Activity
Mon
Wed
Fri
Sun
Oct
Nov
Dec
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
What is this?
Less
More
CyberMAYnia CAREER

583 members • Free

CISSP Study Group

2.3k members • Free

68 contributions to CISSP Study Group
CISSP Practice Question
A multinational organization discovers that a critical third-party SaaS provider processes sensitive customer data. During a routine review, the security team learns that the provider does not support MFA for privileged administrative accounts.The organization’s security policy requires MFA for privileged access, but the SaaS contract does not explicitly require the provider to implement it. The business owner argues that replacing the provider would be expensive and could disrupt operations. What should the security manager do FIRST? A. Require the provider to implement MFA immediately as a condition of continued service. B. Perform a risk assessment to determine whether the provider's control gap exceeds the organization's risk appetite. C. Terminate the provider because it violates the organization's security policy. D. Negotiate a contractual amendment requiring MFA and periodic compliance audits.
1 like • 2d
B.
CISSP Practice Question (Domain 3: Security Architecture and Engineering)
A firm plans to move its enterprise key management service into the same cloud provider hosting its encrypted customer data. The migration eliminates a costly on-premises HSM cluster and satisfies the finance team. What is the security architect's PRIMARY concern? A. Loss of separation of duties between data and key custody B. Increased latency affecting cryptographic operation performance C. Vendor lock-in limiting future portability of encrypted data D. Reduced ability to demonstrate FIPS validated key storage (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
0 likes • 2d
A-
CISSP Practice Question (Domain 1: Security and Risk Management)
A security consultant discovers her client is knowingly misrepresenting remediation status to its customers after an assessment she performed. The client cites confidentiality clauses in her contract and directs her to stay silent. Under the ISC2 Code of Ethics, what is her PRIMARY obligation? A. Honor the confidentiality agreement with the client B. Act honorably and protect the public trust C. Report the misrepresentation to affected customers D. Withdraw from the engagement and document concerns (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
0 likes • 10d
B
CISSP Practice Question (Domain 1: Security and Risk Management)
During business continuity planning, the IT director assigns recovery time objectives based on system complexity and restoration effort. Several business units later dispute the recovery priorities. Who should the BCP coordinator ensure determines the RTOs? A. The IT director, who understands restoration capability B. Business process owners, based on impact analysis C. Executive management, to resolve the dispute with authority D. The BCP coordinator, to maintain plan consistency (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 15d
B. Business owners have best knowledge of rto’s
CISSP Practice Question (Domain 5: Identity and Access Management - AI Exam Guidance)
An autonomous AI agent needs credentials to query production databases and invoke internal APIs on a recurring schedule. The automation team proposes reusing a departed developer's service account to launch quickly. What should the IAM manager require FIRST? A. Rotate the credentials and transfer the account to the automation team B. Register the agent as a distinct non-human identity with a defined owner C. Scope the account's permissions to only the required datasets D. Enable enhanced logging on all agent-initiated transactions (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 21d
B. The first step is to provision identity and assign ownership for accountability
1-10 of 68
Naashon Zalk
3
38 points to level up
@naashon-zalk-2309
Cyber Security Consultant (GRC) | ISO 27001 Lead Implementer |

Active 2d ago
Joined Jan 26, 2026
Powered by