Activity
Mon
Wed
Fri
Sun
Feb
Mar
Apr
May
Jun
Jul
Aug
Sep
Oct
Nov
Dec
What is this?
Less
More

Memberships

CyberMAYnia CAREER

147 members • Free

CyberMAYnia Club

58 members • Free

GovTech Community (Free)

17.1k members • Free

The Cyber Community

7.2k members • Free

CISSP Study Group

1.8k members • Free

102 contributions to CISSP Study Group
CISSP Practice Question (Domain 2: Asset Security / Data Governance)
A company uses a third party AI service to summarize internal incident reports for executives. Reports include sensitive employee and investigation details. The vendor states data may be retained temporarily to improve model performance. Legal and HR raise concerns, but leadership values insight speed. What is the MOST appropriate action to take FIRST? A. Encrypt all reports before submission to the AI service B. Perform a data classification and usage review for the AI workflow C. Require the vendor to sign stricter confidentiality clauses D. Limit AI access to only closed incident reports Come back for the answer tomorrow, or study more now!
0 likes • 3d
B.
Masterclass with May Brooks on the 11th! 7PM UAE
We’re excited to invite the Study Group to another masterclass with May Brooks on the 11th, 7PM UAE As always, registration is free for Study Group members. These sessions have been a great opportunity to go deeper on key concepts and get May’s perspective and corrections in real time. As always free for Study Group members, you can sign up here. Looking forward to seeing you there!
Poll
26 members have voted
1 like • 4d
Can't make it due to time constraints. Conflicts with Church.
CISSP Practice Question (Domain 7: Security Operations)
An organization deploys an AI based alerting system that automatically suppresses repeated low severity security alerts to reduce analyst fatigue. During a later breach investigation, leadership questions whether suppressed alerts should have been retained. What is the MOST appropriate governance concern the security manager should address FIRST? A. Accuracy and tuning thresholds of the AI detection model B. Alignment of alert suppression with evidence retention requirements C. Analyst training on interpreting AI generated alerts D. Cost effectiveness of the AI system compared to manual review
0 likes • 4d
B.
CISSP Practice Question (Domain 3: Security Architecture and Engineering)
A financial institution implements a workflow system where users submit transactions, an application service validates them, and a separate approval service finalizes execution. Auditors require proof that users cannot bypass the workflow or modify transactions directly in the database. What is the MOST appropriate architectural control to meet this requirement? A. Mandatory access control enforced at the database layer B. Constrained interfaces enforcing well formed transactions C. Role based access control with least privilege assignments D. Dual control requiring two administrators for approvals Come back for the answer tomorrow, or study more now!
0 likes • 5d
B
CISSP Practice Question (Domain 6: Identity and Access Management)
A company integrates a third party SaaS platform with its internal systems using single sign on. During review, security finds the vendor provisions user roles automatically based on email domain, without management approval. The business values rapid onboarding. What is the MOST appropriate action for the security manager to take FIRST? A. Disable SSO integration until manual approvals are enforced B. Require documented access approval and role assignment controls C. Increase monitoring and audit logging for SaaS user activity D. Conduct a penetration test against the SaaS access controls Come back for the answer tomorrow, or study more now!
0 likes • 6d
B
1-10 of 102
Alton Butler
3
22points to level up
@alton-butler-7209
Just wanting to learn and pass the CISSP.

Active 2d ago
Joined Jul 7, 2024
Powered by