Threat modeling that systematically identifies potential: Which periodic activity fits this goal?
Threat modeling systematically enumerates and prioritizes potential attack paths, matching the team's security goal.
The question
Before periodically reassessing a deployed AI system newly integrated with an external data source, the security team wants to systematically enumerate how an attacker might exploit the new interface and rank those attack paths. Which periodic activity fits this goal?
Preparing for AIGP? Take the free 5-min readiness quiz →
- A financial audit reviewing the costs of the new integration, so leadership can confirm the added external data source stays within its approved budget envelope.A financial audit evaluates spend, not the attack paths against the new interface that the team wants to enumerate.
- A bias evaluation across demographic subgroups, so the team can verify the integrated system treats different populations equitably after the new data was added.Bias evaluation addresses fairness, which is important but distinct from systematically mapping how the interface could be attacked.
- Threat modeling that systematically identifies potential attack paths against the new interface and prioritizes them so defenses can be planned accordingly. ✓Threat modeling is the structured activity that enumerates and prioritizes how a system could be attacked, matching the team's goal.
- A user-experience review of the interface's usability, so the team can confirm the new integration is intuitive and easy for operators to work with day to day.A usability review concerns ease of use, not the enumeration and ranking of security attack paths.
The trap
Confusing threat modeling with unrelated periodic reviews, or with red teaming's active exploitation. How to remember it
Threat modeling systematically enumerates and prioritizes potential attack paths, matching the team's security goal.
How many of these would you get right?
One of 1581 AIGP questions on Certsqill. Take a free five-minute check and see your score per domain — not one number, but which section to open tonight.
Test your AIGP readiness — freeMore Understanding How to Govern AI Development questions
- Ongoing outcome and prediction-quality metrics compared: To satisfy continuous-monitoring requirements, which →
- Log the incident in a central register with root cause: Which response best discharges the obligation to →
- Model drift, where the statistical relationship between: Working with data scientists and business owners, →
- All 426 Understanding How to Govern AI Development questions →
Part of the Certsqill AIGP question bank · Understanding How to Govern AI Development ·
Every answer, right and wrong, comes with its own explanation.