Activity
Mon
Wed
Fri
Sun
Jun
Jul
Aug
Sep
Oct
Nov
Dec
Jan
Feb
Mar
Apr
May
What is this?
Less
More

Memberships

CyberMAYnia CAREER

439 members β€’ Free

CISSP Study Group

2.1k members β€’ Free

1 contribution to CISSP Study Group
CISSP Practice Question (Domain 8: Software Development Security)
A development team integrates a generative AI coding assistant that was trained on public repositories. The tool accelerates feature delivery but occasionally references deprecated libraries. Legal warns that AI-generated code may contain license violations or expose proprietary logic if the model was trained on leaked internal code. What should the security manager do FIRST? A. Engage legal counsel to review the AI vendor's training data sources and contractual indemnification clauses B. Implement software composition analysis (SCA) and require all AI-generated code to be digitally signed before commit C. Restrict the AI tool's access to internal repositories and enforce output review through secure-coding peer validation D. Retrain or fine-tune the AI model using only vetted, license-compliant code from approved sources
0 likes β€’ Feb 2
B : SCA consists of legal analysis as well, hence it would be reviewed and rectified (if necessary) before code is merged.
1 like β€’ Feb 2
I asked query to AI, and it shows option C as accurate one. What β€œC” should look like in practice (quick actionable breakdown) If you’re the security manager, β€œC” translates into three immediate controls: 1. Limit tool access to internal assets 2. Enforce output review before merge 3. Define policy + guardrails
1-1 of 1
@sukrut-rayate-5014
Working as product security consultant and looking forward for CISSP certification.

Active 10h ago
Joined Dec 22, 2025
Powered by