CISSP Domain 4.3: Your Encrypted Call Has More Companies In It Than You Think

Sep 21, 2026
 

CISSP Domain 4.3: Your Encrypted Call Has More Companies In It Than You Think

A UK company spent this month running a video hotline where fans could call an AI-generated actress and talk to her in real time. Before the call connects, you hand over a video selfie so a third party can estimate your age. During the call, the system reads your camera feed and the tone of your voice to infer your emotional state — and that part cannot be switched off. Transcripts are kept for up to eight weeks, and the terms say staff and third-party partners may read them.

Nobody was hacked. There is no intrusion in this story, no ransom note, no incident response. Every party in that call path was there legitimately, under contract, doing what it had been hired to do. The whole thing was disclosed in the terms of service and consented to by every caller.

That is precisely what makes it the cleanest Domain 4.3 teaching case I have seen in a year.

Count the companies

The published terms name four parties: the operator itself, an age-verification provider based in Spain, a conversational video platform, and Google's model generating the replies. Everyone else in the path is described only as "US providers."

Read that again. A caller who wanted a complete answer to "who can hear me right now?" could not get one from the document written specifically to answer it. Not because anyone lied — because the disclosure names the parties the operator contracts with directly, and stops there.

Now put your own company in that sentence. Your last all-hands, your last client call, your last recorded interview. Can you name every organisation in that path? In my experience most security teams can name the platform. Rather fewer can name the transcription service the platform subcontracts. Almost nobody can name who that service uses for storage.

Encryption answers the wrong question

Here is the distinction the exam tests, and the one I see separated least cleanly in the cohorts I teach:

Encryption in transit tells you who can INTERCEPT the call. It never tells you who can PROCESS it.

Those are two different questions with two different owners. TLS on the wire means a party sitting between endpoints cannot read the stream. It says nothing at all about the parties sitting at the endpoints — the transcription engine, the model generating responses, the sentiment analyser, the storage layer holding the recording for eight weeks. Every one of those handles the call decrypted, because it has to. That is its job.

A candidate who answers a Domain 4.3 question with "the channel was encrypted" has answered the interception question and left the processing question untouched. On the exam, the processing question is very often the one being asked.

This is why 4.3 is written as implement secure communication channels and then enumerated across voice, video, collaboration, remote access, data communications, and third-party connectivity. That last item is not a footnote. It is where the other five stop being under your sole control.

What a trust boundary actually is

There is a definition floating around study groups that a trust boundary is "where your accountability ends." It is worth being blunt: that is wrong, and believing it will cost you questions.

A trust boundary is a threat-modelling construct. It marks a point where data or control passes into the hands of another party, so that you can reason about what changes at that handoff — what assumptions no longer hold, what controls stop applying, what new failure modes appear. It is an analytical line you draw to find risk.

Your accountability does not stop at that line. Accountability is non-delegable. You can contract out the processing; you cannot contract out being answerable for it. A trust boundary tells you where your control changes hands. It tells you nothing about where your responsibility does, because your responsibility does not move at all.

Get those two apart in your head and a whole category of exam questions becomes readable.

The crossover trap

Domain 4 questions frequently resolve in a different domain, and this incident touches three of them. Knowing which is which is worth more marks than knowing any single fact here:

The question Where it actually lives
Can this personal data cross a border to those US providers? Domain 1 — legal and regulatory, transborder data flow
Where is the data stored, and how is it classified? Domain 2 — asset security
Why are transcripts kept eight weeks and not eighty? Domain 2.4 — data lifecycle and retention
Should the platform trust that vendor's session at all? Domain 3.1 — security models, zero trust
Who can intercept, who can process, who is in the path? Domain 4.3 — secure communication channels

Notice retention lands in 2.4, not 2.5. Asset retention and end-of-life is 2.5; the lifecycle of the data itself is 2.4. And zero trust is a Domain 3 security model — it is not a Domain 4 channel control, however often it gets discussed alongside one.

The trap in a well-written question is offering you an answer that is true but belongs to the neighbouring domain. It reads correctly. It is correctly stated. It is answering a question you were not asked.

What to actually do with this

If you want this to stick past the exam, do the exercise rather than reading it:

  1. Pick one collaboration platform your organisation uses. One. Not all of them.
  2. Write down every party in the path of a single recorded call — the platform, the transcription service, the model provider if there is one, the storage layer, the analytics layer, anyone with a support entitlement that includes recording access.
  3. Mark which names came from a contract and which came from a guess. The guesses are the finding.
  4. For each named party, write what it can DO with the content, not whether the link was encrypted.
  5. Find the longest retention period in the list. That is how long this channel can still produce evidence about a call that everyone involved has forgotten.

In my experience, people stop being able to fill in the table somewhere around step two. That is not a failure of the exercise — that is the finding the exercise exists to produce, and it is the same finding the hotline's terms of service produced when they ran out of names and wrote "US providers."

The uncomfortable part

The company running this hotline did not do anything unlawful. It disclosed the processing, named the vendors it contracts with, published its retention period, and is shutting the service down on schedule. By the standard of most consumer services, that is above average.

And a caller still could not get a complete answer to who was in the path.

If your own organisation would do better, you know because you have the diagram. If you are not sure, you already have your answer.


Listen to the full episode: CISSP Cyber Training Podcast — the incident breakdown, the Domain 4.3 training section, and four exam-style questions built to teach the trap rather than the answer.

Studying for the CISSP? CISSP Cyber Training runs three tiers — Accelerator for self-paced study, Pro for the full question bank and monthly office hours, and the Sprint Cohort for candidates working to a booked exam date.


Shon Gerber, CISSP — Former Commander, 177th Information Aggressor Squadron · Former CISO · Fractional CISO · Founder, CISSP Cyber Training

Source: Viral AI actress' hotline face-scans every caller, watches their mood, BleepingComputer

CISSP Cyber Training Academy Program!

Are you anĀ ambitiousĀ Cybersecurity or IT professionalĀ who wants to take yourĀ careerĀ to a wholeĀ new levelĀ by achieving the CISSP Certification?Ā 

LetĀ CISSP Cyber TrainingĀ help you pass the CISSP Test theĀ first time!

LEARN MORE | START TODAY!