nerdexam
Isaca

AAISM · Question #112

Which of the following is the GREATEST concern when a vendor enables generative AI features for an organization's critical system?

The correct answer is A. Access to the model. When a vendor activates generative AI features within a critical system, the foremost concern is what data the AI model can access and who can interact with it. Generative AI models typically require broad access to system data to function, and uncontrolled access can expose…

AI Security Risk Management

Question

Which of the following is the GREATEST concern when a vendor enables generative AI features for an organization's critical system?

Options

  • AAccess to the model
  • BProposed regulatory enhancements
  • CSecurity monitoring and alerting
  • DBias and ethical practices

How the community answered

(26 responses)
  • A
    58% (15)
  • B
    8% (2)
  • C
    23% (6)
  • D
    12% (3)

Explanation

When a vendor activates generative AI features within a critical system, the foremost concern is what data the AI model can access and who can interact with it. Generative AI models typically require broad access to system data to function, and uncontrolled access can expose sensitive organizational data - including data the AI was never intended to see or use. This access control gap is the highest-priority security risk. Regulatory considerations (B), monitoring (C), and bias/ethics (D) are all valid concerns but are secondary to the fundamental question of whether the AI has appropriate and limited access to sensitive data.

Topics

#Generative AI security#Vendor risk management#AI model access control#Critical infrastructure security

Community Discussion

No community discussion yet for this question.

Full AAISM Practice