CISSP Practice Question (Domain 4: Communication and Network Security)
Your organization operates an AI-powered network monitoring tool that inspects encrypted internal traffic using TLS interception. Employees raise privacy concerns, and the legal team warns that interception may violate data protection laws in three operating jurisdictions. What should you do FIRST?
A. Disable TLS interception until legal confirms compliance in all jurisdictions
B. Conduct a legal and privacy impact assessment across all affected jurisdictions
C. Limit interception to high-risk network segments to reduce privacy exposure
D. Notify employees of the monitoring practice and obtain written consent
Come back for the answer tomorrow, or study more now!
0
15 comments
Vincent Primiani
7
CISSP Practice Question (Domain 4: Communication and Network Security)
CISSP Study Group
skool.com/cybersecurity-study-group
Share resources, get advice, and connect with peers studying cybersecurity. Join our CISSP study group and connect with fellow professionals today!
Leaderboard (30-day)
Powered by