Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Isaca AAISM Exam - Topic 1 Question 16 Discussion

An organization deploying an LLM is concerned input manipulations could compromise security. What is the MOST effective way to determine an acceptable risk threshold?
C) Assess the business impact of known threats
A) Deploy real-time logging and monitoring
B) Restrict all inputs containing special characters
D) Implement a static threshold limiting LLM outputs

Isaca AAISM Exam - Topic 1 Question 16 Discussion

Actual exam question for Isaca's AAISM exam
Question #: 16
Topic #: 1
[All AAISM Questions]

An organization deploying an LLM is concerned input manipulations could compromise security. What is the MOST effective way to determine an acceptable risk threshold?

Show Suggested Answer Hide Answer
Suggested Answer: C

AAISM instructs that acceptable risk thresholds must be determined using business impact analysis. This aligns with the broader enterprise risk management principle of defining tolerances based on:

* potential harm

* regulatory exposure

* financial impact

* operational disruption

Monitoring (A) detects attacks but does not set thresholds. Blocking special characters (B) is unrealistic and overly restrictive. Static thresholds (D) ignore business context and practicality.


============================================

Contribute your Thoughts:

0/2000 characters
Santos
2 hours ago
Implementing a static threshold for LLM outputs could be risky too, since it might not adapt to new threats effectively.
upvoted 0 times
...
Deja
5 days ago
Restricting inputs with special characters seems too limiting; I feel like it could hinder functionality more than it helps.
upvoted 0 times
...
Erick
10 days ago
I remember a practice question where we discussed real-time logging and monitoring, but I wonder if that alone is enough to set a risk threshold.
upvoted 0 times
...
Shasta
16 days ago
I think assessing the business impact of known threats might be the best option, but I'm not entirely sure if it covers all scenarios.
upvoted 0 times
...

Save Cancel