Generative AI and Large Language Models
This topic covers LLMs, prompts, grounding, embeddings, retrieval, tools, agents, hallucination, safety controls, and GenAI-specific audit risks.
How to study for ISACA AAIA
Treat each item as an audit decision: understand AI risk, identify criteria, test evidence, assess control effectiveness, then report impact and follow-up.
Core concepts
Concept 1
Generative AI applications combine prompts, models, retrieval, tools, output handling, logging, and user workflows.
Exam cue: Use grounding evidence when outputs must be factual.
Concept 2
LLM risks include hallucination, prompt injection, data leakage, unsafe output, bias, excessive agency, and weak evaluation.
Exam cue: Test prompt injection and tool boundaries for agentic workflows.
Concept 3
Auditors test GenAI controls across input, retrieval, model call, tool use, output validation, monitoring, and escalation.
Exam cue: Review logs for prompts, retrieval, tool calls, outputs, and safety events.
Risk pitfalls and guardrails
Treating LLM output as authoritative without source support.
Guardrail: Avoid treating AI audit as only a technical scan, accepting management assertions without evidence, or omitting prompts, data, vendors, and monitoring.
Auditing only the model while ignoring retrieval and tools.
Guardrail: Avoid treating AI audit as only a technical scan, accepting management assertions without evidence, or omitting prompts, data, vendors, and monitoring.
Allowing broad agent actions without approval, limits, or monitoring.
Guardrail: Avoid treating AI audit as only a technical scan, accepting management assertions without evidence, or omitting prompts, data, vendors, and monitoring.
Memory anchors
Prompt
A prompt gives instructions, context, constraints, variables, and output expectations to an LLM.
Grounding
Grounding supplies trusted source context so GenAI output can be supported by evidence.
Embedding
An embedding represents content numerically so semantic retrieval can find related context.
Prompt Injection
Prompt injection attempts to override instructions, reveal data, or misuse tools through malicious input.
Hallucination
Hallucination is unsupported or incorrect generated content that appears plausible.
Agent Boundary
An agent boundary limits which tools, data, actions, and decisions an AI agent may use.
Output Validation
Output validation checks generated responses against format, policy, facts, safety, and business rules.
LLM Log
An LLM log records prompts, sources, outputs, tool calls, timing, user context, and safety signals as appropriate.
Checkpoint rule
Do the check-up only after you can summarize each concept in one sentence and identify one dangerous pitfall from memory.
Knowledge Check (after reading)
Short check-up to confirm understanding of this module.
Check-up Questions
A policy assistant invents a leave rule even though approved documents are available. Which control BEST addresses this?
A retrieved document contains instructions telling the model to email confidential files. What threat is this?
Answer all questions to submit.
Next step personalized recommendations
Continue learning
Move forward only after this module is stable.
What is Pass Harbor?
Completely free exam prep for 317 U.S. exams.
- Practice questions
- Flashcards
- Study guides
- Mock exams
- No registration
- No paywall
- Start instantly
“No more expensive exam prep. Quality study tools should be accessible to everyone.”
