Home »
Trending Technologies MCQs
AI Security MCQs (Multiple-Choice Questions)
AI Security focuses on protecting artificial intelligence and machine learning systems, their models, data, infrastructure, applications, and users from attacks, misuse, unauthorized access, and unintended behavior. These AI Security MCQs cover important concepts such as adversarial attacks, prompt injection, data poisoning, model security, privacy, RAG security, AI agents, access control, model extraction, supply-chain security, red teaming, monitoring, and AI risk management.
AI Security MCQs
These AI Security multiple-choice questions are useful for students, cybersecurity professionals, AI engineers, developers, researchers, and candidates preparing for technical interviews and examinations related to artificial intelligence, machine learning, and cybersecurity.
List of AI Security MCQs
The following AI Security MCQs cover fundamental and advanced security concepts for protecting AI systems throughout their development, deployment, and operational lifecycle.
1. What is AI Security?
- Protecting AI systems, models, data, infrastructure, and applications from security threats
- Increasing the number of parameters in an AI model
- Improving only the visual design of an AI application
- Training a model without validation
Answer: A) Protecting AI systems, models, data, infrastructure, and applications from security threats
Explanation: AI Security addresses threats to the confidentiality, integrity, and availability of AI systems, as well as security risks introduced by AI-specific components and workflows.
2. Which three security properties are commonly represented by the CIA triad?
- Confidentiality, Integrity, and Availability
- Classification, Inference, and Automation
- Control, Intelligence, and Accuracy
- Consistency, Integration, and Authentication
Answer: A) Confidentiality, Integrity, and Availability
Explanation: Confidentiality protects information from unauthorized disclosure, integrity protects against unauthorized alteration, and availability ensures systems and resources remain accessible when needed.
3. What makes AI Security different from traditional application security?
- AI systems introduce additional risks involving models, training data, inference behavior, and AI-specific inputs
- AI systems do not require authentication
- Traditional security controls cannot be used with AI
- AI systems never interact with external data
Answer: A) AI systems introduce additional risks involving models, training data, inference behavior, and AI-specific inputs
Explanation: AI systems still require conventional security controls, but they also introduce unique attack surfaces involving training data, model behavior, prompts, embeddings, model outputs, and autonomous actions.
4. What is an adversarial attack against an AI model?
- An attack designed to cause a model to produce incorrect or undesirable behavior
- A method for increasing model accuracy
- A process for compressing model weights
- A method for backing up training data
Answer: A) An attack designed to cause a model to produce incorrect or undesirable behavior
Explanation: Adversarial attacks manipulate inputs, data, or other aspects of an AI system to cause incorrect predictions, unsafe behavior, information leakage, or other unintended outcomes.
5. What is an adversarial example?
- An input intentionally modified to cause an AI model to make an incorrect prediction or decision
- A correctly labeled training example
- A model backup file
- A security policy document
Answer: A) An input intentionally modified to cause an AI model to make an incorrect prediction or decision
Explanation: An adversarial example contains carefully designed perturbations or modifications intended to influence a model's output incorrectly.
6. What is an evasion attack in machine learning?
- Manipulating inputs at inference time to evade model detection or classification
- Changing training labels before training
- Stealing model weights from storage
- Deleting a model after deployment
Answer: A) Manipulating inputs at inference time to evade model detection or classification
Explanation: Evasion attacks occur during inference and attempt to make malicious or manipulated inputs appear benign to a deployed model.
7. What is data poisoning?
- Manipulating training, fine-tuning, or other data so that the resulting model behaves undesirably
- Encrypting a dataset before storage
- Compressing a dataset
- Removing duplicate records from a dataset
Answer: A) Manipulating training, fine-tuning, or other data so that the resulting model behaves undesirably
Explanation: Data poisoning attacks introduce malicious or misleading data into a learning pipeline to influence model behavior. OWASP identifies data and model poisoning as an important GenAI security risk.
8. What is a backdoor attack on a machine learning model?
- Embedding behavior that is activated by a particular trigger or condition
- Removing all model parameters
- Encrypting the model with a strong password
- Improving model generalization
Answer: A) Embedding behavior that is activated by a particular trigger or condition
Explanation: A backdoored model can behave normally for most inputs but produce attacker-controlled or undesirable behavior when a specific trigger is present.
9. What is prompt injection?
- Manipulating an LLM through crafted input so that it behaves in an unintended way
- Injecting additional RAM into a server
- Adding neurons to a neural network
- Encrypting a prompt before transmission
Answer: A) Manipulating an LLM through crafted input so that it behaves in an unintended way
Explanation: Prompt injection attempts to influence an LLM's behavior through malicious or unexpected instructions contained in direct user input or external content. OWASP identifies prompt injection as a major LLM security risk.
10. What is indirect prompt injection?
- Malicious instructions embedded in external content that an AI system processes
- A user changing their password
- A developer updating model weights
- An administrator restarting an AI server
Answer: A) Malicious instructions embedded in external content that an AI system processes
Explanation: In indirect prompt injection, instructions may be hidden in webpages, documents, emails, retrieved data, or other content that the AI system later processes.
11. Why is prompt injection difficult to eliminate completely?
- Natural-language instructions and untrusted content can influence model behavior in complex ways
- LLMs cannot process text
- Prompt injection only affects operating systems
- Encryption automatically prevents all prompt attacks
Answer: A) Natural-language instructions and untrusted content can influence model behavior in complex ways
Explanation: LLMs process instructions and data through the same general language-processing mechanism, making it difficult to guarantee that every malicious instruction embedded in content will be ignored.
12. Which is an important defense against prompt injection?
- Treating external content as untrusted and enforcing controls outside the model
- Giving the model unrestricted system access
- Trusting every retrieved document
- Removing authentication from the application
Answer: A) Treating external content as untrusted and enforcing controls outside the model
Explanation: Prompt-level instructions alone are not sufficient security boundaries. Applications should isolate untrusted content and enforce authorization, validation, and tool restrictions outside the model where possible.
13. What is jailbreaking in the context of generative AI?
- Attempting to bypass a model's intended behavioral or safety restrictions through crafted inputs
- Encrypting an AI model
- Deleting model checkpoints
- Training a model on clean data
Answer: A) Attempting to bypass a model's intended behavioral or safety restrictions through crafted inputs
Explanation: Jailbreaking refers to attempts to induce a model to ignore or circumvent restrictions that are intended to govern its responses or actions.
14. What is sensitive information disclosure in an AI application?
- Unintended exposure of confidential, personal, proprietary, or otherwise sensitive information
- Increasing model accuracy
- Improving tokenization
- Reducing model latency
Answer: A) Unintended exposure of confidential, personal, proprietary, or otherwise sensitive information
Explanation: AI systems can expose sensitive information through prompts, retrieved documents, model outputs, logs, training data, or integrations if appropriate controls are missing.
15. Which principle is useful for limiting an AI agent's access to sensitive resources?
- Least privilege
- Maximum privilege
- Anonymous access
- Unrestricted delegation
Answer: A) Least privilege
Explanation: Least privilege gives a component only the permissions required for its intended task, reducing the potential impact if the component or its inputs are compromised.
16. What is excessive agency in an AI application?
- Giving an AI system excessive functionality, permissions, or autonomy to perform actions
- Reducing the number of tools available to an agent
- Using a read-only database
- Adding authentication to an API
Answer: A) Giving an AI system excessive functionality, permissions, or autonomy to perform actions
Explanation: Excessive agency can allow unexpected model outputs or manipulated inputs to cause harmful actions. OWASP identifies excessive functionality, permissions, and autonomy as common causes.
17. Which design most directly reduces excessive agency?
- Granting only necessary tools and permissions and requiring approval for high-impact actions
- Giving the agent administrator access to every system
- Allowing unrestricted tool execution
- Removing authorization checks
Answer: A) Granting only necessary tools and permissions and requiring approval for high-impact actions
Explanation: Restricting available functions, permissions, and autonomy limits the potential impact of incorrect or manipulated model decisions.
18. What is insecure output handling?
- Passing AI-generated output to downstream systems without adequate validation or security controls
- Encrypting model output before storage
- Checking model output against a schema
- Filtering sensitive output
Answer: A) Passing AI-generated output to downstream systems without adequate validation or security controls
Explanation: AI output should not automatically be trusted. If output is used in HTML, SQL, code, commands, or other sensitive contexts, appropriate validation and sanitization are required.
19. Why should AI-generated SQL be treated carefully?
- Unvalidated generated SQL could access or modify data beyond the intended scope
- SQL cannot be generated by AI systems
- SQL is always safe when generated by an LLM
- Database permissions have no effect on AI applications
Answer: A) Unvalidated generated SQL could access or modify data beyond the intended scope
Explanation: Generated database queries should be constrained, validated, parameterized where appropriate, and executed using narrowly scoped database permissions.
20. What is model extraction?
- Attempting to reproduce or approximate a model's behavior through queries or other access
- Removing unnecessary model layers during optimization
- Exporting a model for legitimate backup
- Compressing a model for edge deployment
Answer: A) Attempting to reproduce or approximate a model's behavior through queries or other access
Explanation: Model extraction attacks attempt to obtain information that allows an attacker to recreate or approximate a target model's functionality.
21. Which control can help limit model extraction through an API?
- Rate limiting and monitoring query behavior
- Unlimited anonymous requests
- Removing authentication
- Publishing model internals
Answer: A) Rate limiting and monitoring query behavior
Explanation: Rate limits, authentication, usage monitoring, anomaly detection, and controlled output can make large-scale model extraction more difficult.
22. What is membership inference?
- An attack that attempts to determine whether a particular record was part of a model's training data
- An attack that changes model architecture
- A technique for generating synthetic data
- A method for reducing inference latency
Answer: A) An attack that attempts to determine whether a particular record was part of a model's training data
Explanation: Membership inference attacks attempt to infer whether specific data was included in a model's training set, creating potential privacy risks.
23. What is model inversion?
- Attempting to infer sensitive characteristics or information about training data from model behavior
- Flipping a model's weights randomly
- Converting a neural network into a decision tree
- Removing all model parameters
Answer: A) Attempting to infer sensitive characteristics or information about training data from model behavior
Explanation: Model inversion attacks use model outputs or other information to infer properties or information associated with training data.
24. What is differential privacy used for in machine learning?
- Providing mathematical privacy guarantees while limiting the influence of individual records
- Increasing the number of model parameters
- Eliminating the need for authentication
- Preventing all adversarial examples
Answer: A) Providing mathematical privacy guarantees while limiting the influence of individual records
Explanation: Differential privacy provides a formal framework for limiting how much the presence or absence of an individual record can affect released information or computation results.
25. What is RAG security?
- Protecting retrieval-augmented generation systems from attacks involving retrieved data, access, embeddings, prompts, and outputs
- Encrypting only the model's user interface
- Removing retrieval from an AI system
- Using a larger language model
Answer: A) Protecting retrieval-augmented generation systems from attacks involving retrieved data, access, embeddings, prompts, and outputs
Explanation: RAG introduces additional security considerations because external documents and retrieval systems become part of the model's input and application workflow.
26. Why can malicious documents be dangerous in a RAG system?
- Retrieved documents can contain instructions or data that influence the model's behavior
- Documents cannot be processed by RAG systems
- RAG automatically authenticates every document
- Retrieved content is always trusted
Answer: A) Retrieved documents can contain instructions or data that influence the model's behavior
Explanation: Untrusted retrieved content can contain malicious instructions, misleading information, or sensitive data and may influence the model when inserted into its context.
27. What is vector or embedding security concerned with?
- Protecting vector representations, vector stores, retrieval logic, and associated access controls
- Protecting only the robot's motor controller
- Increasing embedding dimensions without validation
- Replacing all vector databases
Answer: A) Protecting vector representations, vector stores, retrieval logic, and associated access controls
Explanation: Embedding-based systems can introduce risks involving unauthorized retrieval, poisoned content, access-control failures, and weaknesses in vector databases or retrieval pipelines. OWASP's current GenAI guidance includes vector and embedding weaknesses among its covered risks.
28. What is AI supply-chain security?
- Protecting models, datasets, libraries, plugins, dependencies, and other components used to build AI systems
- Managing physical transportation of computers only
- Increasing training dataset size
- Removing all third-party components
Answer: A) Protecting models, datasets, libraries, plugins, dependencies, and other components used to build AI systems
Explanation: AI systems can depend on pretrained models, datasets, packages, APIs, tools, and other third-party components, creating a broader software and data supply chain.
29. What is a malicious pretrained model risk?
- A model may contain malicious behavior, vulnerabilities, or unexpected functionality introduced before deployment
- A model always becomes secure after downloading
- A model cannot contain security-relevant behavior
- A pretrained model cannot interact with applications
Answer: A) A model may contain malicious behavior, vulnerabilities, or unexpected functionality introduced before deployment
Explanation: Third-party models should be evaluated and obtained from trusted sources because model artifacts can become part of an application's security boundary.
30. Why should AI dependencies be scanned and kept up to date?
- Vulnerable dependencies can introduce security weaknesses into the AI application
- Dependency updates always increase model accuracy
- Dependencies cannot contain vulnerabilities
- Scanning is only useful for image files
Answer: A) Vulnerable dependencies can introduce security weaknesses into the AI application
Explanation: AI applications commonly rely on software libraries, frameworks, model-serving components, and infrastructure that may contain vulnerabilities requiring remediation.
31. What is secure model serialization?
- Using model storage and loading mechanisms that minimize the risk of executing or processing untrusted serialized content
- Converting every model into plain text
- Removing model metadata
- Publishing model files publicly
Answer: A) Using model storage and loading mechanisms that minimize the risk of executing or processing untrusted serialized content
Explanation: Some serialization formats or loading mechanisms can introduce code-execution or deserialization risks. Model artifacts should therefore be handled as potentially sensitive software components.
32. What is authentication used for in an AI application?
- Verifying the identity of a user, service, or system making a request
- Determining whether a model prediction is correct
- Improving tokenization
- Increasing GPU memory
Answer: A) Verifying the identity of a user, service, or system making a request
Explanation: Authentication establishes who or what is requesting access to an AI service or resource.
33. What is authorization?
- Determining what an authenticated user or service is allowed to access or perform
- Determining whether a model has enough parameters
- Training a model with more data
- Encrypting every model output
Answer: A) Determining what an authenticated user or service is allowed to access or perform
Explanation: Authorization enforces permissions after identity has been established, such as whether an AI agent may read a particular document or execute a specific tool.
34. Why should an AI agent's tools use separate permissions where possible?
- It limits the impact of a compromised or manipulated tool invocation
- It guarantees that the model will never hallucinate
- It eliminates the need for authentication
- It increases the model's parameter count
Answer: A) It limits the impact of a compromised or manipulated tool invocation
Explanation: Separating permissions according to task requirements helps prevent an agent from using one compromised capability to access unrelated sensitive resources.
35. What is human-in-the-loop security for AI agents?
- Requiring human review or approval for selected high-impact actions
- Allowing an agent to make every decision without oversight
- Removing all automation from an AI system
- Using humans only to label images
Answer: A) Requiring human review or approval for selected high-impact actions
Explanation: Human approval can provide an additional control layer before sensitive actions such as financial transactions, account changes, or destructive operations are executed.
36. What is AI red teaming?
- Systematically testing an AI system to identify vulnerabilities, unsafe behavior, or attack paths
- Training an AI model with red-colored images
- Removing security controls before deployment
- Increasing model size without evaluation
Answer: A) Systematically testing an AI system to identify vulnerabilities, unsafe behavior, or attack paths
Explanation: AI red teaming uses adversarial or realistic scenarios to discover weaknesses in models, prompts, applications, tools, data pipelines, and system integrations.
37. What is an AI security evaluation?
- Testing an AI system against defined security threats, requirements, and failure conditions
- Measuring only the number of model parameters
- Checking only the user interface color
- Deleting failed test cases
Answer: A) Testing an AI system against defined security threats, requirements, and failure conditions
Explanation: Security evaluation can include adversarial testing, privacy tests, access-control verification, prompt-injection tests, abuse testing, and system-level assessments.
38. What is threat modeling for AI systems?
- Identifying assets, threats, attack surfaces, vulnerabilities, and potential impacts
- Increasing training data automatically
- Designing a neural network architecture only
- Generating synthetic images
Answer: A) Identifying assets, threats, attack surfaces, vulnerabilities, and potential impacts
Explanation: Threat modeling helps teams systematically analyze how an AI system could be attacked and where security controls should be applied.
39. Which is an example of an AI attack surface?
- Model API, training pipeline, data store, prompt interface, tools, or model-serving infrastructure
- Only the application's logo
- Only the physical keyboard
- Only the documentation website
Answer: A) Model API, training pipeline, data store, prompt interface, tools, or model-serving infrastructure
Explanation: AI security requires examining the complete system because attacks can target data, models, APIs, prompts, dependencies, tools, infrastructure, and downstream integrations.
40. What is security monitoring in an AI system?
- Continuously observing system activity and security-relevant events for anomalies or threats
- Training the model only once
- Disabling application logs
- Removing authentication after deployment
Answer: A) Continuously observing system activity and security-relevant events for anomalies or threats
Explanation: Monitoring can identify unusual usage, excessive requests, suspicious tool calls, abnormal outputs, authentication failures, and other security signals.
41. Why are audit logs important for AI security?
- They provide records that can support investigation, accountability, and incident response
- They automatically prevent every attack
- They replace authentication
- They eliminate the need for monitoring
Answer: A) They provide records that can support investigation, accountability, and incident response
Explanation: Logs can record relevant events such as user access, tool calls, configuration changes, model requests, and security alerts, subject to appropriate privacy and retention controls.
42. What is an AI incident response process?
- A structured process for detecting, containing, investigating, and recovering from AI-related security incidents
- A process for increasing model parameters
- A method for generating training labels
- A technique for compressing model weights
Answer: A) A structured process for detecting, containing, investigating, and recovering from AI-related security incidents
Explanation: AI incident response adapts established security practices to incidents involving models, data, prompts, agents, infrastructure, and AI-specific attack paths.
43. What is the purpose of the NIST AI Risk Management Framework?
- Helping organizations manage risks associated with AI systems
- Providing a programming language for neural networks
- Replacing all cybersecurity standards
- Defining one mandatory AI model architecture
Answer: A) Helping organizations manage risks associated with AI systems
Explanation: NIST's AI RMF is designed to help organizations incorporate trustworthiness considerations into the design, development, deployment, use, and evaluation of AI systems.
44. Which characteristic is explicitly included among NIST AI RMF trustworthiness considerations?
- Secure and resilient
- Maximum model size
- Unlimited autonomy
- Maximum token count
Answer: A) Secure and resilient
Explanation: NIST identifies secure and resilient systems as one of the trustworthiness characteristics considered in the AI RMF, alongside characteristics such as validity and reliability, accountability and transparency, explainability and interpretability, privacy enhancement, and fairness with harmful bias managed.
45. Why should security be considered throughout the AI lifecycle?
- Security weaknesses can be introduced during data collection, training, deployment, integration, or operation
- Security matters only after an AI model is retired
- Training data cannot affect security
- Deployment introduces no new risks
Answer: A) Security weaknesses can be introduced during data collection, training, deployment, integration, or operation
Explanation: AI security is not limited to inference. Risks can arise throughout the lifecycle, from training data and model development to deployment, external integrations, monitoring, and maintenance. NIST recommends considering trustworthiness across pre-design, design and development, deployment, use, and testing and evaluation.
46. An AI agent can read email, access customer records, issue refunds, and delete files. What is the primary security concern if all these permissions are granted without restrictions?
- Excessive agency
- Data normalization
- Model quantization
- Tokenization
Answer: A) Excessive agency
Explanation: Giving an agent broad functionality and permissions increases the potential impact of unexpected or manipulated model behavior. Limiting tools and permissions is an important mitigation for excessive agency.
47. A RAG application retrieves a document containing hidden instructions telling the LLM to ignore its system instructions and send retrieved customer data to an external service. What type of threat does this scenario primarily illustrate?
- Indirect prompt injection combined with excessive agency
- Model quantization
- Data normalization
- Gradient clipping
Answer: A) Indirect prompt injection combined with excessive agency
Explanation: The malicious instructions originate from retrieved external content, making this an indirect prompt injection scenario. If the agent also has permission to send data externally, excessive agency can increase the potential impact.
48. A company wants to protect confidential customer information in an AI assistant. Which architecture provides the strongest basic security boundary?
- Authenticated access, authorization checks, least-privilege retrieval, data filtering, and controlled model output
- Allowing every user to retrieve every document
- Putting all confidential data into the system prompt
- Relying only on the model to decide whether a user is authorized
Answer: A) Authenticated access, authorization checks, least-privilege retrieval, data filtering, and controlled model output
Explanation: Sensitive-data protection should rely on enforceable application and infrastructure controls rather than expecting the language model alone to enforce authorization boundaries.
49. A security team discovers that an LLM-powered application accepts user input, generates shell commands, and executes them with operating-system administrator privileges. Which architectural change most directly reduces the security impact?
- Use constrained tools with allowlisted operations and least-privilege execution permissions
- Give the model more detailed system instructions and keep administrator privileges
- Increase the model temperature
- Remove application logging
Answer: A) Use constrained tools with allowlisted operations and least-privilege execution permissions
Explanation: Model-generated commands should not automatically receive unrestricted system privileges. Constrained interfaces, allowlisted operations, sandboxing, authentication, authorization, and least-privilege execution can substantially reduce the potential impact of unsafe or manipulated outputs.
50. An organization is deploying an AI agent that can retrieve private documents, call external APIs, update databases, and perform financial actions. Which security architecture is most appropriate?
- Threat modeling, strong authentication and authorization, least-privilege tools, input and output validation, isolated execution, monitoring, audit logs, red teaming, and human approval for high-impact actions
- Give the agent unrestricted access and rely on the language model to make all security decisions
- Disable logging to reduce storage requirements
- Allow external documents to override system policies whenever necessary
Answer: A) Threat modeling, strong authentication and authorization, least-privilege tools, input and output validation, isolated execution, monitoring, audit logs, red teaming, and human approval for high-impact actions
Explanation: An agent with access to sensitive data and external systems has a broad attack surface. Security should therefore be implemented as multiple independent layers rather than relying on the model's instructions alone. Current OWASP GenAI guidance highlights risks such as prompt injection, sensitive information disclosure, supply-chain vulnerabilities, excessive agency, vector and embedding weaknesses, and unbounded consumption, while NIST's AI RMF provides a broader lifecycle-oriented approach to managing AI risks.