Activity
Mon
Wed
Fri
Sun
Nov
Dec
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
Sep
Oct
What is this?
Less
More
17 contributions to CISSP Study Group
CISSP Practice Question (Domain 4: Communication and Network Security)
A hospital wing opens in 45 days. Clinical devices from six vendors will join the flat network and each vendor wants remote support access. No network requirements exist for them. What should the security manager do FIRST? A. Isolate every device on its own VLAN B. Set segmentation and remote access requirements by device risk C. Route all vendor support through one monitored jump host D. Scan each device for vulnerabilities before go-live (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
0 likes • 6h
B - Segmentation is right way approach so the each vendor has its own network segmented.
CISSP Practice Question (Domain 2: Asset Security)
A leasing firm wants 400 laptops back in two weeks. IT plans a quick format before shipping. No sanitization standard exists and the laptops held regulated client data. What should the security manager do FIRST? A. Quick format each laptop and keep signed return manifests B. Define sanitization requirements from the data classification held C. Physically destroy every drive before the laptops ship D. Negotiate an extension to allow full disk wiping (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 3d
B: Clear sanitization requirements must be established to protect against legal liabilities in the event of a security breach.
CISSP Practice Question (Domain 3: Security Architecture and Engineering)
An insurer wants an AI assistant to answer questions from policyholder records. To meet a quarter-end demo, the architect puts it inside the application trust zone. No threat model exists for the new flows. What should the security architect do FIRST? A. Segment the assistant into its own zone B. Threat model the new flows and set trust boundaries C. Encrypt every record the assistant can read D. Limit the assistant to read-only access (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 5d
B: Do threat model and identify the threats over the data flow.
Passed at 100Q
Passed today at 100q with about 25 mins left. Thank you to everyone for the advice and resources you've shared. The exam was not exactly easy but also not nearly as hard as I thought it would be. I felt I was doing okay through most of it. There were a handful of questions that I truly didn't know from the CBK. And a handful that were very difficult, but mostly it was applying analytical thinking to the scenarios. One approach that really helped me is to ask myself what the end game is. What is the true outcome the question is asking for. Framing it that way helped me answer a lot of questions correctly. Here are the resources I used and my study journey: I started about a year ago reading the OSG but found it too dense and boring. I then moved onto the Destination Cert guide, which I highly recommend. After completing the Dest Cert I started with the official Wiley test questions but those were too literal and technical. Then I started with QE. I also later bought the Boson exams (good but slightly too technical) and joined the CISSP Study Group on skool.com. I started doing learning sessions through that group which I found really helpful and motivating. A big shout out to everyone who participated. I also started using https://cissp.app which has an excellent question base. One more test bank I want to mention is really excellent, especially when prepping close to the exam are the questions at the end of Andrew Ramdayal's Udemy course: https://www.udemy.com/course/cisspcertification/?couponCode=MT260928G1A The first set, 50 hard questions, are free on YouTube: https://www.youtube.com/watch?v=qbVY0Cg8Ntw Many of you will already know of them. But it was totally worth getting the additional 100 exam questions which accompany his course. In my opinion these were the closest to the actual exam. (I probably used too many test banks and know that others won't choose that path. But I found that each test bank seems to gravitate towards its own favourite topics so overall it was very helpful to train on a number of them. But everyone is different and some people have passed just using one or two test banks.)
1 like • 8d
Awesome and Congratulations 👏👏👏 Thanks for sharing your journey through. Am sure many would be beneficial the materials you mentioned here. Because I remember you on many occasions we discussed various topics in group discussions.
CISSP Practice Question (Domain 5: Identity and Access Management (IAM))
Attackers twice reset executive passwords by phoning the outsourced help desk. The CIO wants phishing-resistant MFA purchased this month. No standard defines how callers prove identity. What should the security manager do FIRST? A. Deploy phishing-resistant MFA for all executives B. Require manager callback approval for every reset C. Retrain help desk staff on social engineering D. Assess the reset process and define identity proofing requirements (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • 9d
D: Validate and verify the identities is crucial.
1-10 of 17
Vishal Kumar
2
3 points to level up
@vishal-kumar-2187
Cyber Security Professional

Active 6h ago
Joined Sep 14, 2026
Chicago
Powered by