nerdexam
Isaca

AAISM · Question #86

An organization has implemented a natural language processing model to respond to customer questions when personnel are not available. A pre-implementation security assessment revealed attackers…

The correct answer is C. Implementing input validation and templates. Chat interface injection attacks (such as prompt injection) exploit the model by crafting malicious inputs that manipulate the AI into revealing sensitive data or taking unintended actions. Input validation ensures user-supplied text conforms to expected, safe formats, while…

AI Security Design and Implementation

Question

An organization has implemented a natural language processing model to respond to customer questions when personnel are not available. A pre-implementation security assessment revealed attackers could access sensitive company data through a chat interface injection attack. Which of the following is the BEST way to prevent this attack?

Options

  • AEnsuring continuous monitoring and data tagging
  • BManually reviewing AI model outputs
  • CImplementing input validation and templates
  • DConducting regular information security audits

How the community answered

(26 responses)
  • A
    19% (5)
  • B
    8% (2)
  • C
    69% (18)
  • D
    4% (1)

Explanation

Chat interface injection attacks (such as prompt injection) exploit the model by crafting malicious inputs that manipulate the AI into revealing sensitive data or taking unintended actions. Input validation ensures user-supplied text conforms to expected, safe formats, while response templates constrain what the model can return - together they block malicious payloads at the entry and exit points. Option A (continuous monitoring and data tagging) is a detective control, not a preventive one. Option B (manual review of outputs) is reactive and impractical at scale. Option D (security audits) identifies vulnerabilities but does not directly block injection attacks.

Topics

#AI Security#Injection Attacks#Input Validation#Secure Design

Community Discussion

No community discussion yet for this question.

Full AAISM Practice