Activity
Mon
Wed
Fri
Sun
Nov
Dec
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
Sep
What is this?
Less
More
10 contributions to CISSP Study Group
CISSP Practice Question (Domain 8: Software Development Security - AI Exam Guidance)
Your organization wants to integrate a third-party pre-trained ML model into an internal application. The vendor provides the model weights but no documentation on the training data sources. As the security lead, what is the MOST appropriate action BEFORE integration? A. Run the model in an isolated sandbox and monitor its behavior B. Require a software bill of materials covering the model and its provenance C. Scan the model file for embedded malware before deployment D. Limit the model's runtime permissions to read-only data access Come back for the answer tomorrow, or study more now!
1 like • Jun 5
B - (Correct Answer) because acquiring the SBOM provides the security lead with insights into all the dependencies of the third-party pre-trained ML model. A - can be a step to follow after B to gain a better understanding of how all these dependencies work together and behave, especially if there are any potential issues, such as vulnerabilities that need to be addressed. Furthermore, in the Software Development Life Cycle (SDLC), particularly in Agentic Development Life Cycle (ADLC), the sequence of actions is integration followed by testing, which corresponds to the sandboxing phase (A). (Here, we are thinking like managers.)
CISSP Practice Question (Domain 5: Identity and Access Management - AI Exam Guidance)
Your organization deploys an autonomous AI agent that queries multiple internal data repositories to generate executive reports. The development team requests broad read access "so the model can learn what's relevant." As the security architect, what is the MOST appropriate approach? A. Grant read-only access to all repositories and log every query for review B. Provision a non-human identity with least-privilege, task-scoped entitlements C. Route all agent queries through a human-approved request workflow D. Use the developer's service account credentials for traceability Come back for the answer tomorrow, or study more now!
0 likes • May 19
A- With "read-only access to all repositories," the AI-agent can read everywhere utilizing its mechanism of self-attention (Ans: NO) C- "Routing all queries through human approval..." is a slow and ineffective process that is also prone to human errors. (Ans: NO) D- "Use the developer's service account credentials for traceability": out of context choice.(Ans: NO) B- (Ans: YES)
Practice Question
A healthcare organization uses a centralized identity management system for user authentication and authorization. The system supports single sign-on (SSO) and multi-factor authentication (MFA). Recently, the security team identified multiple incidents of unauthorized access attempts. During the investigation, it was discovered that compromised user credentials were being used. Which of the following actions would be MOST effective in mitigating this threat? A) Implement behavioral biometrics for continuous authentication. B) Require password complexity and regular password changes. C) Implement adaptive access controls based on user behavior and risk scoring. D) Conduct a company-wide security awareness training on phishing prevention.
0 likes • Apr '25
The exposure of compromised user credentials is frequently attributed to insufficient user awareness of potential security threats like phishing. To tackle this challenge, option D) emerges as the most pertinent solution in this case, empowering users to develop a security-conscious mindset. This proactive approach aligns seamlessly with the measures proposed in option B. Therefore, the most persuasive answer to the question is D).
Practice Question
Which of the following is an essential component of a disaster recovery plan related to personnel? A) Intrusion detection system (IDS) B) Employee training and awareness C) Physical access controls to data centres D) Defining roles and responsibilities during a disaster
3 likes • Apr '25
In the context of the Disaster Recovery Plan (DRP), providing training to individuals and raising their awareness about potential hazards following an unfortunate event is paramount. Subsequently, during these training sessions, specific roles and responsibilities can be assigned. Therefore, the optimal choice is B).
Practice Question
An e-commerce company collects and processes customer data, including payment card information. The company is expanding its operations to new regions with strict data protection laws. As part of its compliance efforts, the security team is tasked with ensuring proper data classification and implementing appropriate controls. While conducting a data classification audit, the team finds multiple unstructured data repositories containing customer information without clear labeling or access restrictions. Which of the following should the team do FIRST to mitigate this risk? A) Apply automated data discovery tools to identify and classify sensitive information. B) Implement data loss prevention (DLP) solutions to monitor and control data movement. C) Enforce access controls and least privilege principles on all data repositories. D) Develop a comprehensive data classification policy and train employees on data handling procedures.
1 like • Apr '25
To mitigate the risks associated with unstructured data that remains unclassified (lacking clear labeling) or accessible without security measures, the initial step should be to D) them.
1-10 of 10
Armand Tamno
2
4 points to level up
@armand-tamno-2523
Computer scientist.

Active 6h ago
Joined Sep 5, 2024
Powered by