← All CAIC Flashcard Decks

Network Security & Protocols Flashcards

7 cards from real CAIC practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Network Security & Protocols flashcards as text
  1. An AI consultant audits an organization's network for SSRF vulnerabilities in their model-serving infrastructure. What is SSRF?

    Answer: Server-Side Request Forgery, where the server is tricked into making requests to internal resources

    SSRF tricks the server into fetching internal resources (cloud metadata endpoints, internal APIs) by manipulating user-supplied URLs processed server-side.

  2. Which protocol is used to dynamically assign and manage IP addresses for AI compute nodes in a data center, and what is its primary security concern?

    Answer: DHCP — rogue server attacks assigning malicious gateway/DNS settings

    DHCP rogue server attacks occur when an attacker's unauthorized DHCP server responds faster than the legitimate one, assigning itself as the default gateway for man-in-the-middle positioning.

  3. What is the role of an IDS (Intrusion Detection System) versus an IPS (Intrusion Prevention System) in protecting AI infrastructure?

    Answer: IDS detects and alerts on threats; IPS detects and actively blocks threats

    An IDS passively monitors and generates alerts, while an IPS sits inline and can automatically drop or block malicious traffic in real time.

  4. An AI SaaS provider must ensure their API clients connect only to legitimate servers and not imposters. Which PKI mechanism provides this assurance?

    Answer: Certificate Authority (CA)-signed certificates with proper hostname validation

    CA-signed certificates with hostname validation confirm the server's identity is vouched for by a trusted third party and matches the expected domain name.

  5. Which network-level technique can an AI platform use to obscure the internal topology of its model-serving infrastructure from external attackers?

    Answer: NAT (Network Address Translation) combined with reverse proxies

    NAT hides internal IP addresses by presenting a single public IP, while reverse proxies mask backend service topology behind a uniform public endpoint.

  6. When designing secure AI API communication, what does 'certificate pinning' protect against?

    Answer: Rogue or compromised Certificate Authorities issuing fraudulent certificates for your domain

    Certificate pinning embeds expected certificate or public key values in the client, rejecting connections even if a CA fraudulently issues a certificate for the server's domain.

  7. An AI company's security team wants to detect data exfiltration of model weights through DNS. Which technique do they need to identify?

    Answer: DNS tunneling (encoding data in DNS query/response payloads)

    DNS tunneling encodes arbitrary data within DNS queries and responses, exploiting the fact that DNS traffic is rarely blocked, to create a covert exfiltration channel.