Activity
Mon
Wed
Fri
Sun
Nov
Dec
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
Sep
Oct
What is this?
Less
More

Owned by Vincent

Share resources, get advice, and connect with peers studying cybersecurity. Join our CISSP study group and connect with fellow professionals today!

Skoolers
153k
Free
851 contributions to CISSP Study Group
CISSP Practice Question (Domain 4: Communication and Network Security)
A hospital wing opens in 45 days. Clinical devices from six vendors will join the flat network and each vendor wants remote support access. No network requirements exist for them. What should the security manager do FIRST? A. Isolate every device on its own VLAN B. Set segmentation and remote access requirements by device risk C. Route all vendor support through one monitored jump host D. Scan each device for vulnerabilities before go-live (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
CISSP Practice Question (Domain 2: Asset Security)
A leasing firm wants 400 laptops back in two weeks. IT plans a quick format before shipping. No sanitization standard exists and the laptops held regulated client data. What should the security manager do FIRST? A. Quick format each laptop and keep signed return manifests B. Define sanitization requirements from the data classification held C. Physically destroy every drive before the laptops ship D. Negotiate an extension to allow full disk wiping (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 18h
@Olena Chumachenko Correct Answer: B. Define sanitization requirements from the data classification held Explanation (CISSP logic): The clues are "back in two weeks", "quick format before shipping", "no sanitization standard exists" and "regulated client data". Asset security runs from classification to disposal: the handling a device gets at end of life is set by the most sensitive data it held, and a quick format leaves that data recoverable, which is data remanence by another name. Nobody has written down what sanitization the regulated data requires, so the format, the destruction and the extension are all being argued without a requirement to meet. Assess before you act: classify what was on the drives, state the sanitization level that classification demands, and the method and the timeline follow. Breakdown: A. A quick format with signed manifests is the strong distractor because it meets the deadline and leaves a paper trail. But a format removes the index, not the data, so the manifests document the handover of 400 drives that still hold regulated client records, and the signature proves custody, not sanitization. B. ✅ Correct. Defining the sanitization requirement from the classification tells the manager whether clearing, purging or destruction is required for these drives, and whether every laptop needs the same treatment. That single decision sets the method, the evidence to keep and whether two weeks is even achievable. C. Physically destroying every drive is the safest outcome for the data and may be exactly what the classification demands. But the laptops belong to the lessor, destroying 400 drives without a requirement behind it breaches the contract and the budget, and it treats a laptop that held nothing sensitive the same as one that held everything. D. Negotiating an extension buys time and shows the manager respects the deadline rather than cutting corners. It still assumes full disk wiping is the right method, which nobody has established, and if the classification calls for destruction the extra weeks are spent on a wipe the regulator will not accept.
CISSP Practice Question (Domain 3: Security Architecture and Engineering)
An insurer wants an AI assistant to answer questions from policyholder records. To meet a quarter-end demo, the architect puts it inside the application trust zone. No threat model exists for the new flows. What should the security architect do FIRST? A. Segment the assistant into its own zone B. Threat model the new flows and set trust boundaries C. Encrypt every record the assistant can read D. Limit the assistant to read-only access (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 4d
@Vishal Kumar Correct Answer: B. Threat model the new flows and set trust boundaries Explanation (CISSP logic): The clues are "quarter-end demo", "inside the application trust zone" and "no threat model exists for the new flows". Secure design starts by understanding what is crossing which boundary: an AI assistant that reads policyholder records is a new path for data to leave the zone, and placing it inside that zone to save time is a design decision made before anyone has asked what could go wrong. Threat modelling names the assets, the entry points and the trust boundaries, and every control that follows, segmentation, encryption or access limits, is chosen to answer a threat it found. Assess before you act: a demo deadline does not change the order. Breakdown: A. Segmenting the assistant into its own zone is the strong distractor because it is the architect's instinct and may well be the end state. But it is a boundary drawn before the threats are known, so it can isolate the wrong thing, block flows the business needs for the demo and still leave the record access path untouched. B. ✅ Correct. A threat model of the new flows shows where policyholder data moves, who and what can reach the assistant, and which boundaries actually matter. The trust boundaries it sets tell the architect whether the assistant belongs inside the zone at all and which of the other three controls are worth building. C. Encrypting every record the assistant can read protects data at rest and is a sound control. The assistant reads records in the clear to answer questions, so encryption does nothing to the flow that is actually new, and bulk encryption adds key management cost without reducing the exposure the demo creates. D. Read-only access is least privilege in action and will probably appear in the final design. It limits what the assistant can change, not what it can disclose, and the risk in this scenario is policyholder data leaving through answers, which a read-only grant permits in full.
CISSP Practice Question (Domain 6: Security Assessment and Testing)
A fintech board wants a bug bounty live before a funding round in 30 days. No vulnerability disclosure policy exists and internet-facing assets were never inventoried. What should the security manager do FIRST? A. Launch a private bounty limited to the main web application B. Run an authenticated vulnerability scan of all production systems C. Define the disclosure policy and scope the assets in play D. Hire an external firm to penetration test before launch (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
2 likes • 5d
@Tayo Olaomi Correct Answer: C. Define the disclosure policy and scope the assets in play Explanation (CISSP logic): The clues are "live before a funding round", "no vulnerability disclosure policy exists" and "internet-facing assets were never inventoried". Security assessment and testing starts with scope and rules of engagement: you cannot invite strangers to attack systems you have not listed, under terms you have not written. The disclosure policy sets what researchers may touch, how findings are reported and how fast the company must respond, and the asset inventory tells you what is actually exposed. Assess before you act: a bounty launched without either is an unmanaged test with a marketing deadline. Breakdown: A. A private bounty on the main application is the strong distractor because it looks cautious, small and fast enough for the 30 days. But it still needs a policy to govern the researchers and a scope to define the target, and limiting it to one app by guesswork leaves every uninventoried system exposed to the same testers with no rules at all. B. An authenticated scan is a legitimate assessment activity and will surface known weaknesses quickly. It tests only what you point it at, so without an inventory it repeats the same blind spot, and it does nothing to set the disclosure terms the board's bounty depends on. C. ✅ Correct. Writing the disclosure policy and scoping the assets gives the program its rules of engagement, its safe harbour for researchers, its response commitments and its target list. Every later step, the private bounty, the scan or an external test, then runs inside a boundary the company chose rather than one it discovers. D. An external penetration test brings independence and a defined report before launch, which a board would welcome. It is a point-in-time assessment that also needs a scope to be worth anything, and it answers a different question from whether the company is ready to run a continuous public program.
CISSP Practice Question (Domain 5: Identity and Access Management (IAM))
Attackers twice reset executive passwords by phoning the outsourced help desk. The CIO wants phishing-resistant MFA purchased this month. No standard defines how callers prove identity. What should the security manager do FIRST? A. Deploy phishing-resistant MFA for all executives B. Require manager callback approval for every reset C. Retrain help desk staff on social engineering D. Assess the reset process and define identity proofing requirements (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
0 likes • 7d
@Ronald Zierikzee Correct Answer: D. Assess the reset process and define identity proofing requirements Explanation (CISSP logic): The clues are "phoning the outsourced help desk", "purchased this month" and "no standard defines how callers prove identity". Identity and Access Management starts with identity proofing: an authenticator is only as strong as the process that issues and resets it, and here the reset path is the door the attackers used twice. Nobody has written down what proof a caller must give, so every control on the table is being chosen without a requirement to meet. Assess before you act: map how resets really happen, then set the proofing standard the help desk contract and the tools must satisfy. Breakdown: A. Phishing-resistant MFA is the strong distractor because it is modern, funded and almost certainly part of the end state. But the attackers did not phish anyone, they talked the help desk into a reset, and a stronger authenticator that the same desk can re-enroll or bypass on a phone call leaves the door exactly where it was. B. A manager callback is a sensible out-of-band check and may well appear in the final procedure. It is one control picked before the requirement exists, it fails when the manager is unreachable or is the one being impersonated, and applied to every reset it trades availability for a safeguard nobody has sized. C. Retraining addresses the human weakness and awareness belongs in the program. But staff cannot be trained to follow a standard that does not exist, and with an outsourced desk the obligation has to live in the process and the contract, not in the memory of whoever takes the next call. D. ✅ Correct. Assessing the reset process shows how callers are verified today, where the two attacks got through and what the provider is contractually bound to do. The proofing requirements that come out of it tell you which resets need stronger evidence, and the MFA purchase, the callback and the training are then chosen to meet them.
1-10 of 851
Vincent Primiani
7
4,726 points to level up
Cybersecurity. The Study Group Guy.

Active 6h ago
Joined Apr 29, 2024
New York, NY
Powered by