nerdexam
Isaca

CISA · Question #640

Which of the following is the MOST important control consideration when planning the audit of an information system that uses a large language model?

The correct answer is B. The effectiveness of logical access controls over the model's training data. Logical access controls over the model’s training data are the most important consideration because unauthorized access or manipulation of training data can directly compromise the integrity, confidentiality, and reliability of the large language model’s outputs, leading to…

Submitted by ashley.k· Apr 18, 2026Information System Auditing Process

Question

Which of the following is the MOST important control consideration when planning the audit of an information system that uses a large language model?

Options

  • AThe alignment of model outputs with business continuity plans (BCPs)
  • BThe effectiveness of logical access controls over the model's training data
  • CThe frequency of physical security checks at the data center hosting the model
  • DThe schedule for the maintenance of the hardware used by the model

How the community answered

(46 responses)
  • A
    9% (4)
  • B
    76% (35)
  • C
    4% (2)
  • D
    11% (5)

Explanation

Logical access controls over the model’s training data are the most important consideration because unauthorized access or manipulation of training data can directly compromise the integrity, confidentiality, and reliability of the large language model’s outputs, leading to biased, inaccurate, or noncompliant results.

Topics

#LLM security#Training data integrity#Logical access controls#Audit planning

Community Discussion

No community discussion yet for this question.

Full CISA Practice