Activity
Mon
Wed
Fri
Sun
Nov
Dec
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
Sep
Oct
What is this?
Less
More
175 contributions to CISSP Study Group
Key difference between Cryptography and Hashing
In a laymen thought process, Cryptography and Hashing does the same jumbling of the characters. but wanted to know the exact key difference and thought I should also share it with you all.
Key difference between Cryptography and Hashing
1 like • 13h
nice post. Thanks @Vishal Kumar
CISSP Practice Question (Domain 8: Software Development Security)
A bank's mobile team wants a partner's analytics SDK in next week's release. The contract is signed, the SDK is compiled, and nobody knows what data it sends. What should the security manager do FIRST? A. Demand the SDK source code from the partner B. Assess the SDK's data flows and risk against policy C. Capture the SDK's network traffic in dynamic testing D. Hold the release until the partner passes a security audit (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
0 likes • 17h
B. Assess the SDK's data flows and risk against policy should be FIRST. This aligns with security governance principles.
CISSP Practice Question (Domain 3: Security Architecture and Engineering)
An insurer wants an AI assistant to answer questions from policyholder records. To meet a quarter-end demo, the architect puts it inside the application trust zone. No threat model exists for the new flows. What should the security architect do FIRST? A. Segment the assistant into its own zone B. Threat model the new flows and set trust boundaries C. Encrypt every record the assistant can read D. Limit the assistant to read-only access (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 6d
B Threat modeling is the first option in this scenario.
CISSP Practice Question (Domain 2: Asset Security)
A leasing firm wants 400 laptops back in two weeks. IT plans a quick format before shipping. No sanitization standard exists and the laptops held regulated client data. What should the security manager do FIRST? A. Quick format each laptop and keep signed return manifests B. Define sanitization requirements from the data classification held C. Physically destroy every drive before the laptops ship D. Negotiate an extension to allow full disk wiping (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
2 likes • 6d
No sanitization standard exists and the laptops held regulated client data..... A. Quick format each laptop and keep signed return manifests. This quick fix may not follow regulations. B. Define sanitization requirements from the data classification held. This should be performed FIRST followed by D. C. Physically destroy every drive before the laptops ship. The organization will be penalized and will pay the cost of the drives that are destroyed. The scenario did not specify that there are extra drives or the drives could be kept by the organization. D. Negotiate an extension to allow full disk wiping. This is reactionary but may be implemented after a policy is created.
CISSP Practice Question (Domain 8: Software Development Security)
A sales team built a customer portal on a low-code platform without security involvement and wants it live Monday. It holds customer contracts and nobody owns its code or data. What should the security manager do FIRST? A. Schedule a penetration test before Monday B. Move the portal into the corporate development pipeline C. Assess the portal's data, risk and ownership before release D. Require secure coding training for the sales team (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
0 likes • 7d
C "nobody owns its code or data" is the biggest clue that stands out most to me. ..... risk and ownership before release would be considered first.
1-10 of 175
Ed Morawski
5
316 points to level up
@ed-morawski-4430
Ed

Active 6h ago
Joined Nov 21, 2025
Powered by