Activity
Mon
Wed
Fri
Sun
Sep
Oct
Nov
Dec
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
What is this?
Less
More
CISSP Study Group

2.3k members • Free

50 contributions to CISSP Study Group
CISSP Practice Question (Domain 1: Security and Risk Management)
During business continuity planning, the IT director assigns recovery time objectives based on system complexity and restoration effort. Several business units later dispute the recovery priorities. Who should the BCP coordinator ensure determines the RTOs? A. The IT director, who understands restoration capability B. Business process owners, based on impact analysis C. Executive management, to resolve the dispute with authority D. The BCP coordinator, to maintain plan consistency (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 1d
B - The business Process Owner identifies critical business needs and determines the impact of downtime on the business processes.
CISSP Practice Question (Domain 5: Identity and Access Management - AI Exam Guidance)
An autonomous AI agent needs credentials to query production databases and invoke internal APIs on a recurring schedule. The automation team proposes reusing a departed developer's service account to launch quickly. What should the IAM manager require FIRST? A. Rotate the credentials and transfer the account to the automation team B. Register the agent as a distinct non-human identity with a defined owner C. Scope the account's permissions to only the required datasets D. Enable enhanced logging on all agent-initiated transactions (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 8d
B - The first action would be to provision the agent's account by modifying a departed employee service account and assigning appropriate access.
CISSP Practice Question (Domain 7: Security Operations)
During active ransomware containment, the operations team wants to immediately wipe and reimage infected servers to restore a critical service. Cyber insurance and law enforcement notifications are pending. What should the incident commander do FIRST? A. Preserve forensic images of affected systems before restoration B. Restore the service from the most recent clean backup C. Notify the cyber insurer to avoid violating policy conditions D. Isolate remaining unaffected segments to prevent spread (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 11d
A - would preserve the evidence to prevent alteration or destruction before restoration.
CISSP Practice Question (Domain 8: Software Development Security)
A development team adopts a widely used open source library that accelerates delivery of a revenue-critical release. The library has no active maintainer and no published vulnerability disclosure process. What should the security manager recommend FIRST? A. Add the library to the software bill of materials for monitoring B. Evaluate the component against secure acquisition and supply chain criteria C. Fork the library so the organization controls future patching D. Require compensating controls at the application perimeter (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
2 likes • 16d
B - would determine whether the component satisfies the secure acquisition and supply chain criteria by assessing its quality, security, functionality, performance, compatibility, and compliance with requirements.
Provisionally passed CISSP Exam
I’ve officially passed my CISSP exam! A huge shoutout to this incredible community specially @Vincent Primiani , the cissp.app practice questions, and the insightful live group sessions for pushing me over the finish line. Appreciate all the support here! 🚀🎉
2 likes • 22d
Congratulations 🎉
1-10 of 50
David Uchieng
3
34 points to level up
@david-uchieng-6550
Bachelor of Science in Information Technology

Active 1d ago
Joined Mar 9, 2026
Powered by