ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
Your team is integrating a machine-learning fraud detector into an online payment service. The model is retrained weekly using transactions collected in production. To reduce the likelihood that an attacker can inject poisoned samples during this process without adding significant latency to inference, which architectural control is most appropriate?
Deploy a runtime adversarial-example detector at the prediction API to block anomalous input queries.
Adopt a federated learning approach so each client device contributes updates directly to the shared model without central preprocessing.
Encrypt all trained model artifacts at rest with AES-256 keys stored in a hardware security module.
Route production transaction logs through an access-controlled staging pipeline where data is validated and digitally signed before offline model training occurs.
Training-data poisoning targets the learning pipeline, not the deployed model. The most effective architectural mitigation is to decouple model training from the production environment, move it to a controlled offline pipeline, and require that any data entering this pipeline be rigorously validated and cryptographically signed. This prevents untrusted or malicious records from being incorporated during retraining. Encrypting model files protects confidentiality but does not stop tainted data from influencing the model. Federated learning can actually broaden the attack surface because model updates come from many endpoints and are harder to verify. Runtime adversarial example detection addresses inference-time manipulation, not poisoning of the training set.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is training-data poisoning in machine learning?
Open an interactive chat with Bash
How does digitally signing and validating data prevent attacks in machine learning pipelines?
Open an interactive chat with Bash
Why is federated learning less secure in certain scenarios compared to centralized pipelines?
Open an interactive chat with Bash
What is training-data poisoning in machine learning?
Open an interactive chat with Bash
Why is an offline pipeline important for secure model training?
Open an interactive chat with Bash
How does cryptographic signing protect the training pipeline?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Architecture and Design
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .