CISSP Practice Question (Domain 3: Security Architecture and Engineering)
Your organization deploys an AI assistant with access to internal knowledge bases containing data classified at multiple sensitivity levels. The system currently returns results regardless of the requestor's clearance level. No access enforcement layer exists between the AI and the data. What is the PRIMARY risk?
A. The AI model may retain sensitive data in its context and leak it to subsequent users
B. Unauthorized information disclosure through the AI bypassing established access controls
C. Excessive query logging creating a secondary repository of classified information
D. Users developing over-reliance on AI responses instead of consulting original sources
Come back for the answer tomorrow, or study more now!
4
18 comments
Vincent Primiani
7
CISSP Practice Question (Domain 3: Security Architecture and Engineering)
CISSP Study Group
skool.com/cybersecurity-study-group
Share resources, get advice, and connect with peers studying cybersecurity. Join our CISSP study group and connect with fellow professionals today!
Leaderboard (30-day)
Powered by