Activity
Mon
Wed
Fri
Sun
Oct
Nov
Dec
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
Sep
What is this?
Less
More
IA & Automatisations (A-Z)

2.5k members • Free

CISSP Study Group

2.3k members • Free

11 contributions to CISSP Study Group
CISSP Practice Question (Domain 1: Security and Risk Management - AI Exam Guidance)
Your organization adopts an AI-driven system to automate loan approval decisions. Compliance raises concerns that the model may produce discriminatory outcomes against protected groups. As the CISO advising leadership, what is the MOST appropriate FIRST step? A. Implement explain ability tooling to interpret model decisions B. Establish AI governance with bias assessment and accountability for automated decisions C. Retrain the model on a more representative dataset D. Add a human reviewer to approve all model-rejected applications Come back for the answer tomorrow, or study more now!
0 likes • Jun 11
B
CISSP Practice Question (Domain 8: Software Development Security - AI Exam Guidance)
Your organization wants to integrate a third-party pre-trained ML model into an internal application. The vendor provides the model weights but no documentation on the training data sources. As the security lead, what is the MOST appropriate action BEFORE integration? A. Run the model in an isolated sandbox and monitor its behavior B. Require a software bill of materials covering the model and its provenance C. Scan the model file for embedded malware before deployment D. Limit the model's runtime permissions to read-only data access Come back for the answer tomorrow, or study more now!
0 likes • Jun 5
B.
CISSP Practice Question (Domain 7: Security Operations - AI Exam Guidance)
Your organization integrates an AI engine into its SOAR platform to auto-execute containment actions on flagged hosts. During a coordinated attack, the AI quarantines a critical production server, causing an outage. As the SOC manager, what is the MOST appropriate corrective action? A. Disable AI-driven automation and revert to fully manual response B. Define human-approval gates for high-impact automated actions C. Lower the AI's confidence threshold to reduce false containments D. Restrict automated containment to non-production network segments Come back for the answer tomorrow, or study more now!
0 likes • May 29
B
CISSP Practice Question (Domain 3: Security Architecture and Engineering - AI Exam Guidance)
Your organization is deploying a customer-facing chatbot powered by a third-party LLM. The product team wants to connect it directly to the order management database to answer real-time inventory questions. As the security architect, what is the BEST design control? A. Implement input validation to block prompt injection attempts B. Place an API gateway with strict allow-listed queries between the LLM and the database C. Require TLS 1.3 for all traffic between the chatbot and backend systems D. Deploy a WAF tuned for LLM-specific attack signatures Come back for the answer tomorrow, or study more now!
0 likes • May 27
B
CISSP Practice Question (Domain 5: Identity and Access Management - AI Exam Guidance)
Your organization deploys an autonomous AI agent that queries multiple internal data repositories to generate executive reports. The development team requests broad read access "so the model can learn what's relevant." As the security architect, what is the MOST appropriate approach? A. Grant read-only access to all repositories and log every query for review B. Provision a non-human identity with least-privilege, task-scoped entitlements C. Route all agent queries through a human-approved request workflow D. Use the developer's service account credentials for traceability Come back for the answer tomorrow, or study more now!
1 like • May 17
B After reflexion
1-10 of 11
Nono Bon
2
14 points to level up
@nono-bon-5305
I am a cybersecurity analyst since 10 years

Active 5h ago
Joined Jan 5, 2025
Powered by