AI Vulnerabilities, Threats and Security
Auditors should recognize AI threat models, adversarial behavior, model theft, poisoning, prompt injection, data leakage, insecure tools, and control testing.
How to study for ISACA AAIA
Treat each item as an audit decision: understand AI risk, identify criteria, test evidence, assess control effectiveness, then report impact and follow-up.
Core concepts
Concept 1
AI threats include prompt injection, adversarial input, data poisoning, model extraction, model inversion, leakage, tool abuse, and supply chain compromise.
Exam cue: Threat model the AI workflow before choosing tests.
Concept 2
Security testing should reflect the AI architecture, data flows, model access, retrieval, tools, APIs, and user roles.
Exam cue: Include retrieval and tools in security testing.
Concept 3
Controls include input validation, output filtering, access limits, monitoring, rate limits, isolation, secure development, and incident response.
Exam cue: Use layered controls because prompt instructions alone are weak protection.
Risk pitfalls and guardrails
Assuming standard web testing covers all AI-specific threats.
Guardrail: Avoid treating AI audit as only a technical scan, accepting management assertions without evidence, or omitting prompts, data, vendors, and monitoring.
Treating prompt wording as a security boundary.
Guardrail: Avoid treating AI audit as only a technical scan, accepting management assertions without evidence, or omitting prompts, data, vendors, and monitoring.
Ignoring data poisoning and model supply chain risk.
Guardrail: Avoid treating AI audit as only a technical scan, accepting management assertions without evidence, or omitting prompts, data, vendors, and monitoring.
Memory anchors
Threat Model
A threat model identifies likely AI attackers, assets, entry points, abuse paths, and controls.
Prompt Injection
Prompt injection uses malicious input to alter instructions, reveal data, or misuse tools.
Data Poisoning
Data poisoning corrupts training, tuning, retrieval, or feedback data to influence AI behavior.
Model Extraction
Model extraction attempts to copy model behavior, parameters, or sensitive knowledge through queries.
Adversarial Input
Adversarial input is crafted to trigger incorrect, unsafe, or bypass behavior.
Tool Abuse
Tool abuse occurs when an AI agent uses connected actions outside authorized purpose or limits.
Rate Limit
A rate limit reduces abuse by limiting request volume, frequency, or cost exposure.
Layered Control
A layered control design combines prevention, detection, response, and recovery across the AI workflow.
Checkpoint rule
Do the check-up only after you can summarize each concept in one sentence and identify one dangerous pitfall from memory.
Knowledge Check (after reading)
Short check-up to confirm understanding of this module.
Check-up Questions
Before choosing security tests for an AI agent, what should the auditor review FIRST?
A small sticker causes a vision model to misclassify a stop sign. What type of threat is illustrated?
Answer all questions to submit.
Next step personalized recommendations
Continue learning
Move forward only after this module is stable.
What is Pass Harbor?
Completely free exam prep for 317 U.S. exams.
- Practice questions
- Flashcards
- Study guides
- Mock exams
- No registration
- No paywall
- Start instantly
“No more expensive exam prep. Quality study tools should be accessible to everyone.”
