Activity
Mon
Wed
Fri
Sun
May
Jun
Jul
Aug
Sep
Oct
Nov
Dec
Jan
Feb
Mar
What is this?
Less
More

Memberships

CISSP Study Group

2k members • Free

72 contributions to CISSP Study Group
OFFICIAL ISC2 AI security exam guidance doc
ISC2 published this yesterday. It maps out exactly how AI security concepts show up across the CISSP exam. This is NOT a new exam outline. The current outline (April 2024) already has AI baked in. But this document spells out the specifics so you know what to expect. The big picture: AI isn't a separate topic. It's woven into everything from risk management (Domain 1) to software development security (Domain 8). A few things that stood out to me: - You need to know about protecting training data and model weights (Domain 2) - Prompt injection and adversarial attacks are fair game (Domain 3) - AI red teaming is now part of security testing (Domain 6) - Managing identities for AI agents and service accounts - least privilege still applies (Domain 5) - Model drift and AI in the SOC are covered in operations (Domain 7) If you're studying right now, don't panic. Most of this maps to concepts you already know -- just applied to AI systems. But you should absolutely be familiar with terms like data poisoning, adversarial attacks, algorithmic bias, model drift, and prompt injection. On our end we're going to keep weaving more AI-focused questions into the https://cissp.app and bringing more of this into our study group discussions. I attached the PDF if you want to read the full thing.
1 like • 1d
Great find and explanation on the domains.
CISSP Practice Question (Domain 3: Security Architecture and Engineering)
An architect proposes implementing end-to-end encryption for all internal microservice communications. The SOC team warns this will eliminate their ability to inspect east-west traffic for lateral movement detection. Both teams escalate to you. What is the BEST course of action? A. Prioritize encryption and accept reduced network visibility as residual risk B. Reject encryption to preserve the SOC's detection capabilities C. Implement encryption with TLS termination points that allow authorized inspection D. Defer the decision until a formal threat model evaluates both risks Come back for the answer tomorrow, or study more now!
0 likes • 1d
D is the best option here.
CISSP Practice Question (Domain 1: Security and Risk Management)
Your organization acquires a competitor and inherits their customer database containing PII subject to GDPR. The integration team wants to merge both databases immediately to eliminate duplicate customer records. The acquired company's privacy notices did not disclose data sharing with third parties. What should you do FIRST? A. Obtain updated consent from the acquired company's customers before merging B. Conduct a data protection impact assessment on the proposed database merge C. Proceed with the merge using the acquiring company's existing privacy framework D. Engage the DPO to determine whether a lawful basis for processing exists under the new entity Come back for the answer tomorrow, or study more now!
1 like • 5d
D. It deals with data privacy.
0 likes • 6d
@Hassan Na Great find. What does Quantum use as a source for the answer ? If there is non, the source may be AI based although Quantum normally states the source for the answer.
CISSP Practice Question (Domain 4: Communication and Network Security)
A remote workforce uses split-tunnel VPN to reduce bandwidth costs. The security team discovers employees are accessing sanctioned SaaS applications directly from home networks, bypassing the corporate proxy and DLP controls. Management values the current performance gains. What is the MOST appropriate recommendation? A. Switch to full-tunnel VPN to route all traffic through corporate controls B. Deploy a cloud-based secure web gateway to enforce policy at the endpoint C. Accept the risk and document the DLP gap as a known exception D. Restrict SaaS access to corporate-managed devices only Come back for the answer tomorrow, or study more now!
0 likes • 8d
B. @Vincent Primiani Great question!
1-10 of 72
Ed Morawski
3
12points to level up
@ed-morawski-4430
Ed

Active 1d ago
Joined Nov 21, 2025
Powered by