AAIR self-assessment questions support the content in this manual and provide an understanding of the type and structure of questions that typically appear on the exam. Often a question will require the candidate to choose the MOST likely or BEST answer among the options provided. Please note that these questions are not actual or retired exam items. Please see About This Manual for more guidance regarding practice questions.
While model theft can be a concern, adversarial attacks focus on causing incorrect predictions rather than stealing model architectures.
Overfitting is a performance issue, not a security risk.
Adversarial attacks involve manipulating input data in ways that cause machine learning (ML) models to make incorrect predictions, which is a significant security risk.
Increasing computational cost is a technical concern, not a security issue related to adversarial attacks.
As the event was not yet confirmed, suspending the solution would be a premeditated option. This reactive approach may unnecessarily disrupt healthcare operations without addressing the underlying problem.
Identifying and understanding the root cause of a security-related incident is fundamental for effective risk assessment and response. A reassessment grounded in root cause analysis enables organizations to reframe and respond to risk accurately, especially in cases of human misuse.
Updating internal policies is necessary to deal with human error and misuse as part of a broader set of directives, but policies must be based on a reassessed risk landscape.
Applying liability measures to users addresses symptoms, not the system. Focusing solely on punitive actions treats symptoms rather than causes.
While vendor certifications are useful, they are not a substitute for independent verification. Independent verification is the best way to account for all potential risk or vulnerabilities.
Isolating the system reduces external risk but does not address the integrity of components or datasets already integrated into the AI solution.
Auditing third-party components emphasizes proactive verification, which is critical for ensuring the authenticity and security of third-party components and datasets before integration.
Continuous monitoring is important but reactive. It does not prevent the integration of compromised components or datasets.