1 of 15
Question 1 of 10 · AI Governance and Program Management
Which data should staff be told not to enter into public AI tools?
Public tools may retain or train on inputs, so confidential and personal data should not be entered.
Question 2 of 10 · AI Risk Management
What should be done when an AI vendor cannot provide evidence of security testing?
Absent evidence is a risk to assess, compensate or avoid.
Question 3 of 10 · AI Technologies and Controls
What should be tested before deploying an updated model version?
Regression testing on accuracy, safety and security catches degradation.
Question 4 of 10 · AI Governance and Program Management
What should AI policies say about third-party AI features embedded in existing software?
New AI features in existing tools change data flows and risk, so they need assessment.
Question 5 of 10 · AI Risk Management
What is a key risk in using AI for security operations?
Automation bias leads analysts to accept wrong conclusions; verification remains necessary.
Question 6 of 10 · AI Technologies and Controls
Which attack corrupts training data to change a model's behavior?
Poisoning alters training data to degrade or backdoor a model; extraction and membership inference target a trained model.
Question 7 of 10 · AI Governance and Program Management
What should an AI governance charter define?
A charter sets mandate, scope, authority and decision rights; technical detail belongs elsewhere.
Question 8 of 10 · AI Risk Management
How should AI risks be recorded?
AI risks belong in the enterprise register for visibility and accountability.
Question 9 of 10 · AI Technologies and Controls
Which technique reduces the risk of a model memorizing personal data?
Minimization, de-identification and differentially private training reduce memorization.
Question 10 of 10 · AI Governance and Program Management
What should a security manager do FIRST when asked to secure the organization's use of AI?
Security cannot be applied to systems nobody knows about. An inventory of models, tools and uses, including shadow AI, comes first.
0 of 10
AI Governance and Program Management
AI Risk Management
AI Technologies and Controls