Which of the following is the MOST effective action an organization can take to address data security risk when using generative AI features in an application?
AAISM directs organizations to manage third-party AI risks through contractual and technical controls that explicitly govern data use, retention, training/fine-tuning, isolation, and deletion. The most effective data-security action when consuming generative AI features is to require enforceable opt-out provisions that prohibit the provider from using the organization's data for training or secondary purposes and that mandate retention limits and secure deletion. Third-party audit reports (A) provide assurance but do not guarantee provider behavior for your specific data; awareness policies (B) are necessary but insufficient to control external processing; IP ownership guidelines (D) address legal rights, not data-security risk.
===========
When addressing privacy concerns related to AI, what is the GREATEST significance of user consent?
AAISM clarifies that the primary regulatory purpose of user consent is to provide lawful authorization for processing personal data, including use in AI models.
Consent does not directly prevent unauthorized access (A). Deletion rights (B) relate to data subject rights but are not the purpose of consent. Bias detection (D) is unrelated.
============================================
What is the GREATEST benefit of performing AI security risk assessments?
AAISM emphasizes that the primary value of AI security risk assessments is prioritizing risks based on likelihood, impact, and business relevance.
Updating the register (A) is administrative. Privacy controls (B) are one category of mitigation. Funding (D) is possible but not the primary purpose.
============================================
A viral video shows a blurry person making claims about a product safety issue. The video has random low-quality sections. This MOST likely represents what threat?
AAISM defines deepfakes as manipulated media where individuals appear in synthetic or altered video/audio. Indicators include:
* blurred or inconsistent facial rendering
* mismatched frames
* low-quality or distorted transitions
These characteristics match the scenario provided.
Hallucinations (A) relate to model outputs, not video manipulation. Drift (B) affects model performance. Poisoning (C) affects training data, not video content.
An organization deploying an LLM is concerned input manipulations could compromise security. What is the MOST effective way to determine an acceptable risk threshold?
AAISM instructs that acceptable risk thresholds must be determined using business impact analysis. This aligns with the broader enterprise risk management principle of defining tolerances based on:
* potential harm
* regulatory exposure
* financial impact
* operational disruption
Monitoring (A) detects attacks but does not set thresholds. Blocking special characters (B) is unrealistic and overly restrictive. Static thresholds (D) ignore business context and practicality.
============================================
Joseph Flores
10 days agoCrystal Harris
28 days agoCharles Martinez
1 month agoBetty Stewart
2 months agoJeffrey Bell
2 months agoMatthew Carter
3 months agoBarbara Martin
3 months agoAndrew Anderson
4 months agoAmanda Thomas
4 months agoMichelle Bailey
4 months agoDennis Ramirez
4 months agoChristopher Flores
4 months agoChristopher Jones
4 months agoViola
5 months agoFranklyn
5 months agoThad
5 months agoRosio
6 months agoRebbeca
6 months agoJulie
6 months agoCarrol
7 months agoGiovanna
7 months agoKing
7 months agoRebeca
7 months agoDolores
8 months agoNovella
8 months agoRebecka
8 months agoYolando
8 months agoOlene
8 months agoLayla
9 months agoMarylyn
9 months agoElin
9 months agoMaddie
9 months agoDaniel
10 months agoTien
10 months agoLavonna
10 months agoMaynard
10 months agoTerry
11 months agoVirgina
11 months agoCarry
11 months agoStephaine
11 months agoJesus
12 months agoAbraham
12 months agoValene
1 year agoGracie
1 year agoJanine
1 year ago