Activity
Mon
Wed
Fri
Sun
Sep
Oct
Nov
Dec
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
What is this?
Less
More
CISSP Study Group

2.3k members • Free

10 contributions to CISSP Study Group
CISSP Practice Question (Domain 6: Security Assessment and Testing)
Leadership orders a penetration test of a customer-facing platform after a competitor's breach. Half the platform runs on a SaaS provider's infrastructure. The testing firm is contracted and ready to begin. What should the security manager confirm FIRST? A. Authorization and scope boundaries from the SaaS provider B. Rules of engagement defining escalation and stop conditions C. Backups of production data before intrusive testing begins D. Cyber liability coverage extends to testing activities (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
0 likes • 8h
A
CISSP Practice Question (Domain 1: Security and Risk Management)
During business continuity planning, the IT director assigns recovery time objectives based on system complexity and restoration effort. Several business units later dispute the recovery priorities. Who should the BCP coordinator ensure determines the RTOs? A. The IT director, who understands restoration capability B. Business process owners, based on impact analysis C. Executive management, to resolve the dispute with authority D. The BCP coordinator, to maintain plan consistency (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
0 likes • 2d
B
Support Community
This platform has provided a great support community for me … Thanks to all of those that have been supportive and shared their time with me …
1
0
CISSP Practice Question (Domain 7: Security Operations)
During active ransomware containment, the operations team wants to immediately wipe and reimage infected servers to restore a critical service. Cyber insurance and law enforcement notifications are pending. What should the incident commander do FIRST? A. Preserve forensic images of affected systems before restoration B. Restore the service from the most recent clean backup C. Notify the cyber insurer to avoid violating policy conditions D. Isolate remaining unaffected segments to prevent spread (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
0 likes • 10d
A
CISSP Practice Question (Domain 6: Security Assessment and Testing - AI Exam Guidance)
Your organization's fraud detection ML model passes all traditional software vulnerability scans. However, a red team discovers they can subtly alter transaction inputs to cause the model to misclassify fraudulent activity as legitimate. What testing gap does this BEST illustrate? A. The vulnerability scans lacked authenticated scanning credentials B. Static application security testing was not integrated into the CI/CD pipeline C. The assessment program did not include adversarial robustness testing of the model D. The red team should have coordinated findings with the vulnerability management team first Come back for the answer tomorrow, or study more now!
1 like • Apr 13
C
1-10 of 10
David Terrazas
2
13 points to level up
@david-terrazas-8761
Cyber Security Leader

Active 3h ago
Joined Mar 29, 2026
Powered by