Activity
Mon
Wed
Fri
Sun
Mar
Apr
May
Jun
Jul
Aug
Sep
Oct
Nov
Dec
Jan
Feb
What is this?
Less
More

Memberships

CyberMAYnia CAREER

226 members β€’ Free

CISSP Study Group

1.9k members β€’ Free

2 contributions to CISSP Study Group
CISSP Practice Question (Domain 8: Software Development Security)
A company deploys an internal generative AI assistant trained on corporate documents to support developers and analysts. Leadership wants rapid adoption, but legal raises concerns about sensitive data being exposed through prompts and outputs. What is the MOST appropriate control to implement FIRST? A. Log and monitor all AI prompts and responses for misuse B. Classify and restrict training and prompt-accessible data sources C. Add contractual liability clauses for AI misuse to employment agreements D. Conduct periodic audits of AI model accuracy and bias Come back for the answer tomorrow, or study more now!
2 likes β€’ 13d
Keywords are "MOST" and "FIRST"; the requirements come from leadership, AI has been deployed and time is a factor. Legal's concern, which is still relevant, means that sensitive data needs to be protected. Based on this alone, we must look for an answer that is able to identify and protect against the exposure of sensitive data in a proactive or preemptive manner. With this information alone, you can eliminate A, C, and D as these are primarily reactive and do very little to mitigate Legal's concern (i.e., these are not the MOST appropriate). In addition to the above, B most directly addresses the concern. While none of the choices appear to directly impact leadership's "rapid" requirement, B is the only actionable item that would directly and proactively reduce risk. You can't protect what you don't know about, therefore you must FIRST classify the data source(s) for the AI. Then based on the classification, you can ensure only the reviewed/approved data sources are used with the AI (i.e., "restrict training and prompt-accessible data source". There's two ways to answer this one, eliminate the wrong choices or know/determine which one is the most correct.
CISSP Practice Question (Domain 6: Security Assessment and Testing)
A company uses red team exercises to validate detection and response capabilities. After several successful simulations, leadership concludes incident readiness is high. An independent review finds that scenarios are reused and defenders have begun anticipating tactics. Management wants realistic assurance without increasing test frequency. What is the MOST appropriate change to make? A. Rotate red team members to reduce defender familiarity B. Introduce threat informed testing with adaptive scenario design C. Increase reliance on automated attack simulation tools D. Separate detection and response teams during exercises Come back for the answer tomorrow, or study more now!
2 likes β€’ 19d
B
1-2 of 2
@nicholas-murray-2056
Cyber Security Leader, Mentor, Partner - https://www.linkedin.com/in/nickm42/

Active 8h ago
Joined Jan 16, 2026
Powered by