nerdexam
Isaca

AAIA · Question #26

An organization shares an AI model with external partners. One partner reports that sensitive data has been inadvertently exposed through the model's outputs. Which of the following is the IS…

The correct answer is C. Disable the shared model and notify partners of the potential breach. When a data breach is reported, the immediate priority is containment - stopping further exposure - followed by notification of all potentially affected parties. Disabling the shared model halts ongoing leakage, and notifying partners allows them to take protective action and…

AI Risk Management and Controls

Question

An organization shares an AI model with external partners. One partner reports that sensitive data has been inadvertently exposed through the model's outputs. Which of the following is the IS auditor's BEST recommendation?

Options

  • ALimit the model's outputs to anonymized results while investigating further.
  • BAudit the data pipelines of all partners to identify the source of the leak.
  • CDisable the shared model and notify partners of the potential breach.
  • DRetrain the model immediately and implement privacy-preserving techniques.

How the community answered

(28 responses)
  • A
    21% (6)
  • B
    4% (1)
  • C
    64% (18)
  • D
    11% (3)

Explanation

When a data breach is reported, the immediate priority is containment - stopping further exposure - followed by notification of all potentially affected parties. Disabling the shared model halts ongoing leakage, and notifying partners allows them to take protective action and fulfill their own regulatory obligations. This follows standard incident response and breach notification requirements (e.g., GDPR Article 33). Option A (anonymizing outputs) does not stop the breach and is an inadequate containment measure. Option B (auditing all partners) is an investigative step that comes after containment. Option D (retraining) addresses the root cause but skips the critical containment and notification steps.

Topics

#AI data privacy#Incident response#Risk mitigation#AI model security

Community Discussion

No community discussion yet for this question.

Full AAIA Practice