Activity
Mon
Wed
Fri
Sun
Nov
Dec
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
Sep
Oct
What is this?
Less
More
10 contributions to CISSP Study Group
CISSP Practice Question (Domain 1: Security and Risk Management)
A cloud outage cost a retailer a day of online sales. The CFO has funded a second region and wants migration started this quarter. No business impact analysis exists. What should the security manager do FIRST? A. Design the second region with the cloud team B. Conduct a business impact analysis to set recovery targets C. Negotiate a stronger uptime commitment with the provider D. Buy business interruption insurance for cloud outages (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
0 likes • 21h
B The CFO has already decided to fund a second cloud region because of a previous outage. However, there is no BIA, the organisation does not know its required RTO/RPO/MTPD, and the actual business impact of downtime has not been formally assessed. A BIA identifies critical business processes, financial and operational impacts, acceptable downtime, recovery priorities, and RTOs and RPOs. Only after these requirements are defined can the organisation determine whether a second region is necessary and sufficient to business requirements. Business requirements drive technical solutions, not the other way around.
CISSP Practice Question (Domain 4: Communication and Network Security)
A hospital wing opens in 45 days. Clinical devices from six vendors will join the flat network and each vendor wants remote support access. No network requirements exist for them. What should the security manager do FIRST? A. Isolate every device on its own VLAN B. Set segmentation and remote access requirements by device risk C. Route all vendor support through one monitored jump host D. Scan each device for vulnerabilities before go-live (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 22h
B From the scenario given the environment contains: - Clinical devices from six vendors - A flat network - Multiple requests for remote support access - No existing network security requirements The logic is to determine: - Which devices are highest risk - What level of network segmentation is required - How vendors may access systems remotely - Authentication, monitoring, and logging requirements - Whether access should be persistent or on-demand Once these requirements are defined, the organisation can implement the appropriate architecture. Risks -> Security architecture design -> Technical implementation.
CISSP Practice Question (Domain 6: Security Assessment and Testing)
A fintech board wants a bug bounty live before a funding round in 30 days. No vulnerability disclosure policy exists and internet-facing assets were never inventoried. What should the security manager do FIRST? A. Launch a private bounty limited to the main web application B. Run an authenticated vulnerability scan of all production systems C. Define the disclosure policy and scope the assets in play D. Hire an external firm to penetration test before launch (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 4d
C There are no vulnerability disclosure policy exists, internet-facing assets were never inventoried, and Board wants a bug bounty launched quickly. A bug bounty programme requires: 1.Clear rules of engagement and disclosure process. 2.Defined scope (what can and cannot be tested). 3.Asset inventory and ownership. 4.Triage and response procedures. Therefore, it should be Governance → Scope → Assessment → Bug Bounty.
CISSP Practice Question (Domain 2: Asset Security)
A leasing firm wants 400 laptops back in two weeks. IT plans a quick format before shipping. No sanitization standard exists and the laptops held regulated client data. What should the security manager do FIRST? A. Quick format each laptop and keep signed return manifests B. Define sanitization requirements from the data classification held C. Physically destroy every drive before the laptops ship D. Negotiate an extension to allow full disk wiping (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
2 likes • 4d
B The scenario explicitly states: - The laptops contain regulated client data. - No sanitisation standard exists. - IT wants to do a quick format. The security manager's first responsibility is to determine what level of sanitisation is required based on the classification and sensitivity of the data. Only after the requirements are defined can an appropriate method be selected (clear, purge, cryptographic erase, destroy, etc.). Data classification → Sanitisation requirements → Sanitisation method → Verification → Disposal You cannot decide whether quick formatting, wiping, crypto-erase, or destruction is appropriate until you know the required level of protection.
CISSP Practice Question (Domain 3: Security Architecture and Engineering)
An insurer wants an AI assistant to answer questions from policyholder records. To meet a quarter-end demo, the architect puts it inside the application trust zone. No threat model exists for the new flows. What should the security architect do FIRST? A. Segment the assistant into its own zone B. Threat model the new flows and set trust boundaries C. Encrypt every record the assistant can read D. Limit the assistant to read-only access (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
0 likes • 4d
B
1-10 of 10
Olena Chumachenko
2
14 points to level up
@olena-chumachenko-4193
Information Security Auditor

Active 20h ago
Joined Jun 29, 2026
Powered by