โ† All CAIC Flashcard Decks

Network Security & Protocols Flashcards

7 cards from real CAIC practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Network Security & Protocols flashcards as text
  1. An AI model is deployed in a Kubernetes cluster. Which network policy action BEST reduces the attack surface between pods?

    Answer: Default-deny all ingress/egress with explicit allow rules per service

    A default-deny Kubernetes NetworkPolicy forces explicit declaration of allowed traffic flows, implementing least-privilege networking between pods.

  2. Which cryptographic protocol property ensures that past AI API session traffic cannot be decrypted even if the server's private key is later compromised?

    Answer: Perfect Forward Secrecy (PFS)

    PFS uses ephemeral session keys (e.g., ECDHE) so that compromising the long-term private key does not expose previously recorded session traffic.

  3. An AI data pipeline ingests logs via syslog. Which protocol upgrade adds encryption and authentication to protect log integrity?

    Answer: Syslog over TLS (RFC 5425)

    RFC 5425 defines TLS transport for syslog, adding authentication and encryption to prevent log tampering or interception in transit.

  4. What is the security risk of using wildcard TLS certificates (*.example.com) for AI microservice endpoints?

    Answer: Compromise of one service's private key exposes all subdomains

    A single wildcard certificate covers all subdomains, so a key compromise on any one service allows impersonation of every service under that domain.

  5. Which mechanism allows an AI API server to inform clients that it should only be accessed over HTTPS for a specified duration?

    Answer: HTTP Strict Transport Security (HSTS)

    HSTS instructs browsers to automatically use HTTPS for all future requests to the domain for the max-age duration, preventing protocol downgrade attacks.

  6. An adversary uses a slow HTTP attack (Slowloris) against an AI web service. What is the PRIMARY defense?

    Answer: Setting aggressive connection timeouts and limiting concurrent connections per IP

    Slowloris holds connections open by sending partial HTTP headers slowly; aggressive timeouts and per-IP connection limits cause the server to close stalled connections before resources are exhausted.

  7. Which network security concept isolates AI training workloads from production inference traffic using separate virtual networks within the same physical infrastructure?

    Answer: VLAN segmentation

    VLANs create logically separate broadcast domains on shared physical hardware, allowing training and inference workloads to be isolated at Layer 2.