Cybersecurity & Risk Flashcards
7 cards from real CAIC practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Cybersecurity & Risk flashcards as text
What does 'model inversion attack' allow an adversary to do?
Answer: Reconstruct approximate training data from model outputs
Model inversion attacks exploit query access to infer or reconstruct sensitive training data from model responses.
Which of the following is a key principle of 'privacy by design' as applied to AI systems?
Answer: Embedding privacy controls proactively into system architecture from the start
Privacy by design requires integrating data protection mechanisms during the design phase, not as an afterthought.
A financial institution's AI fraud detection model begins performing poorly six months after deployment due to changing fraud patterns. This is an example of:
Answer: Model drift
Model drift occurs when real-world data distributions shift from the training distribution, degrading performance over time.
Which control specifically addresses the risk that a third-party pre-trained model contains a hidden backdoor triggered by a specific input pattern?
Answer: Model provenance verification and red-team testing
Verifying model provenance and conducting adversarial red-team testing help detect backdoors embedded in third-party models.
In the context of AI risk, 'explainability' is important for cybersecurity because:
Answer: It allows security teams to understand and audit why a model flagged or missed a threat
Explainability enables security analysts to audit AI-driven decisions, identify errors, and detect manipulation or bias.
Which approach best protects an AI model's intellectual property and parameters from extraction via repeated querying?
Answer: Rate limiting queries and adding output perturbation
Rate limiting restricts query volume while output perturbation makes it harder to reconstruct model behavior through API queries.
What is the main cybersecurity concern when AI systems are integrated with legacy enterprise software?
Answer: Legacy systems may introduce unpatched vulnerabilities that attackers can exploit via the AI integration layer
Legacy systems often carry unpatched vulnerabilities that attackers can leverage through the new AI integration layer as an attack path.