Network Security & Protocols Flashcards
7 cards from real CAIC practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Network Security & Protocols flashcards as text
An AI inference API is exposed via an API gateway. Which rate-limiting strategy BEST prevents model extraction attacks through repeated queries?
Answer: Token bucket with per-API-key quotas and anomaly detection
Per-API-key token bucket limiting with anomaly detection catches extraction attempts even when attackers rotate IPs while staying within per-IP limits.
Which network protocol vulnerability allows an attacker to intercept AI API calls on a shared network by broadcasting fake MAC address associations?
Answer: ARP poisoning
ARP poisoning floods the local network with fake ARP replies, associating the attacker's MAC with a legitimate IP to intercept traffic on the LAN.
A zero-trust network architecture for AI workloads requires which core principle when a service requests access to a model endpoint?
Answer: Verify identity and authorization explicitly for every request
Zero trust mandates explicit verification of identity, device health, and authorization for every request regardless of network location.
Which TLS configuration weakness allows a downgrade attack that could expose AI API traffic encrypted with weak ciphers?
Answer: Supporting TLS 1.0/1.1 alongside TLS 1.3
Keeping legacy TLS versions enabled allows attackers to force negotiation of weaker protocol versions with exploitable vulnerabilities like POODLE or BEAST.
An AI company deploys a BGP-announced IP range for its inference endpoints. What attack could cause global traffic to be rerouted to an adversary's network?
Answer: BGP route hijacking
BGP route hijacking involves announcing more-specific or false routes that cause internet routers to send traffic intended for the victim to the attacker's infrastructure.
Which security control detects when an AI service's network traffic deviates significantly from its established baseline behavior?
Answer: Network anomaly detection / behavioral analytics
Network anomaly detection systems learn normal traffic patterns and alert on deviations such as unusual data volumes, new destinations, or unexpected protocols.
HTTP/2 multiplexing introduces which security risk compared to HTTP/1.1 for AI API gateways?
Answer: Stream-based attacks like HTTP/2 rapid reset that can overwhelm servers
HTTP/2 rapid reset attacks exploit stream multiplexing to send and cancel thousands of requests per second, bypassing traditional rate limiting and causing DoS.