nerdexam
Isaca

AAISM · Question #109

Which of the following strategies BEST ensures generative AI tools do not expose company data?

The correct answer is C. Implementing a solution to prohibit the input of sensitive data. AAISM prioritizes preventive controls at the point of use for generative AI, specifically input- governance and DLP controls that block or redact confidential, regulated, or high-risk data before it can be sent to external models. Audits, pre-deployment tests, and regulatory…

AI Security Design and Implementation

Question

Which of the following strategies BEST ensures generative AI tools do not expose company data?

Options

  • AConducting an independent AI data audit
  • BTesting AI tools before implementation
  • CImplementing a solution to prohibit the input of sensitive data
  • DEnsuring AI tools are compliant with local regulations

How the community answered

(56 responses)
  • A
    11% (6)
  • B
    9% (5)
  • C
    77% (43)
  • D
    4% (2)

Explanation

AAISM prioritizes preventive controls at the point of use for generative AI, specifically input- governance and DLP controls that block or redact confidential, regulated, or high-risk data before it can be sent to external models. Audits, pre-deployment tests, and regulatory conformance are necessary but do not themselves prevent an employee from pasting sensitive content into prompts. Enforcing input restrictions, pattern-based redaction, policy-aware controls, and allow- lists for approved contexts provides the highest assurance of preventing exposure.

Topics

#Generative AI Security#Data Exposure Prevention#Sensitive Data Handling#Input Controls

Community Discussion

No community discussion yet for this question.

Full AAISM Practice