Topic module

Generative AI and Large Language Models

This topic covers LLMs, prompts, grounding, embeddings, retrieval, tools, agents, hallucination, safety controls, and GenAI-specific audit risks.

Long-form learning
Concept to Risk to Memory to Check-up

How to study for ISACA AAIA

Treat each item as an audit decision: understand AI risk, identify criteria, test evidence, assess control effectiveness, then report impact and follow-up.

Core concepts

Concept 1

Generative AI applications combine prompts, models, retrieval, tools, output handling, logging, and user workflows.

Exam cue: Use grounding evidence when outputs must be factual.

Concept 2

LLM risks include hallucination, prompt injection, data leakage, unsafe output, bias, excessive agency, and weak evaluation.

Exam cue: Test prompt injection and tool boundaries for agentic workflows.

Concept 3

Auditors test GenAI controls across input, retrieval, model call, tool use, output validation, monitoring, and escalation.

Exam cue: Review logs for prompts, retrieval, tool calls, outputs, and safety events.

Risk pitfalls and guardrails

Treating LLM output as authoritative without source support.

Guardrail: Avoid treating AI audit as only a technical scan, accepting management assertions without evidence, or omitting prompts, data, vendors, and monitoring.

Auditing only the model while ignoring retrieval and tools.

Guardrail: Avoid treating AI audit as only a technical scan, accepting management assertions without evidence, or omitting prompts, data, vendors, and monitoring.

Allowing broad agent actions without approval, limits, or monitoring.

Guardrail: Avoid treating AI audit as only a technical scan, accepting management assertions without evidence, or omitting prompts, data, vendors, and monitoring.

Memory anchors

Prompt

A prompt gives instructions, context, constraints, variables, and output expectations to an LLM.

Grounding

Grounding supplies trusted source context so GenAI output can be supported by evidence.

Embedding

An embedding represents content numerically so semantic retrieval can find related context.

Prompt Injection

Prompt injection attempts to override instructions, reveal data, or misuse tools through malicious input.

Hallucination

Hallucination is unsupported or incorrect generated content that appears plausible.

Agent Boundary

An agent boundary limits which tools, data, actions, and decisions an AI agent may use.

Output Validation

Output validation checks generated responses against format, policy, facts, safety, and business rules.

LLM Log

An LLM log records prompts, sources, outputs, tool calls, timing, user context, and safety signals as appropriate.

Checkpoint rule

Do the check-up only after you can summarize each concept in one sentence and identify one dangerous pitfall from memory.

Knowledge Check (after reading)

Short check-up to confirm understanding of this module.

Check-up Questions

1-2 question checkpoint

A policy assistant invents a leave rule even though approved documents are available. Which control BEST addresses this?

A retrieved document contains instructions telling the model to email confidential files. What threat is this?

Answer all questions to submit.

Next step personalized recommendations

What is Pass Harbor?

Completely free exam prep for 317 U.S. exams.

  • Practice questions
  • Flashcards
  • Study guides
  • Mock exams
  • No registration
  • No paywall
  • Start instantly
No more expensive exam prep. Quality study tools should be accessible to everyone.