Topic module

AI Vulnerabilities, Threats and Security

Auditors should recognize AI threat models, adversarial behavior, model theft, poisoning, prompt injection, data leakage, insecure tools, and control testing.

Long-form learning
Concept to Risk to Memory to Check-up

How to study for ISACA AAIA

Treat each item as an audit decision: understand AI risk, identify criteria, test evidence, assess control effectiveness, then report impact and follow-up.

Core concepts

Concept 1

AI threats include prompt injection, adversarial input, data poisoning, model extraction, model inversion, leakage, tool abuse, and supply chain compromise.

Exam cue: Threat model the AI workflow before choosing tests.

Concept 2

Security testing should reflect the AI architecture, data flows, model access, retrieval, tools, APIs, and user roles.

Exam cue: Include retrieval and tools in security testing.

Concept 3

Controls include input validation, output filtering, access limits, monitoring, rate limits, isolation, secure development, and incident response.

Exam cue: Use layered controls because prompt instructions alone are weak protection.

Risk pitfalls and guardrails

Assuming standard web testing covers all AI-specific threats.

Guardrail: Avoid treating AI audit as only a technical scan, accepting management assertions without evidence, or omitting prompts, data, vendors, and monitoring.

Treating prompt wording as a security boundary.

Guardrail: Avoid treating AI audit as only a technical scan, accepting management assertions without evidence, or omitting prompts, data, vendors, and monitoring.

Ignoring data poisoning and model supply chain risk.

Guardrail: Avoid treating AI audit as only a technical scan, accepting management assertions without evidence, or omitting prompts, data, vendors, and monitoring.

Memory anchors

Threat Model

A threat model identifies likely AI attackers, assets, entry points, abuse paths, and controls.

Prompt Injection

Prompt injection uses malicious input to alter instructions, reveal data, or misuse tools.

Data Poisoning

Data poisoning corrupts training, tuning, retrieval, or feedback data to influence AI behavior.

Model Extraction

Model extraction attempts to copy model behavior, parameters, or sensitive knowledge through queries.

Adversarial Input

Adversarial input is crafted to trigger incorrect, unsafe, or bypass behavior.

Tool Abuse

Tool abuse occurs when an AI agent uses connected actions outside authorized purpose or limits.

Rate Limit

A rate limit reduces abuse by limiting request volume, frequency, or cost exposure.

Layered Control

A layered control design combines prevention, detection, response, and recovery across the AI workflow.

Checkpoint rule

Do the check-up only after you can summarize each concept in one sentence and identify one dangerous pitfall from memory.

Knowledge Check (after reading)

Short check-up to confirm understanding of this module.

Check-up Questions

1-2 question checkpoint

Before choosing security tests for an AI agent, what should the auditor review FIRST?

A small sticker causes a vision model to misclassify a stop sign. What type of threat is illustrated?

Answer all questions to submit.

Next step personalized recommendations

Continue learning

Move forward only after this module is stable.

What is Pass Harbor?

Completely free exam prep for 317 U.S. exams.

  • Practice questions
  • Flashcards
  • Study guides
  • Mock exams
  • No registration
  • No paywall
  • Start instantly
No more expensive exam prep. Quality study tools should be accessible to everyone.