Activity
Mon
Wed
Fri
Sun
Oct
Nov
Dec
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
What is this?
Less
More
CyberMAYnia CAREER

582 members • Free

CISSP Study Group

2.3k members • Free

193 contributions to CISSP Study Group
CISSP Practice Question
A multinational organization discovers that a critical third-party SaaS provider processes sensitive customer data. During a routine review, the security team learns that the provider does not support MFA for privileged administrative accounts.The organization’s security policy requires MFA for privileged access, but the SaaS contract does not explicitly require the provider to implement it. The business owner argues that replacing the provider would be expensive and could disrupt operations. What should the security manager do FIRST? A. Require the provider to implement MFA immediately as a condition of continued service. B. Perform a risk assessment to determine whether the provider's control gap exceeds the organization's risk appetite. C. Terminate the provider because it violates the organization's security policy. D. Negotiate a contractual amendment requiring MFA and periodic compliance audits.
0
0
CISSP Practice Question (Domain 1: Security and Risk Management)
A security consultant discovers her client is knowingly misrepresenting remediation status to its customers after an assessment she performed. The client cites confidentiality clauses in her contract and directs her to stay silent. Under the ISC2 Code of Ethics, what is her PRIMARY obligation? A. Honor the confidentiality agreement with the client B. Act honorably and protect the public trust C. Report the misrepresentation to affected customers D. Withdraw from the engagement and document concerns (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 8d
A. Honor the confidentiality agreement with the client ( Confidentiality is important, but it is subordinate to the higher ethical obligations established by the ISC2 Code of Ethics). B. Act honorably and protect the public trust ( ISC2 canon I & II applies here for primary obligation) C. Report the misrepresentation to affected customers (Reporting directly to affected customers may be one possible action, but it is not automatically the consultant's primary or first obligation under the Code of Ethics). D. Withdraw from the engagement and document concerns (Withdrawal and documentation may be appropriate actions if the client refuses to correct the misrepresentation, but it does not itdself define the consultant's PRIMARY ethical obligation).
The CISSP Risk‑Based Mindset – A Prerequisite for the Exam
Adopting the CISSP mindset requires embracing the perspective of a strategic risk practitioner whose primary responsibility is to evaluate, communicate, and manage organizational risk. Rather than approaching security as a collection of technical tasks, the CISSP mindset centers on understanding how every decision influences the organization’s overall risk posture. This perspective positions the security leader as a trusted advisor who guides executives in making informed, risk‑aligned choices that support mission objectives. A risk‑based mindset begins with recognizing that security decisions must be evaluated through the dual lenses of business impact and risk tolerance. Human life and safety remain paramount, followed by the preservation of business continuity, critical assets, and organizational reputation. The goal is not to eliminate risk entirely—an unrealistic and cost‑prohibitive endeavor—but to reduce risk to levels that leadership deems acceptable. Achieving this requires the thoughtful integration of administrative, physical, and technical controls that are both effective and economically justified. This mindset also demands a holistic understanding of the organization’s operations, dependencies, and vulnerabilities. Security policies and controls must be proactive, grounded in risk assessments, and aligned with legal, regulatory, and contractual obligations. A CISSP practitioner recognizes that security is not an obstacle but a business enabler, ensuring that risk‑informed decisions support strategic objectives rather than hinder them. Ultimately, thinking like a CISSP means taking ownership of governance responsibilities, anticipating how security decisions ripple across the enterprise, and consistently advocating for defense‑in‑depth as a means of managing uncertainty. It reflects a disciplined commitment to evaluating threats, vulnerabilities, and impacts in a structured manner, ensuring that security practices remain aligned with organizational risk appetite throughout the entire enterprise lifecycle.
1 like • 11d
Well said, in cut short, the strongest message is the shift from technical problem-solving to strategic risk management, where security decisions are evaluated in terms of business impact, risk appetite, and organizational objectives. CISSP is not just about knowing security controls—it is about understanding risk, business objectives, and helping leadership make informed decisions. Security should enable the business, not simply restrict it.
CISSP Practice Question (Domain 6: Security Assessment and Testing)
Leadership orders a penetration test of a customer-facing platform after a competitor's breach. Half the platform runs on a SaaS provider's infrastructure. The testing firm is contracted and ready to begin. What should the security manager confirm FIRST? A. Authorization and scope boundaries from the SaaS provider B. Rules of engagement defining escalation and stop conditions C. Backups of production data before intrusive testing begins D. Cyber liability coverage extends to testing activities (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
2 likes • 11d
A. Authorization and scope boundaries from the SaaS provider (authorization must be confirmed first because the organization may not have the right to authorize testing of infrastructure owned or operated by the SaaS provider) B. Rules of engagement defining escalation and stop conditions (rules of engagement are established once authorized assets and scope boundaries are confirmed) C. Backups of production data before intrusive testing begins ( backups are a risk mitigation and operational preparation activity, but they cannot substitute for obtaining authorization) D. Cyber liability coverage extends to testing activities ( insurance coverage is a risk-transfer consideration and may need to be reviewed, but it does not establish authorization to test the SaaS provider's environment).
CISSP Practice Question (Domain 1: Security and Risk Management)
During business continuity planning, the IT director assigns recovery time objectives based on system complexity and restoration effort. Several business units later dispute the recovery priorities. Who should the BCP coordinator ensure determines the RTOs? A. The IT director, who understands restoration capability B. Business process owners, based on impact analysis C. Executive management, to resolve the dispute with authority D. The BCP coordinator, to maintain plan consistency (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 12d
A. The IT director, who understands restoration capability ( IT is supporitng function for business, IT should follow business requirement by business process owners for determing RTO). B. Business process owners, based on impact analysis (business process owners should determine recovery requirements based on business impact and acceptable downtime. IT then evaluates the technical feasibility and implements the recovery capability necessary to meet the established RTO). C. Executive management, to resolve the dispute with authority ( If the different business prcocesses owners has conflict for RTOs then executive management can come in). D. The BCP coordinator, to maintain plan consistency ( BCP coordinator is responsible for smooth impelmentation of BCP by keeping all relevant on one page but business process owner are primarily responsible for RTOs).
1-10 of 193
Hassan Na
5
199 points to level up
@hassan-hassan-4557
CISSP, CC

Active 11m ago
Joined Dec 7, 2025
Powered by