nerdexam
Isaca

AAISM · Question #181

A security assessment revealed that attackers could access sensitive company data through chat interface injection. What is the BEST mitigation?

The correct answer is C. Implementing input validation and templates. Chat interface injection attacks-such as prompt injection-exploit uncontrolled user input to manipulate AI behavior or exfiltrate data. Input validation (sanitizing and constraining what users can submit) combined with structured prompt templates (limiting the shape and content…

AI Security Design and Implementation

Question

A security assessment revealed that attackers could access sensitive company data through chat interface injection. What is the BEST mitigation?

Options

  • AConducting regular security audits
  • BManually reviewing AI model outputs
  • CImplementing input validation and templates
  • DEnsuring continuous monitoring and tagging

How the community answered

(23 responses)
  • A
    4% (1)
  • B
    4% (1)
  • C
    83% (19)
  • D
    9% (2)

Explanation

Chat interface injection attacks-such as prompt injection-exploit uncontrolled user input to manipulate AI behavior or exfiltrate data. Input validation (sanitizing and constraining what users can submit) combined with structured prompt templates (limiting the shape and content of queries sent to the model) directly closes the attack surface at the point of entry. Audits and output reviews are detective controls that identify problems after the fact; continuous monitoring and tagging provide visibility but do not prevent the injection from reaching the model in the first place.

Topics

#Input Validation#Injection Attacks#AI Security#Mitigation Strategies

Community Discussion

No community discussion yet for this question.

Full AAISM Practice