โ† All CAIC Flashcard Decks

Cybersecurity & Risk Flashcards

7 cards from real CAIC practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Cybersecurity & Risk flashcards as text
  1. Which attack vector specifically targets the training data of an AI model to degrade its performance or introduce malicious behavior?

    Answer: Data poisoning

    Data poisoning corrupts training data to manipulate model outputs or degrade accuracy.

  2. An AI system used for loan approvals is found to systematically deny applications from a protected demographic. Which risk category best describes this?

    Answer: Algorithmic bias risk

    Algorithmic bias risk covers discriminatory outcomes embedded in model outputs affecting protected groups.

  3. What is the primary purpose of an AI model's threat model during the risk assessment phase?

    Answer: To identify assets, adversaries, and attack surfaces relevant to the AI system

    A threat model maps the assets, potential adversaries, and attack surfaces to guide security controls.

  4. A prompt injection attack against an LLM-powered customer service bot successfully makes it reveal internal system instructions. Which control would most directly mitigate this?

    Answer: Implementing output filtering and strict prompt sandboxing

    Output filtering and prompt sandboxing limit the model's ability to expose sensitive instructions or be manipulated via crafted inputs.

  5. Under NIST AI RMF, which function focuses on detecting adverse events or anomalies in an AI system's behavior?

    Answer: Measure

    The Measure function in NIST AI RMF focuses on analyzing and monitoring AI risks, including detecting anomalies.

  6. Which technique allows a red team to assess an AI system's robustness by systematically crafting inputs designed to cause misclassification?

    Answer: Adversarial testing

    Adversarial testing involves crafting perturbed inputs to probe model vulnerabilities and misclassification thresholds.

  7. An organization deploys an AI chatbot that retains conversation history across sessions without user consent. Which risk is most prominently violated?

    Answer: Data privacy and retention risk

    Storing user conversation data without consent violates data privacy regulations such as GDPR and CCPA.