Activity
Mon
Wed
Fri
Sun
Mar
Apr
May
Jun
Jul
Aug
Sep
Oct
Nov
Dec
Jan
Feb
What is this?
Less
More

Memberships

CISSP Study Group

1.9k members • Free

56 contributions to CISSP Study Group
CISSP Practice Question (Domain 1: Security and Risk Management)
An organization's CISO discovers that a third-party SaaS vendor processing customer PII has been acquired by a foreign company. The acquiring company is headquartered in a jurisdiction with government data access laws that conflict with the organization's regulatory obligations under GDPR. The vendor contract has 18 months remaining. What should the CISO do FIRST? A. Invoke the contract's termination-for-convenience clause and begin immediate vendor transition planning B. Conduct a risk assessment to evaluate the change in data sovereignty exposure and regulatory compliance impact C. Require the vendor to migrate all customer data to data centers located within approved jurisdictions D. Notify the Data Protection Authority and affected customers of the potential cross-border data transfer Come back for the answer tomorrow, or study more now!
0 likes • 10h
B. First impression would be to act. (Migrate, terminate eg). But as a manager take a step back and first check (assess) how big is the risk actually?
CISSP Practice Question (Domain 8: Software Development Security)
A development team integrates a generative AI coding assistant that was trained on public repositories. The tool accelerates feature delivery but occasionally references deprecated libraries. Legal warns that AI-generated code may contain license violations or expose proprietary logic if the model was trained on leaked internal code. What should the security manager do FIRST? A. Engage legal counsel to review the AI vendor's training data sources and contractual indemnification clauses B. Implement software composition analysis (SCA) and require all AI-generated code to be digitally signed before commit C. Restrict the AI tool's access to internal repositories and enforce output review through secure-coding peer validation D. Retrain or fine-tune the AI model using only vetted, license-compliant code from approved sources
0 likes • 1d
D: The issue is that the incorrect data is being used (incl. copy right data as it seems) A. Checking with legal what the contractual indemnification clauses (compensation) might be is not the solution to the problem. B. there is no indication the software is at fault. C. No intenrnal repositories are being used as the case states: "..was trained on public repositories."
Passed!
PASSED. Today I passed at the first try after studying hard!! To help me pass I did the research and did Many exam questions using this app but also 2 different apps. In Total more than 2000 questions. Thanks for your input !!
2 likes • 2d
@Ryan W The offical Wiley testbank (Part of the study material) is very similar as the exam as it uses the same phrasing and depth of dificulty. As for the LearnZapp app (Payed) and Destcert app (Free), I think the Descert is the more difficult one. Because of depth of the questions. I highly recommend these three as there is a large variation in setup, questions, depth, worden etc. which means that if you know these questions you can answer everything (CISSP related).
CISSP Practice Question (Domain 2: Asset Security)
An organization allows multiple business units to deploy their own AI agents using shared enterprise data lakes. Each unit claims ownership of its AI outputs, while data sources remain centrally managed. A dispute arises after an AI-generated report exposes sensitive correlations between departments. What is the MOST appropriate action to take FIRST? A. Reclassify the AI-generated outputs under the highest data sensitivity level B. Clarify and formally assign data ownership and stewardship for AI-derived assets C. Segregate AI workloads by business unit to prevent cross-correlation D. Implement stronger access controls on the shared data lake Come back for the answer tomorrow, or study more now!
0 likes • 3d
B.
CISSP Practice Question (Domain 1: Security and Risk Management)
An organization deploys an AI system that recommends layoffs and budget cuts based on financial and productivity data. Executives approve its use but do not fully understand its decision logic. The recommendations align with profits but raise ethical and reputational concerns internally. What is the MOST appropriate action for the security leader? A. Require human review of all AI-generated workforce decisions B. Document the risk acceptance and ethical considerations in governance records C. Suspend the AI system until explainability requirements are met D. Conduct a privacy impact assessment focused on employee data Come back for the answer tomorrow, or study more now!
0 likes • 6d
A
1-10 of 56
@ivo-mulders-1100
ISO Netherlands

Active 5h ago
Joined Oct 28, 2025
Netherlands
Powered by