Activity
Mon
Wed
Fri
Sun
Oct
Nov
Dec
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
Sep
What is this?
Less
More
CISSP Study Group

2.3k members • Free

123 contributions to CISSP Study Group
CISSP Practice Question (Domain 2: Asset Security)
A cloud migration reveals thousands of unlabeled legacy files containing mixed customer and internal data. The project sponsor wants to bulk-encrypt everything and proceed to meet the cutover date. What should the data governance lead do FIRST? A. Classify the data according to the organizational scheme B. Encrypt all files at the highest protection level C. Identify data owners to assign accountability D. Apply retention policies to purge obsolete records (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!
1 like • Jul 16
C. For datagovernance prioriteit is accountability.
CISSP Practice Question (Domain 1: Security and Risk Management - AI Exam Guidance)
Your company plans to adopt a third-party AI vendor to process regulated customer data. The vendor offers strong contractual indemnification but declines to share model documentation. What should the security leader do FIRST? A. Negotiate stronger audit rights into the contract B. Perform a vendor risk assessment against organizational risk appetite C. Require the vendor to obtain independent AI certification D. Pilot the tool with anonymized data to evaluate performance
1 like • Jul 15
B. A. seems fruitless as vendor already declined sharing. C. Will give Some security but will not add to explainability of the model. D. Seems like “hit and miss”. Doing this will not guarentee you will find what you are looking for.
CISSP Practice Question (Domain 6: Security Assessment and Testing - AI Exam Guidance)
Your organization deploys a customer-facing AI model that passed standard penetration testing. Leadership wants assurance the model itself cannot be manipulated or stolen. As the security assessment lead, what is the MOST appropriate NEXT step? A. Commission AI red teaming for evasion and model extraction attacks B. Repeat penetration testing with expanded application scope C. Review the vendor's secure development attestation D. Enable runtime anomaly monitoring on model outputs Come back for the answer tomorrow, or study more now!
1 like • Jul 7
A. AI read teaming is specifically intented for detecting theft and manipulation in AI. B is "more of the same". It is not tailored to AI threats. C. A review is useful but does not test or gaurentee the actual AI. D. Is a reactive measure. while pentesting is a proactive measure.
CISSP Practice Question (Domain 5: Identity and Access Management - AI Exam Guidance)
An AI scheduling agent needs calendar and email access for all executives. The vendor requests a single privileged service account to simplify deployment before next month's rollout deadline. As the IAM lead, what is the MOST appropriate action? A. Approve the account with session recording enabled B. Issue scoped non-human identities per function with credential rotation C. Delay rollout until the vendor supports federated authentication D. Grant access but restrict it to business hours only Come back for the answer tomorrow, or study more now!
0 likes • Jul 3
B.
CISSP Practice Question (Domain 4: Communication and Network Security - AI Exam Guidance)
Your organization runs a high-value AI model training environment on the same internal network segment as general corporate workstations. A risk assessment flags the shared segment as a concern. As the network security architect, what is the BEST control to implement? A. Deploy AI-driven network detection and response to monitor the segment B. Microsegment the training environment to isolate it from the corporate network C. Encrypt all traffic to and from the training environment D. Place an intrusion prevention system at the segment boundary Come back for the answer tomorrow, or study more now!
0 likes • Jun 14
B
1-10 of 123
Ivo Mulders
4
18 points to level up
@ivo-mulders-1100
ISO Netherlands CISM, CISSP, (aspiring) AAISM

Active 29d ago
Joined Oct 28, 2025
Netherlands
Powered by