Activity
Mon
Wed
Fri
Sun
Nov
Dec
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
Sep
Oct
What is this?
Less
More
78 contributions to CISSP Study Group
CISSP Practice Question (Domain 4: Communication and Network Security)
A hospital wing opens in 45 days. Clinical devices from six vendors will join the flat network and each vendor wants remote support access. No network requirements exist for them. What should the security manager do FIRST? A. Isolate every device on its own VLAN B. Set segmentation and remote access requirements by device risk C. Route all vendor support through one monitored jump host D. Scan each device for vulnerabilities before go-live (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 7h
I think scanning the devices for vulnerability first would help determine the device risk and then you can set segmentation and remote access based on device risk …. “D” for me .
CISSP Practice Question (Domain 2: Asset Security)
A leasing firm wants 400 laptops back in two weeks. IT plans a quick format before shipping. No sanitization standard exists and the laptops held regulated client data. What should the security manager do FIRST? A. Quick format each laptop and keep signed return manifests B. Define sanitization requirements from the data classification held C. Physically destroy every drive before the laptops ship D. Negotiate an extension to allow full disk wiping (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 5d
Since there isn’t much time - I’d negotiate an extension to allow full disk wiping (D) .. after I need to define sanitization requirements from data classification held .
CISSP Practice Question (Domain 6: Security Assessment and Testing)
A fintech board wants a bug bounty live before a funding round in 30 days. No vulnerability disclosure policy exists and internet-facing assets were never inventoried. What should the security manager do FIRST? A. Launch a private bounty limited to the main web application B. Run an authenticated vulnerability scan of all production systems C. Define the disclosure policy and scope the assets in play D. Hire an external firm to penetration test before launch (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 7d
Define the disclosure policy and scope the assets in play - C … it seems more like the better option of all .
CISSP Practice Question (Domain 5: Identity and Access Management (IAM))
Attackers twice reset executive passwords by phoning the outsourced help desk. The CIO wants phishing-resistant MFA purchased this month. No standard defines how callers prove identity. What should the security manager do FIRST? A. Deploy phishing-resistant MFA for all executives B. Require manager callback approval for every reset C. Retrain help desk staff on social engineering D. Assess the reset process and define identity proofing requirements (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 9d
Assess the reset process and define identity proofing Requirement - D
CISSP Practice Question (Domain 1: Security and Risk Management)
A cloud outage cost a retailer a day of online sales. The CFO has funded a second region and wants migration started this quarter. No business impact analysis exists. What should the security manager do FIRST? A. Design the second region with the cloud team B. Conduct a business impact analysis to set recovery targets C. Negotiate a stronger uptime commitment with the provider D. Buy business interruption insurance for cloud outages (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
2 likes • 12d
Conduct a BIA to set recovery time
1-10 of 78
Idris Onimole
4
67 points to level up
@idris-onimole-7612
CS Incident Responder - Love learn and share knowledge, find a mentor towards being a Security consultant / Infosec manager. Taking CISSP soon.

Active 7h ago
Joined Sep 14, 2025
ENTP
Prague
Powered by