Activity
Mon
Wed
Fri
Sun
Oct
Nov
Dec
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
Sep
What is this?
Less
More
CISSP Study Group

2.3k members • Free

26 contributions to CISSP Study Group
CISSP Practice Question (Domain 8: Software Development Security)
A product team used an AI coding assistant to build a payment feature and wants it in Friday's release. Nobody threat modeled the code, and the pipeline only runs unit tests. What should the application security manager require FIRST? A. Static and dynamic scanning gates in the pipeline B. Threat model of the feature's payment data flows C. Senior developer review of the generated code D. Feature flag and rollback plan for the release (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
0 likes • 3h
B
Group Mock Exam Day, Saturday September 19. Let's all sit it together.
Saturday September 19 is our first Group Mock Exam Day, and I want the whole group in on it. Here is the plan. On September 19, cissp.app is open to everyone, free, no subscription needed. Midnight to midnight Eastern you can sit a real adaptive CISSP mock exam, 100 to 150 questions, up to 3 hours, the same engine paying members use, and get a domain-by-domain breakdown at the end. Kickoff, Saturday 3:00pm Eastern. We will host a live kickoff on Google Meet, the link is in your enrollment confirmation. Log in together, last-minute questions, then everyone goes and sits the exam. If you cannot make 3:00pm, you can start any time that day. Everyone who signs up goes on the public board at cissp.app/mock-exam-day, and as the day goes on it shows who has started and who has finished. Real names or a handle, up to you. No scores on the board, just who showed up and who finished, which is the part that matters. Afterwards. Take your weakest two or three domains to a study group session the week after, while it is all still fresh. Bring someone! The day is open to everyone, so send cissp.app/mock-exam-day to anyone you know who is studying for the CISSP. No subscription needed, and they will not be sitting it alone. Sign up now at cissp.app/mock-exam-day so your access is ready when the day starts. Then comment below with "I'm in" so we can see who is coming! If you have been putting off finding out where you actually stand, this is the day we can all do it together.
Group Mock Exam Day, Saturday September 19. Let's all sit it together.
2 likes • 22h
This is fantastic Vinny. Such a huge help to the community. Thank you very much sir.
CISSP Practice Question (Domain 4: Communication and Network Security)
A hospital wants new internet-connected infusion pumps on the existing user VLAN to hit a ward opening date. The pumps cannot run endpoint agents and are patched quarterly. What should the network security manager require FIRST? A. Dedicated network zone for the pumps with controlled ingress B. Risk assessment of the pumps against clinical network requirements C. Network intrusion detection covering the user VLAN D. Vendor commitment to a faster patch cadence (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
2 likes • 1d
B. While it might add a delay and risk to meet the deadline of the opening date, assessing the risk against already determined clinical standards is the safest approach. Once that is understood technical solutions can be offered and considered.
CISSP Practice Question (Domain 2: Asset Security)
A SaaS contract ends and the vendor confirms customer records were deleted from production. Retention for those records has expired, and legal wants proof before signing the closure letter. What should the data owner require FIRST? A. Certificate of destruction covering backups and replicas B. Cryptographic erasure of the vendor's data encryption keys C. Signed attestation from the vendor's compliance officer D. Independent audit of the vendor's deletion procedures (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
0 likes • 2d
A
CISSP Practice Question (Domain 3: Security Architecture and Engineering)
A firm plans to move its enterprise key management service into the same cloud provider hosting its encrypted customer data. The migration eliminates a costly on-premises HSM cluster and satisfies the finance team. What is the security architect's PRIMARY concern? A. Loss of separation of duties between data and key custody B. Increased latency affecting cryptographic operation performance C. Vendor lock-in limiting future portability of encrypted data D. Reduced ability to demonstrate FIPS validated key storage (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 4d
A. Having the keys in the same infra as the data they are used to protect significantly increases the risk to that data. The data and keys could be exfiltrated in an attack and used to decrypt offline later rendering remediation efforts ineffective once discovered.
1-10 of 26
James Dobbin
3
32 points to level up
@james-dobbin-9355
20+ as a jack of all trades years in I.T systems administration. Moving my career to I.T security

Active 3h ago
Joined Feb 18, 2026
Powered by