Activity
Mon
Wed
Fri
Sun
Apr
May
Jun
Jul
Aug
Sep
Oct
Nov
Dec
Jan
Feb
Mar
What is this?
Less
More

Memberships

GuitarZoom

3.3k members • Free

The Cybersecurity Mentors

58 members • Free

The Cyber Range

1.8k members • $129/m

Agentic AI Trade Skool

300 members • Free

The Cyber Community

8.2k members • Free

Timeless Jump™ Skool

2.1k members • Free

JamFast Guitar Insiders

248 members • $49/month

Mobility & Injury Prevention

191k members • Free

CISSP Study Group

2k members • Free

12 contributions to CISSP Study Group
CISSP Practice Question (Domain 8: Software Development Security)
Your engineering team integrates a third-party AI API that generates dynamic access control policies based on user behavior analytics. During testing, the API occasionally grants excessive permissions that violate least privilege. What should you address FIRST? A. Implement a policy validation layer that enforces least privilege before applying AI-generated rules B. Request the AI vendor to retrain the model to reduce permission over-granting C. Revert to static role-based access control until the AI system is reliable D. Log all AI-generated policy decisions for quarterly audit review Come back for the answer tomorrow, or study more now!
0 likes • Feb 24
A
CISSP Practice Question (Domain 4: Communication and Network Security)
During a cloud migration, your team discovers that sensitive customer data traverses an unencrypted internal network segment between two trusted zones. Operations argues encryption would add latency to time-sensitive transactions. What is the BEST approach? A. Accept the risk since both zones are internally trusted and monitored B. Conduct a risk assessment weighing data sensitivity against performance impact C. Encrypt all internal traffic regardless of performance concerns D. Implement network segmentation to isolate the sensitive data path Come back for the answer tomorrow, or study more now!
0 likes • Feb 18
B
CISSP Practice Question (Domain 1: Security and Risk Management)
An organization deploys an AI system that recommends layoffs and budget cuts based on financial and productivity data. Executives approve its use but do not fully understand its decision logic. The recommendations align with profits but raise ethical and reputational concerns internally. What is the MOST appropriate action for the security leader? A. Require human review of all AI-generated workforce decisions B. Document the risk acceptance and ethical considerations in governance records C. Suspend the AI system until explainability requirements are met D. Conduct a privacy impact assessment focused on employee data Come back for the answer tomorrow, or study more now!
0 likes • Jan 29
A
CISSP Practice Question (Domain 3: Security Architecture and Engineering)
A financial services company needs to share highly sensitive customer transaction data with a third-party analytics provider. The company's legal department mandates that the third-party must be able to perform statistical analysis on the data, but the data must remain encrypted at all times, including while it is being processed by the provider's algorithms to ensure the company never loses control over the plaintext. What is the MOST appropriate cryptographic solution to meet this requirement? A. Symmetric encryption using AES-256 with a managed Key Vault B. Asymmetric encryption using RSA-4096 with Perfect Forward Secrecy C. Homomorphic encryption D. Quantum-resistant cryptography
0 likes • Jan 24
C
CISSP Practice Question (Domain 1: Security and Risk Management)
A business unit deploys an AI agent that autonomously negotiates vendor contracts within predefined spend limits. The agent improves efficiency but occasionally commits the company to unfavorable terms. Executives want to continue using it. What is the MOST appropriate action for the security leader? A. Disable autonomous execution and require human approval for commitments B. Update the organization’s risk register to reflect agent decision authority C. Require explainability reports for every AI-driven contract decision D. Transfer contractual risk to vendors through revised legal language Come back for the answer tomorrow, or study more now!
0 likes • Jan 24
A
1-10 of 12
Wilbert Philippe
2
11points to level up
@wilbert-philippe-2311
Hello everyone!

Active 3d ago
Joined Aug 10, 2024
Powered by