Which of the following BEST represents a combination of quantitative and qualitative metrics that can be used to comprehensively evaluate AI transparency?
An organization implementing a large language model (LLM) application notices significant and unexpected cost increases due to excessive computational resource usage. Which vulnerability is MOST likely in need of mitigation?
An organization develops and implements an AI-based plug-in for users that summarizes their individual emails. Which of the following is the GREATEST risk associated with this application?
Within an incident handling process, which of the following would BEST help restore end-user trust in an AI system?
Which of the following strategies is the MOST effective way to protect against AI data poisoning?
Which of the following should be the PRIMARY consideration for an organization concerned about liabilities associated with unforeseen behavior from agentic AI systems?
A programmer suspects an AI system is inferring sensitive user information. What is the BEST action?
A newly hired programmer suspects that the organization’s AI solution is inferring users’ sensitive information and using it to advise future decisions. Which of the following is the programmer’s BEST course of action?
What is the GREATEST concern when a vendor enables generative AI features for an organization’s critical system?
Which of the following BEST addresses risk associated with hallucinations in AI systems?
An organization is designing an AI-based credit risk assessment system that will integrate with sensitive financial datasets. Which of the following would BEST support the implementation of security-by-design principles in the AI system’s architecture?
Which testing technique is BEST for determining how an AI model makes decisions?
Which of the following BEST describes the role of risk documentation in an AI governance program?
A retail organization implements an AI-driven recommendation system that utilizes customer purchase history. Which of the following is the BEST way for the organization to ensure privacy and comply with regulatory standards?
Which of the following BEST ensures AI components are validated as part of disaster recovery testing?
An organization's CIO provided the AI steering committee with a list of AI technologies in use and tasked them with categorizing the technologies by risk. Which of the following should the committee do FIRST?
Which of the following is the MOST effective use of AI-enabled tools in a security operations center (SOC)?
An organization plans to apply an AI system to its business, but developers find it difficult to predict system results due to lack of visibility to the inner workings of the AI model. Which of the following is the GREATEST challenge associated with this situation?
Which of the following is the MOST effective way to identify and address security risk in an AI model?
Implementing which of the following would MOST effectively address bias in generative AI models?
Which of the following MOST effectively addresses bias in generative AI models?
A data scientist creating categories and training an algorithm on large data sets is performing which learning technique?
When evaluating a third-party AI service provider, which master services agreement (MSA) provision is MOST critical for managing security risk?
An organization plans to use an open-source foundational AI model. Which of the following is MOST important for the AI governance committee to consider when approving its use?
An organization is deploying a large language model (LLM) and is concerned that input manipulations may compromise its integrity. Which of the following is the MOST effective way to determine an acceptable risk threshold?
An automotive manufacturer uses AI-enabled sensors on machinery to monitor variables such as vibration, temperature, and pressure. Which of the following BEST demonstrates how this approach contributes to operational resilience?
The PRIMARY purpose of adopting and implementing AI architecture within an organizational AI program is to:
For a life insurance company deploying AI for fraud detection, which factor is MOST critical?
When deriving statistical information from AI systems, which source of risk is MOST important to address?
An organization is implementing AI agent development across engineering teams. What should AI-specific training focus on?
When robust input controls are not practical on a large language model (LLM) to prevent prompt injection attacks from external threats, which of the following would be the BEST compensating control to address the risk?
Which of the following is MOST important to monitor in order to ensure the effectiveness of an organization’s AI vendor management program?
A global organization has experienced multiple incidents of staff copying confidential data into public chatbots and acting on the model outputs. Which of the following is MOST important to reduce short-term risk when launching an AI security awareness initiative?
Which of the following would BEST help to prevent the compromise of a facial recognition AI system through the use of alterations in facial appearance?
A health services organization is developing a proprietary generative AI chatbot to assist patients with medical devices. Which of the following should be the organization’s HIGHEST priority?
After implementing a third-party generative AI tool, an organization learns about new regulations related to how organizations use AI. Which of the following would be the BEST justification for the organization to decide not to comply?
Which of the following would BEST help an organization align its AI initiatives with business objectives?
Which of the following BEST ensures the integrity of data sets used to train AI models?
A SaaS-based LLM system has risks including prompt injection, data poisoning, and model exfiltration. What is the BEST way to ensure consistent risk treatment?
Which of the following is BEST for analyzing true positives, true negatives, false positives, and false negatives produced by an AI model?
When an attacker uses synthetic data to reverse engineer an organization’s AI model, it is an example of which of the following types of attack?
The PRIMARY benefit of implementing moderation controls in generative AI applications is that it can:
When addressing privacy concerns related to AI systems, which of the following is the GREATEST significance of user consent for an organization?
Which of the following is a key risk indicator (KRI) for an AI system used for threat detection?
Which of the following strategies BEST ensures generative AI tools do not expose company data?
Which of the following AI data life cycle phases presents the GREATEST inherent risk?
An aerospace manufacturing company that prioritizes accuracy and security has decided to use generative AI to enhance operations. Which of the following large language model (LLM) adoption plans BEST aligns with the company’s risk appetite?
Which of the following should be the PRIMARY objective of implementing differential privacy techniques in AI models leveraging fraud detection systems?
Which of the following mitigation control strategies would BEST reduce the risk of introducing hidden backdoors during model fine-tuning via third-party components?
An AI system that supports critical processes has deviated from expected performance and is producing biased outcomes. Which of the following is the BEST course of action?
How can an organization best remain compliant when decommissioning an AI system that recorded patient data?
An organization decides to use an anomaly-based intrusion detection system (IDS) integrated with a generative adversarial network–enabled AI tool. The integrated tool would MOST effectively detect intrusions by leveraging:
Which of the following would MOST effectively obtain ongoing support from stakeholders to align AI initiatives with business objectives?
Which of the following should be done FIRST when developing an acceptable use policy for generative AI?
Which of the following BEST describes how supervised learning models help reduce false positives in cybersecurity threat detection?
Which of the following is the MOST effective strategy for penetration testers assessing the security of an AI model against membership inference attacks?
Which of the following controls would BEST help to prevent data poisoning in AI models?
Which of the following is the MOST effective action an organization can take to address data security risk when using generative AI features in an application?
A vendor switched its chatbot’s AI model without due diligence, causing unethical investment advice. What control BEST prevents this scenario?
A viral video shows a blurry person making claims about a product safety issue. The video has random low-quality sections. This MOST likely represents what threat?
Which of the following security framework elements BEST helps to safeguard the integrity of outputs generated by AI algorithms?
Which of the following should be a PRIMARY consideration when defining recovery point objectives (RPOs) and recovery time objectives (RTOs) for generative AI solutions?
Within an incident handling process, which of the following would BEST help restore end user trust with an AI system?
To ensure ethical and responsible AI use, which AI usage policy metric is MOST important to monitor?