Activity
Mon
Wed
Fri
Sun
May
Jun
Jul
Aug
Sep
Oct
Nov
Dec
Jan
Feb
Mar
What is this?
Less
More

Memberships

The Cyber Community

8.3k members • Free

CyberMAYnia CAREER

363 members • Free

CISSP Study Group

2k members • Free

84 contributions to CISSP Study Group
CISSP Practice Question (Domain 2: Asset Security - AI Exam Guidance)
A financial services firm acquires a pre-trained ML model from a third-party vendor for fraud detection. During onboarding, the security team discovers the vendor cannot provide documentation on the origin of the training dataset. What should the CISO address FIRST? A. Commission an independent bias audit before production deployment B. Classify the model and its training data as high-value intellectual property C. Assess whether the undocumented data sourcing introduces unmanageable supply chain risk D. Require the vendor to retrain the model using only internally sourced datasets Come back for the answer tomorrow, or study more now!
1 like • 6h
C is appropriate.As there is no documentation, assessment is great way to start.
CISSP Practice Question (Domain 3: Security Architecture and Engineering)
An architect proposes implementing end-to-end encryption for all internal microservice communications. The SOC team warns this will eliminate their ability to inspect east-west traffic for lateral movement detection. Both teams escalate to you. What is the BEST course of action? A. Prioritize encryption and accept reduced network visibility as residual risk B. Reject encryption to preserve the SOC's detection capabilities C. Implement encryption with TLS termination points that allow authorized inspection D. Defer the decision until a formal threat model evaluates both risks Come back for the answer tomorrow, or study more now!
1 like • 3d
C looks appropriate with balancing both aspect encryption and inspection
CISSP Practice Question (Domain 1: Security and Risk Management)
Your organization acquires a competitor and inherits their customer database containing PII subject to GDPR. The integration team wants to merge both databases immediately to eliminate duplicate customer records. The acquired company's privacy notices did not disclose data sharing with third parties. What should you do FIRST? A. Obtain updated consent from the acquired company's customers before merging B. Conduct a data protection impact assessment on the proposed database merge C. Proceed with the merge using the acquiring company's existing privacy framework D. Engage the DPO to determine whether a lawful basis for processing exists under the new entity Come back for the answer tomorrow, or study more now!
1 like • 5d
D looks relevant to sure about lawful reason
CISSP Practice Question (Domain 6: Security Assessment and Testing)
Your organization passes its annual SOC 2 Type II audit with no findings. Two months later, a penetration test reveals a critical vulnerability in a customer-facing application that has existed for over a year. The board questions why the audit missed it. What is the BEST explanation? A. The penetration testing firm used more advanced techniques than the SOC 2 auditors B. SOC 2 evaluates control design and operating effectiveness, not technical vulnerability discovery C. The audit scope was improperly defined and should have included application testing D. The auditors failed to meet professional due diligence standards Come back for the answer tomorrow, or study more now!
1 like • 6d
B looks appropriate as SOC 2 for control effectiveness
Strong vs Best changes the answer option completly ?
A financial institution is implementing a new authentication system for its high-security online banking platform. Which of the following combinations BEST represents (strong vs best ) multi-factor authentication approach using two distinct authentication factors? Options: - Combining a smart card and a password Best - Requiring a USB security key and a one-time password (OTP) Strong - Using a password and a security question - Implementing facial recognition and a PIN
0 likes • 6d
B looks appropriate
1-10 of 84
Dj Sahoo
4
43points to level up
@dj-sahoo-9937
Dj

Active 6h ago
Joined Dec 12, 2025
Powered by