Activity
Mon
Wed
Fri
Sun
Jul
Aug
Sep
Oct
Nov
Dec
Jan
Feb
Mar
Apr
May
Jun
What is this?
Less
More

Memberships

CISSP Study Group

2.2k members • Free

119 contributions to CISSP Study Group
CISSP Practice Question (Domain 4: Communication and Network Security - AI Exam Guidance)
Your organization runs a high-value AI model training environment on the same internal network segment as general corporate workstations. A risk assessment flags the shared segment as a concern. As the network security architect, what is the BEST control to implement? A. Deploy AI-driven network detection and response to monitor the segment B. Microsegment the training environment to isolate it from the corporate network C. Encrypt all traffic to and from the training environment D. Place an intrusion prevention system at the segment boundary Come back for the answer tomorrow, or study more now!
0 likes • 14d
B
CISSP Practice Question (Domain 1: Security and Risk Management - AI Exam Guidance)
Your organization adopts an AI-driven system to automate loan approval decisions. Compliance raises concerns that the model may produce discriminatory outcomes against protected groups. As the CISO advising leadership, what is the MOST appropriate FIRST step? A. Implement explain ability tooling to interpret model decisions B. Establish AI governance with bias assessment and accountability for automated decisions C. Retrain the model on a more representative dataset D. Add a human reviewer to approve all model-rejected applications Come back for the answer tomorrow, or study more now!
1 like • 17d
B. A is as such does not prevent potential bias. It explains only after the fact. C datasets alone is no guarantee against bias. To prevent bias you also need to look at the algorithm design. D. Only looks at rejections. What about the approved loans. They might have been approved because of the bias.
Provisionally passed the exam
I’m excited to let you all know that I passed the exam today. I’m still pretty overwhelmed am not sure how well I did but I guess it was good enough!
0 likes • 21d
Be proud! Nicely done.
CISSP Practice Question (Domain 8: Software Development Security - AI Exam Guidance)
Your organization wants to integrate a third-party pre-trained ML model into an internal application. The vendor provides the model weights but no documentation on the training data sources. As the security lead, what is the MOST appropriate action BEFORE integration? A. Run the model in an isolated sandbox and monitor its behavior B. Require a software bill of materials covering the model and its provenance C. Scan the model file for embedded malware before deployment D. Limit the model's runtime permissions to read-only data access Come back for the answer tomorrow, or study more now!
0 likes • 22d
B
CISSP Practice Question (Domain 7: Security Operations - AI Exam Guidance)
Your organization integrates an AI engine into its SOAR platform to auto-execute containment actions on flagged hosts. During a coordinated attack, the AI quarantines a critical production server, causing an outage. As the SOC manager, what is the MOST appropriate corrective action? A. Disable AI-driven automation and revert to fully manual response B. Define human-approval gates for high-impact automated actions C. Lower the AI's confidence threshold to reduce false containments D. Restrict automated containment to non-production network segments Come back for the answer tomorrow, or study more now!
3 likes • 29d
B. as A would defeat the purpose of the benefits AI has. C lowering the threshold would ultimately not proect against a coordinated attack. D. no solution as the attack was on the production network. B. Is also mandatory for high risk AI systems (and infrastructure) according to the EU-act (Art. 14)
1-10 of 119
Ivo Mulders
4
21points to level up
@ivo-mulders-1100
ISO Netherlands CISM, CISSP, (aspiring) AAISM

Active 14d ago
Joined Oct 28, 2025
Netherlands
Powered by