Cybersecurity & Risk Flashcards
7 cards from real CAIC practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Cybersecurity & Risk flashcards as text
Which type of attack attempts to determine whether a specific individual's data was used in training an AI model?
Answer: Membership inference attack
Membership inference attacks query a model to infer whether a given data point was part of its training set.
Which EU regulation directly imposes mandatory risk classification and conformity requirements on AI systems used in high-risk contexts such as credit scoring and law enforcement?
Answer: EU AI Act
The EU AI Act classifies AI systems by risk tier and mandates conformity assessments, transparency, and human oversight for high-risk uses.
What is the key difference between 'AI safety' and 'AI security' as risk domains?
Answer: AI safety focuses on unintended harmful outcomes from AI behavior; AI security focuses on deliberate attacks by adversaries
AI safety addresses unintended harms from flawed design or misalignment, while AI security addresses intentional exploitation by adversaries.
A red team discovers that a deployed LLM will follow harmful instructions if they are wrapped in a fictional roleplay framing. This vulnerability is best categorized as:
Answer: Jailbreaking via prompt injection
Roleplay-based prompt injection is a jailbreaking technique that bypasses safety guardrails through fictional reframing.
Which risk management strategy involves transferring AI-related financial risk exposure to a third party?
Answer: Risk transfer
Risk transfer, such as through cyber insurance or contractual liability clauses, shifts financial consequences of AI risks to another party.
An AI consultant reviewing a healthcare AI system recommends implementing 'human-in-the-loop' oversight. The primary security and risk benefit of this control is:
Answer: It ensures a human can catch and override erroneous or harmful AI decisions before they cause harm
Human-in-the-loop oversight provides a critical safety check that can catch and stop harmful AI outputs before they impact patients.
When conducting a risk assessment for an AI system, which asset is typically considered the most sensitive and requires the strongest access controls?
Answer: The training dataset containing personal or proprietary information
Training datasets often contain sensitive personal or proprietary information and are the primary target for data theft and poisoning attacks.