Activity
Mon
Wed
Fri
Sun
Oct
Nov
Dec
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
Sep
What is this?
Less
More
Cyber Stack Elite

27 members • Free

CISSP Study Group

2.3k members • Free

The AI/GRC Career Starter

625 members • Free

Big Stage Energy

143 members • $499/y

Cloud Tech Free Training

20.2k members • Free

BowTiedCyber Hoodies

4k members • Free

Cythority

615 members • Free

Real Estate Investing

5.7k members • Free

Symoné GovTech Community(Free)

25.8k members • Free

4 contributions to CISSP Study Group
CISSP Practice Question (Domain 6: Security Assessment and Testing)
A retailer's payment platform needs a penetration test before a regulator's deadline in six weeks. The platform team offers to test it themselves. What is the MOST appropriate response from the security manager? A. Accept the offer and review the resulting report yourself B. Engage an independent tester and agree scope and rules of engagement C. Run a vulnerability scan first to fix known defects D. Postpone testing until open platform findings are remediated (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
0 likes • 6d
B
CISSP Practice Question (Domain 1: Security and Risk Management)
A security consultant discovers her client is knowingly misrepresenting remediation status to its customers after an assessment she performed. The client cites confidentiality clauses in her contract and directs her to stay silent. Under the ISC2 Code of Ethics, what is her PRIMARY obligation? A. Honor the confidentiality agreement with the client B. Act honorably and protect the public trust C. Report the misrepresentation to affected customers D. Withdraw from the engagement and document concerns (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
0 likes • 22d
B
🧠The CISSP Mindset - Pre-requisite for the exam
The CISSP mindset is fundamentally that of a strategic risk manager and trusted advisor, not a hands-on technical firefighter. It requires evaluating every security decision through the dual lenses of business alignment and risk management—prioritizing human life and safety above all else, followed closely by business continuity and asset protection. Rather than aiming for absolute, cost-prohibitive security, a CISSP practitioner seeks to reduce risk to an acceptable level through balanced, cost-effective administrative, physical, and technical controls. This mindset demands a holistic view of the organization, ensuring security policies are proactive rather than reactive, compliance and legal requirements are met, and security functions as an enabler of business goals rather than a bottleneck. Ultimately, thinking like a CISSP means taking accountability for governance, understanding the broader operational impact of security decisions, and constantly advocating for defense-in-depth across the entire enterprise lifecycle.
1 like • 28d
I've been struggling with selecting answers that are non technical, at times I want to go for technical and choose a risk approach based answer and at times still get the answer wrong and it just make me feel discouraged sometimes
CISSP Practice Question (Domain 1: Security and Risk Management)
A new CISO inherits a mature control environment but finds no documented risk assessments supporting it. Leadership considers the controls sufficient and resists spending on analysis. What should the CISO do FIRST? A. Conduct a risk assessment to align controls with business risk B. Benchmark the control set against an industry framework C. Present leadership a business case for the assessment budget D. Continue operations while documenting controls retroactively (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 28d
C
1-4 of 4
Karizma Hanshaw
1
4 points to level up
@karizma-hanshaw-5811
Vendor Security & Privacy Analyst

Active 7h ago
Joined Aug 17, 2026
Powered by