Activity
Mon
Wed
Fri
Sun
Jul
Aug
Sep
Oct
Nov
Dec
Jan
Feb
Mar
Apr
May
What is this?
Less
More

Memberships

CISSP Study Group

2.1k members • Free

115 contributions to CISSP Study Group
CISSP Practice Question (Domain 7: Security Operations - AI Exam Guidance)
Your organization integrates an AI engine into its SOAR platform to auto-execute containment actions on flagged hosts. During a coordinated attack, the AI quarantines a critical production server, causing an outage. As the SOC manager, what is the MOST appropriate corrective action? A. Disable AI-driven automation and revert to fully manual response B. Define human-approval gates for high-impact automated actions C. Lower the AI's confidence threshold to reduce false containments D. Restrict automated containment to non-production network segments Come back for the answer tomorrow, or study more now!
1 like • 1d
B. as A would defeat the purpose of the benefits AI has. C lowering the threshold would ultimately not proect against a coordinated attack. D. no solution as the attack was on the production network. B. Is also mandatory for high risk AI systems (and infrastructure) according to the EU-act (Art. 14)
CISSP Practice Question (Domain 3: Security Architecture and Engineering - AI Exam Guidance)
Your organization is deploying a customer-facing chatbot powered by a third-party LLM. The product team wants to connect it directly to the order management database to answer real-time inventory questions. As the security architect, what is the BEST design control? A. Implement input validation to block prompt injection attempts B. Place an API gateway with strict allow-listed queries between the LLM and the database C. Require TLS 1.3 for all traffic between the chatbot and backend systems D. Deploy a WAF tuned for LLM-specific attack signatures Come back for the answer tomorrow, or study more now!
2 likes • 3d
B LLM gateway enforces security policies. And is vendor neutral. A is part of the solution in B. C. Does not prevent dataleakage or injection attempts. D. WAF is insufficiënt as it build for traditional signaturen.
CISSP Practice Question (Domain 2: Asset Security - AI Exam Guidance)
Your data science team plans to fine-tune a large language model using historical customer support transcripts containing PII. The business wants the model deployed organization-wide for internal use. As the CISO, what is the MOST appropriate action BEFORE training begins? A. Encrypt the training dataset at rest and restrict access to data scientists B. Apply data minimization and de-identification techniques to the training corpus C. Require model output filtering to prevent PII disclosure in responses D. Obtain renewed customer consent for the new processing purpose Come back for the answer tomorrow, or study more now!
1 like • 5d
B. “Fine tuning” seems to refer to “training” and so the answer should reflect that. Train the model with anonymous data.
CISSP Practice Question (Domain 7: Security Operations)
During a ransomware incident, the IR team contains affected systems and begins recovery from backups. Mid-recovery, the CFO authorizes paying the ransom to accelerate restoration. As the incident commander, what should you do FIRST? A. Comply with the CFO's directive and coordinate the payment through counsel B. Halt recovery and escalate to the executive crisis team and legal for a documented decision C. Continue recovery from backups and refuse the payment on policy grounds D. Engage law enforcement to evaluate the legality of the ransom payment Come back for the answer tomorrow, or study more now!
3 likes • 15d
B. Payment does not ensure a genuine recovery key. or that no backdoors are left behind. Payment is alwasy discouraged. C. Refusing payment is probably not in your ability. D. In some countries payment may be illegal. A. might be done but after a formal statement from CEO.
CISSP Practice Question (Domain 8: Software Development Security)
A development team adopts a CI/CD pipeline that auto-deploys to production upon passing unit tests. Security testing currently runs weekly in a separate environment. A recent release introduced a SQL injection flaw that reached production. As the application security lead, what is the BEST corrective action? A. Block all deployments until weekly security testing completes B. Integrate SAST and dependency scanning as gating checks within the pipeline C. Require manual security review before each production release D. Shift security testing to a post-deployment runtime monitoring tool Come back for the answer tomorrow, or study more now!
1 like • 17d
B. when deploying new version all tests have to be part of change process. Make sure new versions adhere to all security requirements.
1-10 of 115
Ivo Mulders
4
25points to level up
@ivo-mulders-1100
ISO Netherlands CISM, CISSP, (aspiring) AAISM

Active 1d ago
Joined Oct 28, 2025
Netherlands
Powered by