nerdexam
Isaca

AAISM · Question #169

An organization deploying an LLM is concerned input manipulations could compromise security. What is the MOST effective way to determine an acceptable risk threshold?

The correct answer is C. Assess the business impact of known threats. An acceptable risk threshold must be grounded in business impact, not arbitrary technical limits. Assessing the business impact of known threats (C) allows the organization to weigh the likelihood and severity of input manipulation attacks (e.g., prompt injection) against the…

AI Security Risk Management

Question

An organization deploying an LLM is concerned input manipulations could compromise security. What is the MOST effective way to determine an acceptable risk threshold?

Options

  • ADeploy real-time logging and monitoring
  • BRestrict all inputs containing special characters
  • CAssess the business impact of known threats
  • DImplement a static threshold limiting LLM outputs

How the community answered

(53 responses)
  • A
    11% (6)
  • B
    6% (3)
  • C
    81% (43)
  • D
    2% (1)

Explanation

An acceptable risk threshold must be grounded in business impact, not arbitrary technical limits. Assessing the business impact of known threats (C) allows the organization to weigh the likelihood and severity of input manipulation attacks (e.g., prompt injection) against the cost and friction of mitigations, producing a threshold that balances security with usability. Real-time logging (A) is a detection control, not a threshold-setting method. Blocking all special characters (B) is overly broad and may break legitimate use. A static output limit (D) addresses symptoms, not the risk calculus needed to define what level of threat is acceptable.

Topics

#Risk threshold determination#Business impact assessment#LLM input security#Threat assessment

Community Discussion

No community discussion yet for this question.

Full AAISM Practice