraderie. Thank you all again. On to the next chapter!
1 like • 8d
Thank you @Eswari K . Beyond the OSG and Destination Certification materials, my experience as a security solutions architect working with a wide variety of clients was key. Designing complex environments for diverse needs allowed me to consider security across all CCSP domains. It's all about applying that real-world breadth to tackle the exam questions
CISSP Practice Question (Domain 6: Security Assessment and Testing)
A fintech board wants a bug bounty live before a funding round in 30 days. No vulnerability disclosure policy exists and internet-facing assets were never inventoried. What should the security manager do FIRST? A. Launch a private bounty limited to the main web application B. Run an authenticated vulnerability scan of all production systems C. Define the disclosure policy and scope the assets in play D. Hire an external firm to penetration test before launch (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 8d
C - scope definition should be done first
1-10 of 31
Chiru Adapa
3
27 points to level up
@chiru-adapa-1499
Senior Security Solutions Architect

Active 2h ago
Joined Aug 8, 2026
Powered by