nerdexam
Isaca

AAISM · Question #92

An organization is implementing AI agent development across multiple engineering teams. Which of the following is the MOST important focus of AI-specific security training for developers?

The correct answer is A. Prompt injection, agent memory control, and insecure tool execution. For developer-facing, near-term hardening of AI agents, AAISM prioritizes secure agent design and runtime controls against prompt injection, unsafe memory/tool use, and tool-execution compromise. These are primary exploitation paths for agents that read external content…

AI Security Design and Implementation

Question

An organization is implementing AI agent development across multiple engineering teams. Which of the following is the MOST important focus of AI-specific security training for developers?

Options

  • APrompt injection, agent memory control, and insecure tool execution
  • BDataset bias, explainability, and fairness in model decisions
  • COutput moderation, hallucination handling, and policy alignment
  • DAPI abuse, data leakage, and third-party plug-in risk

How the community answered

(27 responses)
  • A
    81% (22)
  • B
    4% (1)
  • C
    4% (1)
  • D
    11% (3)

Explanation

For developer-facing, near-term hardening of AI agents, AAISM prioritizes secure agent design and runtime controls against prompt injection, unsafe memory/tool use, and tool-execution compromise. These are primary exploitation paths for agents that read external content, persist memory, and call tools with elevated privileges. Training must center on: guarding tool invocation, constraining memory scope, sanitizing/validating inputs, and isolating high-risk actions.

Topics

#Prompt Injection#AI Agent Security#Secure AI Development#Insecure Tool Execution

Community Discussion

No community discussion yet for this question.

Full AAISM Practice