โ† All CAIC Flashcard Decks

Cybersecurity & Risk Flashcards

7 cards from real CAIC practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Cybersecurity & Risk flashcards as text
  1. Which type of attack attempts to determine whether a specific individual's data was used in training an AI model?

    Answer: Membership inference attack

    Membership inference attacks query a model to infer whether a given data point was part of its training set.

  2. Which EU regulation directly imposes mandatory risk classification and conformity requirements on AI systems used in high-risk contexts such as credit scoring and law enforcement?

    Answer: EU AI Act

    The EU AI Act classifies AI systems by risk tier and mandates conformity assessments, transparency, and human oversight for high-risk uses.

  3. What is the key difference between 'AI safety' and 'AI security' as risk domains?

    Answer: AI safety focuses on unintended harmful outcomes from AI behavior; AI security focuses on deliberate attacks by adversaries

    AI safety addresses unintended harms from flawed design or misalignment, while AI security addresses intentional exploitation by adversaries.

  4. A red team discovers that a deployed LLM will follow harmful instructions if they are wrapped in a fictional roleplay framing. This vulnerability is best categorized as:

    Answer: Jailbreaking via prompt injection

    Roleplay-based prompt injection is a jailbreaking technique that bypasses safety guardrails through fictional reframing.

  5. Which risk management strategy involves transferring AI-related financial risk exposure to a third party?

    Answer: Risk transfer

    Risk transfer, such as through cyber insurance or contractual liability clauses, shifts financial consequences of AI risks to another party.

  6. An AI consultant reviewing a healthcare AI system recommends implementing 'human-in-the-loop' oversight. The primary security and risk benefit of this control is:

    Answer: It ensures a human can catch and override erroneous or harmful AI decisions before they cause harm

    Human-in-the-loop oversight provides a critical safety check that can catch and stop harmful AI outputs before they impact patients.

  7. When conducting a risk assessment for an AI system, which asset is typically considered the most sensitive and requires the strongest access controls?

    Answer: The training dataset containing personal or proprietary information

    Training datasets often contain sensitive personal or proprietary information and are the primary target for data theft and poisoning attacks.