Activity
Mon
Wed
Fri
Sun
Oct
Nov
Dec
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
Sep
What is this?
Less
More
CISSP Study Group

2.3k members • Free

21 contributions to CISSP Study Group
CISSP Practice Question (Domain 1: Security and Risk Management)
A security consultant discovers her client is knowingly misrepresenting remediation status to its customers after an assessment she performed. The client cites confidentiality clauses in her contract and directs her to stay silent. Under the ISC2 Code of Ethics, what is her PRIMARY obligation? A. Honor the confidentiality agreement with the client B. Act honorably and protect the public trust C. Report the misrepresentation to affected customers D. Withdraw from the engagement and document concerns (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
0 likes • 15d
B
CISSP Practice Question (Domain 1: Security and Risk Management)
A new CISO inherits a mature control environment but finds no documented risk assessments supporting it. Leadership considers the controls sufficient and resists spending on analysis. What should the CISO do FIRST? A. Conduct a risk assessment to align controls with business risk B. Benchmark the control set against an industry framework C. Present leadership a business case for the assessment budget D. Continue operations while documenting controls retroactively (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
0 likes • 22d
A
Practice Questions
Which of the following is the PRIMARY goal of a security awareness training program within an organization? 1. To ensure all employees can respond effectively to security incidents 2.To reduce likelihood of insider threats and data breaches 3.To achieve compliance with industry security standards 4.To teach employees the organization security expectations
Poll
36 members have voted
1 like • Nov '25
4.To teach employees the organization security expectations
Practice Question
Your organization has hired a new Security Architect who has experience with products from a particular vendor and is therefore inclined to use their suite of products. She suggests your team replaces the existing tools with the products of her chosen vendor. What is the primary concept missing from this action? A Risk Assessment B Due Diligence C Due Care D Strategic Alignment
1 like • Nov '25
A Risk Assessment
CISSP Practice Question (Identity and Access Management (IAM) - Hard):
An organization utilizes a combination of centralized and decentralized identity management systems. One day, the IT security team discovers that a user, involved in various departments, has retained access to systems beyond what their current role necessitates, leading to excessive privilege accumulation. Given the hybrid nature of the identity management system, what should be the immediate course of action to rectify the situation according to IAM best practices? Options: A. Run a script to automatically remove excess privileges across all systems. B. Conduct a comprehensive audit of user access rights and adjust privileges manually. C. Enforce multifactor authentication for all user logins. D. Transition to a fully centralized identity management system. (answer tomorrow!) Study more at : cissp.app !
0 likes • Oct '25
B
1-10 of 21
Dilruba Sharmeen
2
7 points to level up
@dilruba-sharmeen-2505
With experience in networking and a recently completed MSc in Information Security, I am now aspiring to become a CISSP-certified professional.

Active 4d ago
Joined Aug 5, 2025
Powered by