Summer Sale Special - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sntaclus

Users report that the output of a generative AI application seems unrelated to the prompts and contains offensive content. A security team investigates and determines that there was an on-path attack.

Which of the following is the most likely attack method?

A.

Application server hijacking

B.

Session hijacking

C.

Domain hijacking

D.

Model hijacking

Which of the following is an example of how a security analyst uses generative AI in the triage process?

A.

To predict the next attack target with higher accuracy

B.

To use statistical analysis for malicious code assessment

C.

To summarize security findings by category

D.

To tag malware using machine learning (ML) algorithms

A security analyst notices that regardless of user-submitted prompts, an AI model always returns unsanitized responses. These responses are then passed to multiple plug-ins. The analyst is concerned with the potential security implications.

Which of the following Open Worldwide Application Security Project (OWASP) categories addresses this vulnerability?

A.

Misinformation

B.

Prompt injection

C.

Unbounded consumption

D.

Improper output handling

A detection engineering team wants to use AI to automatically prevent vulnerable code from reaching production.

Which of the following is the most effective way to accomplish this task?

A.

Deploying an integrated development environment (IDE) plug-in that will warn developers of dangerous code before compiling

B.

Using a security orchestration, automation, and response (SOAR) with a machine learning (ML) model to classify code

C.

Implementing a large language model (LLM) in the continuous integration and continuous deployment (CI/CD) runner to examine code and pass or fail build jobs

D.

Developing an agentic penetration testing tool to validate potential vulnerable code

An administrator, who works for a financial institution, is required to implement data security controls for data at rest within AI systems that involve data disclosure.

Which of the following is the most suitable control?

A.

Data lineage

B.

Rate limits

C.

Encryption

D.

Masking

A team of data scientists is ready to release a model for enterprise use. The team wants to protect the model from unintentional changes or tampering.

Which of the following is the most appropriate action?

A.

Change the model to a large language model (LLM) for interactive features with guardrails.

B.

Provide secure copies of the model for local runtime usage.

C.

Restrict access to only IT professionals in the organization.

D.

Integrate an application programming interface (API) with identity and access management (IAM) roles to interact with the model.

Which of the following attacks is most enabled by AI-generated content?

A.

Model poisoning

B.

Phishing

C.

Ransomware

D.

Remote code execution

Which of the following is the primary security risk when deploying AI models in production?

A.

Graphics processing unit (GPU) acceleration

B.

Model overfitting

C.

Model encryption

D.

Data exposure

An architect is using the firm ' s recommended large language model (LLM) to find an internal solution for content management.

Given the following:

Which of the following controls is the best for mitigating this issue?

A.

Model training

B.

Response validation

C.

Access controls

D.

Integrity monitoring

A security operations center (SOC) has a very high volume of logs and alerts. The manager proposes the implementation of a machine learning (ML) system to help with triage.

Which of the following tasks is most suitable?

A.

Applying filters on specific alerts

B.

Automatically patching vulnerable systems

C.

Identifying and classifying alerts

D.

Summarizing the content of alerts