Cybersecurity & Risk Flashcards
7 cards from real CAIC practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Cybersecurity & Risk flashcards as text
Which framework specifically provides guidance for managing risks unique to AI systems throughout their lifecycle, published by NIST?
Answer: NIST AI RMF 1.0
NIST AI RMF 1.0 (AI Risk Management Framework) is specifically designed to address AI-specific risks across the full lifecycle.
An attacker adds imperceptible pixel-level noise to a stop sign image, causing an autonomous vehicle's AI to misclassify it as a speed limit sign. This is called:
Answer: Adversarial example attack
Adversarial example attacks craft minimal perturbations to inputs that reliably fool a model's classification.
Which of the following best describes 'differential privacy' as used in AI systems?
Answer: Adding calibrated statistical noise to data or outputs to prevent individual privacy leakage
Differential privacy adds mathematically calibrated noise so that individual records cannot be identified from model outputs or aggregate statistics.
In AI supply chain security, which risk is introduced when using open-source model repositories without verification?
Answer: Malicious actors may publish tampered models with embedded backdoors or trojans
Unverified open-source models may contain backdoors, data exfiltration hooks, or trojans planted by malicious contributors.
A company uses an AI model to screen resumes. After deployment, employees notice it rarely selects candidates from certain universities. The FIRST step an AI consultant should recommend is:
Answer: Conduct a bias audit to quantify and trace the source of the disparity
A bias audit first quantifies the disparity and identifies whether it stems from biased training data, features, or model design.
Which security practice ensures that an AI model's behavior can be audited and its decision trail reconstructed after an incident?
Answer: Comprehensive logging and audit trails of inputs, outputs, and model versions
Comprehensive logging of inputs, outputs, and model versions enables post-incident forensic analysis and accountability.
When assessing residual risk after security controls are applied to an AI system, the risk consultant should compare it against:
Answer: The organization's defined risk appetite and tolerance thresholds
Residual risk must be evaluated against the organization's risk appetite to determine whether it is acceptable or requires further treatment.