nerdexam
Isaca

AAIA · Question #96

Which of the following should be done FIRST when an attacker exfiltrates sensitive information from an AI model?

The correct answer is B. Isolate impacted systems until the attack vector is identified. In incident response, the first priority is always containment-isolating impacted systems stops the active attack and prevents further data loss. You cannot effectively remediate, notify stakeholders, or rebuild until you understand the attack vector, and you cannot safely…

AI Risk Management and Controls

Question

Which of the following should be done FIRST when an attacker exfiltrates sensitive information from an AI model?

Options

  • AImplement rate limiting and query restrictions to reduce exploitation attempts.
  • BIsolate impacted systems until the attack vector is identified.
  • CRebuild the AI model using a more secure architecture.
  • DInform regulators and affected stakeholders of a potential data breach.

How the community answered

(17 responses)
  • A
    6% (1)
  • B
    82% (14)
  • D
    12% (2)

Explanation

In incident response, the first priority is always containment-isolating impacted systems stops the active attack and prevents further data loss. You cannot effectively remediate, notify stakeholders, or rebuild until you understand the attack vector, and you cannot safely identify the attack vector while systems remain exposed. This follows the standard incident response lifecycle (Identify → Contain → Eradicate → Recover). Rate limiting (A) is a longer-term mitigation, not an immediate containment step. Rebuilding the model (C) is a recovery action that comes much later. Notifying regulators (D) is required but should follow initial containment so you have accurate information to report.

Topics

#Incident Response#AI Security#Data Exfiltration#Containment

Community Discussion

No community discussion yet for this question.

Full AAIA Practice