CISSP Practice Question (Domain 3: Security Architecture and Engineering)
An insurer wants an AI assistant to answer questions from policyholder records. To meet a quarter-end demo, the architect puts it inside the application trust zone. No threat model exists for the new flows. What should the security architect do FIRST?
A. Segment the assistant into its own zone
B. Threat model the new flows and set trust boundaries
C. Encrypt every record the assistant can read
D. Limit the assistant to read-only access
(Explain your answer for more points in the comments!)
Come back for the answer tomorrow, or study more now!
3
14 comments
Vincent Primiani
7
CISSP Practice Question (Domain 3: Security Architecture and Engineering)
CISSP Study Group
skool.com/cybersecurity-study-group
Share resources, get advice, and connect with peers studying cybersecurity. Join our CISSP study group and connect with fellow professionals today!
Leaderboard (30-day)
Powered by