nerdexam
Isaca

AAISM · Question #162

Which strategy BEST ensures generative AI tools do not expose company data?

The correct answer is B. Implementing a solution prohibiting input of sensitive data. The most direct way to prevent generative AI tools from exposing company data is to implement a technical control that prohibits sensitive data from being entered in the first place (B) - such as DLP (Data Loss Prevention) policies, browser extensions, or API gateways that…

AI Security Design and Implementation

Question

Which strategy BEST ensures generative AI tools do not expose company data?

Options

  • AConducting an independent AI data audit
  • BImplementing a solution prohibiting input of sensitive data
  • CTesting AI tools before implementation
  • DEnsuring AI tools comply with local regulations

How the community answered

(42 responses)
  • A
    7% (3)
  • B
    88% (37)
  • C
    2% (1)
  • D
    2% (1)

Explanation

The most direct way to prevent generative AI tools from exposing company data is to implement a technical control that prohibits sensitive data from being entered in the first place (B) - such as DLP (Data Loss Prevention) policies, browser extensions, or API gateways that block sensitive content at the input layer. An audit (A) is retrospective and does not prevent exposure. Pre-deployment testing (C) validates behavior at a point in time but does not control ongoing user behavior. Regulatory compliance (D) sets a legal floor but does not technically prevent data from being submitted to AI tools.

Topics

#Generative AI Security#Data Loss Prevention#Preventative Controls#Data Privacy

Community Discussion

No community discussion yet for this question.

Full AAISM Practice