AAISM · Question #169
An organization deploying an LLM is concerned input manipulations could compromise security. What is the MOST effective way to determine an acceptable risk threshold?
The correct answer is C. Assess the business impact of known threats. An acceptable risk threshold must be grounded in business impact, not arbitrary technical limits. Assessing the business impact of known threats (C) allows the organization to weigh the likelihood and severity of input manipulation attacks (e.g., prompt injection) against the…
Question
An organization deploying an LLM is concerned input manipulations could compromise security. What is the MOST effective way to determine an acceptable risk threshold?
Options
- ADeploy real-time logging and monitoring
- BRestrict all inputs containing special characters
- CAssess the business impact of known threats
- DImplement a static threshold limiting LLM outputs
How the community answered
(53 responses)- A11% (6)
- B6% (3)
- C81% (43)
- D2% (1)
Explanation
An acceptable risk threshold must be grounded in business impact, not arbitrary technical limits. Assessing the business impact of known threats (C) allows the organization to weigh the likelihood and severity of input manipulation attacks (e.g., prompt injection) against the cost and friction of mitigations, producing a threshold that balances security with usability. Real-time logging (A) is a detection control, not a threshold-setting method. Blocking all special characters (B) is overly broad and may break legitimate use. A static output limit (D) addresses symptoms, not the risk calculus needed to define what level of threat is acceptable.
Topics
Community Discussion
No community discussion yet for this question.