QuestionQ22

Securing AI systems

A penetration tester is evaluating the controls of a deployed AI system designed to search for and return file contents. The tester executes the following:

Question Image

Which of the following is the most effective control for preventing abuse of the system?

Explanation

Applying least privilege to the service account limits the files, buckets, permissions, and administrative operations the application can access. This constrains the impact of attacker-controlled requests even when the application is manipulated to invoke unintended backend actions.

Community Discussion

No comments yet. Be the first to start the discussion!