Activity
Mon
Wed
Fri
Sun
Sep
Oct
Nov
Dec
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
What is this?
Less
More

Owned by Vincent

CISSP Study Group

2.3k members • Free

Share resources, get advice, and connect with peers studying cybersecurity. Join our CISSP study group and connect with fellow professionals today!

Skoolers

161.8k members • Free

815 contributions to CISSP Study Group
CISSP Practice Question (Domain 1: Security and Risk Management)
During business continuity planning, the IT director assigns recovery time objectives based on system complexity and restoration effort. Several business units later dispute the recovery priorities. Who should the BCP coordinator ensure determines the RTOs? A. The IT director, who understands restoration capability B. Business process owners, based on impact analysis C. Executive management, to resolve the dispute with authority D. The BCP coordinator, to maintain plan consistency (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
CISSP Practice Question (Domain 1: Security and Risk Management)
A new CISO inherits a mature control environment but finds no documented risk assessments supporting it. Leadership considers the controls sufficient and resists spending on analysis. What should the CISO do FIRST? A. Conduct a risk assessment to align controls with business risk B. Benchmark the control set against an industry framework C. Present leadership a business case for the assessment budget D. Continue operations while documenting controls retroactively (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 23h
@Aidah Nakyejwe Correct Answer: C. Present leadership a business case for the assessment budget Explanation (CISSP logic): This question flips the usual pattern on purpose. "Assess first" is the right instinct, but the scenario plants a constraint: leadership resists funding the analysis. Every security program rests on senior management support, and a CISO cannot execute an assessment leadership hasn't authorized or funded. When the blocker is management buy-in, obtaining that buy-in is Step 1. The business case translates security need into business language, which is the CISO's core job. Breakdown: A. The strong distractor, because it's our own mantra used against us. Assessment is the right destination, but conducting one over leadership's objection means running an unfunded, unsanctioned program. Authority precedes activity. B. Benchmarking against a framework proves conformity, not risk alignment. It's also the tempting shortcut for a resistant leadership team: "we match the framework" is compliance logic, and compliance is a snapshot, not a risk decision. C. ✅ Correct. Secure sponsorship and budget first. The business case gives leadership the information to fund the assessment, making everything downstream legitimate. D. Retroactive documentation is accepting the status quo and papering over it. Controls without risk linkage may be over-spent, under-scoped, or pointed at threats that no longer exist, and now that gap has your signature on it. Think like a manager: The CISO doesn't overrule the business; the CISO informs it. When leadership is the obstacle, persuasion is the first control you deploy.
CISSP Question
Which of the following assurance mechanism’s is most likely to provide continuous feedback about how well the access control systems are working? a) Vulnerability Review b) Penetration Testing c) Security Policy Review d) Intrusion Detection System
0 likes • 2d
D. IDS seems most continuous
CISSP Practice Question (Domain 5: Identity and Access Management - AI Exam Guidance)
An autonomous AI agent needs credentials to query production databases and invoke internal APIs on a recurring schedule. The automation team proposes reusing a departed developer's service account to launch quickly. What should the IAM manager require FIRST? A. Rotate the credentials and transfer the account to the automation team B. Register the agent as a distinct non-human identity with a defined owner C. Scope the account's permissions to only the required datasets D. Enable enhanced logging on all agent-initiated transactions (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 3d
✅ Correct Answer: B. Register the agent as a distinct non-human identity with a defined owner Explanation (CISSP logic): Identity governance comes before access control. The clue is the accountability gap: a departed developer's account has no owner, so every action the agent takes traces back to nobody. Registering the agent as its own identity with a named owner establishes the accountability foundation that rotation, scoping, and logging all depend on. Breakdown: A. Rotation is good hygiene, but rotating credentials on an orphaned account still leaves the agent operating under someone else's identity. Right action, wrong step. B. ✅ Correct. IAAA starts with identification. The agent needs its own registered identity and owner before any access decisions are made. C. The strong distractor. Least privilege matters, but you cannot properly scope permissions for an identity that does not formally exist yet. Ownership precedes design. D. Logging an orphaned account produces records nobody is accountable for reviewing. Monitoring comes last in the sequence, not first. Think like a manager: An AI agent is a new hire, not a hand-me-down. Great discussion this round. If your org deployed an AI agent tomorrow, who would own its identity: the automation team, IAM, or the business sponsor?
CISSP Practice Question (Domain 7: Security Operations)
During active ransomware containment, the operations team wants to immediately wipe and reimage infected servers to restore a critical service. Cyber insurance and law enforcement notifications are pending. What should the incident commander do FIRST? A. Preserve forensic images of affected systems before restoration B. Restore the service from the most recent clean backup C. Notify the cyber insurer to avoid violating policy conditions D. Isolate remaining unaffected segments to prevent spread (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 8d
@Paing Zin Correct Answer: A. Preserve forensic images of affected systems before restoration Explanation (CISSP logic): The scenario tells you containment is already active, so the decision on the table is the wipe. Wiping and reimaging is eradication and recovery, and doing it now would permanently destroy the evidence that pending insurance claims and law enforcement referrals depend on. Evidence preservation is the gating step between containment and recovery: once you image the systems, restoration can proceed without sacrificing the investigation, the claim, or potential prosecution. Breakdown: A. ✅ Correct. Capture forensically sound images first. It is the only option that protects evidence integrity while still enabling the restore the business needs. B. Restoring from backup is where the operations team wants to jump, and it's the right destination. But recovery before preservation converts your best evidence into blank disks. Availability pressure is exactly how evidence gets destroyed. C. Notifying the insurer matters, and policies often require prompt notice, but a phone call can happen in parallel. It's the strong distractor because it invokes a real compliance condition, yet it does not stop the irreversible act about to occur. D. Isolating unaffected segments is genuine containment, but the stem says containment is underway. Choosing D means answering a question the team already handled while the evidence gets wiped behind you. Think like a manager: In incident response, the irreversible step waits. Recovery restores the business; preservation protects the truth, and you can only skip one of them once.
1-10 of 815
Vincent Primiani
7
4,857 points to level up
Cybersecurity. The Study Group Guy.

Active 4h ago
Joined Apr 29, 2024
New York, NY
Powered by