Which of the following is the MOST effective action an organization can take to address data security risk when using generative AI features in an application?
Which AI model is BEST suited to ensure explainability in an HR department’s pre-screening tool for candidate resumes?
Which of the following is the MAIN objective of the operational phase of AI life cycle management?
Which of the following is the MOST effective defense against cyberattacks that alter input data to avoid detection by the model?
An organization is reviewing an AI application to determine whether it is still needed. Engineers have been asked to analyze the number of incorrect predictions against the total number of predictions made. Which of the following is this an example of?
Implementing which of the following would MOST effectively address bias in generative AI models?
Which of the following factors is MOST important for preserving user confidence and trust in generative AI systems?
A data scientist creating categories and training an algorithm on large data sets is performing which learning technique?
Which of the following BEST describes the role of risk documentation in an AI governance program?
An organization plans to implement a new AI system. Which of the following is the MOST important factor in determining the level of risk monitoring activities required?
An organization is commissioning a third-party AI system using sensitive data. Which metric is MOST important to consider?
An organization develops and implements an AI-based plug-in for users that summarizes their individual emails. Which of the following is the GREATEST risk associated with this application?
AI developers often find it difficult to explain the processes inside deep learning systems PRIMARILY because:
A financial organization is concerned about AI data poisoning. Which control BEST mitigates this risk?
Which of the following would MOST effectively obtain ongoing support from stakeholders to align AI initiatives with business objectives?
In a new supply chain management system, AI models used by participating parties are interactively connected to generate advice in support of management decision making. Which of the following is the GREATEST challenge related to this architecture?
Within an incident handling process, which of the following would BEST help restore end user trust with an AI system?
A CISO must provide KPIs for the organization’s newly deployed AI chatbot. Which metrics are BEST?
A financial organization relies on AI-based identity verification and fraud detection services. Which of the following BEST integrates AI security risk into the business continuity plan (BCP)?
An organization is deploying an automated AI cybersecurity system. Which of the following would be the MOST effective strategy to minimize human error and improve overall security?
Within an incident handling process, which of the following would BEST help restore end-user trust in an AI system?
Which of the following is the GREATEST benefit of implementing an AI tool to safeguard sensitive data and prevent unauthorized access?
AI developers often find deep learning systems difficult to explain PRIMARILY because:
When robust input controls cannot prevent prompt injections in an LLM, what is the BEST compensating control?
When robust input controls are not practical on a large language model (LLM) to prevent prompt injection attacks from external threats, which of the following would be the BEST compensating control to address the risk?
An aerospace manufacturing company that prioritizes accuracy and security has decided to use generative AI to enhance operations. Which of the following large language model (LLM) adoption plans BEST aligns with the company’s risk appetite?
An organization has requested a developer to apply AI algorithms to existing modules in order to improve customer service quality. At this stage, which of the following should be considered FIRST?
An organization has discovered that employees have started regularly utilizing open-source generative AI without formal guidance. Which of the following should be the CISO’s GREATEST concern?
When evaluating a new AI tool for intrusion prevention, which is MOST important to ensure fit within the existing program architecture?
Which of the following is the GREATEST concern when a vendor enables generative AI features for an organization's critical system?
Which of the following is the MOST effective way to prevent a model inversion attack?
When using AI as part of incident response, which of the following BEST ensures the automation aligns with regulatory and governance obligations?
Which of the following would MOST effectively ensure an organization developing AI systems has comprehensive data classification and inventory management?
Which of the following mitigation control strategies would BEST reduce the risk of introducing hidden backdoors during model fine-tuning via third-party components?
Which of the following is the MOST important consideration when an organization is adopting generative AI for personalized advertising?
Which of the following AI data management techniques involves creating validation and test data?
A global organization experienced multiple incidents of staff pasting confidential data into public chatbots. Which action is MOST important to reduce short-term risk?
Which of the following BEST describes an adversarial attack on an AI model?
An organization implementing an LLM application sees unexpected cost increases due to excessive computational resource usage. Which vulnerability is MOST likely in need of mitigation?
Which defense is MOST effective against cyberattacks that alter input data to avoid detection?
A large corporation has received an influx of sophisticated credential-phishing emails and wants to leverage an AI solution to detect and quarantine these messages before they reach employees. Which of the following blue-team AI features is BEST suited to this task?
When creating a use case for an AI model that provides sensitive decisions affecting end users, which of the following is the GREATEST benefit of using model cards?
Which of the following is a key risk indicator (KRI) for an AI system used for threat detection?
Which of the following methods provides the MOST effective protection against model inversion attacks?
Which phase of the AI data life cycle presents the GREATEST inherent risk?
An aerospace manufacturer prioritizing accuracy and security wants to use generative AI. Which LLM adoption plan BEST aligns with its risk appetite?
Which of the following BEST strengthens information security controls around the use of generative AI applications?
Which of the following controls BEST mitigates the risk of bias in AI models?
During red-team testing of an AI system used to make lending decisions, which of the following techniques BEST simulates a data poisoning attack?
Which of the following is the BEST approach for minimizing risk when integrating acceptable use policies for AI foundation models into business operations?
Which AI data management technique involves creating validation and test data?
Which of the following key risk indicators (KRIs) is MOST relevant when evaluating the effectiveness of an organization’s AI risk management program?
A vendor switched its chatbot’s AI model without due diligence, causing unethical investment advice. What control BEST prevents this scenario?
A data scientist creating categories and training the algorithm on large data sets is an example of which type of AI model learning technique?
Which of the following AI system vulnerabilities is MOST easily exploited by adversaries?
An organization plans to apply an AI system to its business, but developers find it difficult to predict system results due to lack of visibility to the inner workings of the AI model. Which of the following is the GREATEST challenge associated with this situation?
An organization plans to use AI to analyze the shopping patterns of its customers to predict interests and send targeted, customized marketing emails. Which of the following should be done FIRST?
How can an organization best remain compliant when decommissioning an AI system that recorded patient data?
Which of the following should be the PRIMARY consideration for an organization concerned about liabilities associated with unforeseen behavior from agentic AI systems?
A programmer suspects an AI system is inferring sensitive user information. What is the BEST action?
Which of the following is the BEST way to ensure role clarity and staff effectiveness when implementing AI-assisted security monitoring tools?
A viral video shows a blurry person making claims about a product safety issue. The video has random low-quality sections. This MOST likely represents what threat?
An AI system that supports critical processes has deviated from expected performance and is producing biased outcomes. Which of the following is the BEST course of action?
Security and assurance requirements for AI systems should FIRST be embedded in the:
Which of the following strategies is the MOST effective way to protect against AI data poisoning?