TechNuggets Academy

AI Technologies and Controls

Free ISACA Advanced in AI Security Management practice — 6 questions on AI Technologies and Controls, with explanations. No sign-up. Full 12-question mixed test →

Question 1 of 6 · Domain 3: AI Technologies and Controls
A company deploys an autonomous AI agent with access to internal HR, finance, and ticketing APIs to complete multi-step tasks on behalf of employees. Security is concerned that a prompt injection embedded in an incoming ticket could hijack the agent into exfiltrating finance data. Which architecture BEST minimizes the blast radius of such an attack?
A broker/proxy issuing scoped, short-lived, per-task credentials enforces least privilege and segmentation at the identity/access layer, so even a successfully hijacked agent cannot reach systems outside its authorized task scope — this is the core secure-agentic-architecture control (tool/permission isolation).
Question 2 of 6 · Domain 3: AI Technologies and Controls
A security architect is designing the training pipeline for an LLM fine-tuned on customer support tickets containing PII. The organization must later be able to prove exactly which dataset version and which records were used to produce a specific deployed model version, in order to honor data subject deletion requests. Which control provides this capability?
Only immutable version-hashed lineage that maps dataset versions to specific training run/model IDs creates a verifiable, record-level traceability chain, which is required to determine which model versions were built from data that must later be removed or retrained.
Question 3 of 6 · Domain 3: AI Technologies and Controls
A healthcare AI system generates draft treatment recommendations and, as a safety control, requires clinician sign-off before any recommendation reaches the patient record. An audit discovers clinicians are approving 98% of recommendations within seconds, effectively rubber-stamping the AI's output and negating the intended human oversight. What is the MOST effective corrective control?
Requiring a documented rationale forces clinicians to actively engage with each recommendation rather than passively approve it, and outcome-based auditing gives measurable evidence of whether oversight is genuine — this restores the substance of 'human oversight at critical decision points' rather than its mere appearance.
Question 4 of 6 · Domain 3: AI Technologies and Controls
An AI security team knows their pre-launch red team exercise on a customer-facing chatbot will not catch jailbreak techniques that emerge after deployment. Which control BEST addresses this ongoing, evolving risk once the chatbot is in production?
Continuous automated red-teaming tied to live telemetry detects new jailbreak patterns as they emerge in production, closing the gap left by a point-in-time pre-launch test — this is the intended continuous evaluation/monitoring control for deployed generative AI systems.
Question 5 of 6 · Domain 3: AI Technologies and Controls
Before fully replacing a production LLM-based fraud-detection classifier with a newer fine-tuned version, the security team wants to evaluate the new model's real-world safety and accuracy against live traffic while ensuring zero customers are exposed to any risk from the new model's decisions. Which deployment pattern BEST achieves this?
Shadow deployment scores real traffic to validate the new model's behavior but never surfaces its decisions to end users, giving the security team true real-world evaluation data with zero customer risk exposure.
Question 6 of 6 · Domain 3: AI Technologies and Controls
Which statement BEST distinguishes a 'fairness constraint' control from a 'differential privacy' control in an AI system?
Fairness constraints are performance-equity controls that target disparate outcomes across protected groups, whereas differential privacy is a data-protection technique that mathematically bounds how much any single training record can influence or be inferred from the model's output — the two address distinct risk categories.
Ready for the real thing?

The full course: two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed explanations.

undefined $34.99 with code FREETEST33 — valid through Oct 6.

Get my $34.99 deal →