Section 2 Quiz

Test Your Knowledge: Security for AI Blueprint Overview

Let’s see how much you’ve learned!

This quiz tests your understanding of the 6-layer Blueprint framework, the four control types and how they differ, coverage versus stopping power, how the layers interrelate, and the role of TrendAI Vision One as a unified platform.

--- shuffle_answers: true shuffle_questions: false --- ## A security team is evaluating their AI deployment against the Security for AI Blueprint. They've secured their training data with DSPM, scanned their model containers, and configured IDS/IPS rules. Which Blueprint layers have they addressed? > Hint: Map each control to the specific layer it belongs to. - [ ] Layers 1, 2 and 3 -- data, models and the underlying infrastructure > IDS/IPS is not Layer 3 (Infrastructure). Layer 3 covers posture management (AI-SPM), not network intrusion detection. - [x] Layers 1, 2 and 6 -- data (DSPM), models (scanning), zero-day (IDS/IPS) > Correct! DSPM maps to Layer 1 (Secure Your Data), container scanning maps to Layer 2 (Secure Your AI Models), and IDS/IPS maps to Layer 6 (Defend Against Zero-Day Exploits). They've covered three layers but still need Layer 3 (Infrastructure posture), Layer 4 (User protection), and Layer 5 (Access controls). - [ ] Layers 1, 3 and 5 -- data, infrastructure and service access > Container scanning is Layer 2 (Models), not Layer 3 (Infrastructure). IDS/IPS is Layer 6 (Zero-Day), not Layer 5 (Access). - [ ] All six layers -- between them these three controls give complete coverage > Three controls cannot cover all six layers. Each layer addresses a distinct protection domain. The team still needs infrastructure posture management (Layer 3), user protection (Layer 4), and access controls (Layer 5). ## Why does the Blueprint use a defense-in-depth approach with six overlapping layers rather than a single comprehensive security layer? > Hint: Think about what happens when any single security control fails. - [ ] Six layers are needed because AI systems are six times more complex than traditional ones > The number of layers isn't derived from relative complexity. Defense in depth is a design principle about redundancy and independent failure modes. - [ ] Each layer addresses a different compliance requirement, and the regulations mandate six of them > The Blueprint's six layers are based on AI architecture domains, not compliance requirements. Compliance is addressed through the security controls within each layer. - [x] Each layer protects independently, so bypassing one still leaves the attacker facing the others > Correct! Defense in depth ensures redundancy. A prompt injection that bypasses Layer 5's prompt filter still faces Layer 6's anomaly detection, Layer 3's posture monitoring, and Layer 1's data access controls. The layers are independent -- bypassing one doesn't automatically bypass the others, forcing attackers to defeat multiple defense mechanisms. - [ ] The six layers correspond one-to-one with the six stages of the AI lifecycle > The Blueprint layers map to protection domains (data, models, infrastructure, users, access, zero-day), not lifecycle stages. The AI-adapted DevSecOps pipeline from Section 1 covers lifecycle stages. ## According to the Blueprint's layer interrelationship model, how does Layer 1 (Data) inform Layer 5 (Access)? > Hint: Think about what Layer 1 knows that Layer 5 needs for its filtering decisions. - [ ] Layer 1 supplies the encryption keys that Layer 5 uses for API authentication > Encryption key management is infrastructure-level, not a direct Layer 1 to Layer 5 relationship. The connection between these layers is about data classification informing access decisions. - [x] Layer 1's classification tells Layer 5 which sensitivity levels need stricter response filtering > Correct! Layer 1's data classification directly informs Layer 5's filtering policies. When Layer 1 identifies that RAG corpora contain PII or sensitive business logic, Layer 5's response filtering is configured to apply more aggressive redaction and blocking rules. The layers share information to create more intelligent defense. - [ ] Layer 1 forwards blocked data requests to Layer 5 for a second round of filtering > Layer 1 manages data assets and access controls, not request routing. The relationship flows from Layer 1's classification intelligence to Layer 5's policy configuration. - [ ] Layer 5 operates entirely independently, because access and data controls are separate domains > The Blueprint explicitly states that layers are not isolated silos -- they share data and inform each other's policies. Layer 1 and Layer 5 have a direct information-sharing relationship. ## An attacker attempts to extract PII from a model by crafting a prompt injection that bypasses Layer 5's prompt filter. The injection reaches the model, and the model generates a response containing a customer's email address. What prevents this data from reaching the attacker? > Hint: Consider the multiple stages of Layer 5's request flow and what happens after the model generates its response. - [ ] Layer 1's DSPM detects the PII in flight and blocks the response > DSPM operates on data assets at rest and in transit, not on model inference responses in real time. The real-time defense against PII in responses is at the access layer. - [ ] Layer 2's model scanning prevents the model from generating PII at all > Layer 2 scans model artifacts and containers, not runtime model outputs. Model scanning is a pre-deployment control. - [x] Layer 5's output-side response filtering detects the PII and redacts it before delivery > Correct! Layer 5 operates in both directions -- input filtering catches injection attempts, and output filtering catches data leakage in responses. Even though the injection bypassed the input filter, the AI Gateway's output filter scans the model's response for PII patterns. The email address is detected and redacted before the response leaves the system. This is defense in depth within a single layer. - [ ] Layer 6's behavioral detection flags the unusual response and blocks it in time > While Layer 6 might eventually detect the anomalous behavior pattern, the immediate defense against PII in responses is Layer 5's response filtering, which operates on every response in real time. ## What is the primary role of TrendAI Vision One in the Blueprint architecture? > Hint: Consider the challenge of managing six separate defense layers. - [ ] It removes the need for individual layer controls by providing one consolidated solution > Vision One doesn't replace layer-specific controls. Each layer has its own products and capabilities. Vision One provides unified visibility across all of them. - [ ] It is the Layer 5 AI Gateway component under a different product name > While Vision One includes AI Gateway capabilities, its role in the Blueprint is broader than any single layer. - [x] It correlates signals from all six layers into one view, without replacing any of them > Correct! Vision One's primary role is unification. Rather than managing six separate security consoles, Vision One correlates alerts across all layers -- tracing an attack from initial access (Layer 5) through infrastructure impact (Layer 3) to data exposure risk (Layer 1) in one investigation timeline. This reduces mean time to detection and eliminates visibility gaps between layers. - [ ] It supplies the zero-day threat intelligence consumed by Layer 6, and nothing else > Vision One contributes to all six layers, not just Layer 6. Its unified platform approach is the distinguishing characteristic in the Blueprint architecture. ## A prompt injection reaches a deployed assistant. Layer 5's input filter misses it, Layer 5's output filter redacts the PII from the response, and Layer 3's AI-SPM raises an alert on anomalous endpoint access. What did Layer 3 contribute? > Hint: Layer 3 is a detective control. Ask what changes because of its alert, given the attack was already handled elsewhere. - [ ] It blocked the second stage of the attack once the input filter had failed > AI-SPM is not in the request path and cannot block anything. The interception here was entirely Layer 5's output filter. - [ ] It closed the gap in the input filter so the same payload fails next time > Rule tuning is a Layer 5 activity. AI-SPM reports on infrastructure configuration and access patterns; it does not author or update prompt filters. - [x] It made the event legible as an attack rather than an unlucky prompt > Correct! Layer 3 stopped nothing -- the redaction was Layer 5's. What its alert adds is evidence: without it, a redacted response is indistinguishable from routine filtering, and nobody investigates. Detective layers convert a handled event into a known one, which is what triggers rule tuning, credential review, and threat intelligence. That is a real contribution, and it is not interception. - [ ] Nothing, since the attack was already handled by the layer that intercepted it > This is the trap in reading defense in depth as a queue of gates. Detection has value independent of interception: an architecture that redacts silently never learns it is under attack, and never improves. ## Layer 3 (Infrastructure) is named in 10 of the 20 OWASP categories and Layer 2 (Models) in only 3. A team cites this to justify deploying Layer 3 and deferring Layer 2. What is wrong with the reasoning? > Hint: Compare what the two layers do, not how many categories each one is named in. - [ ] Nothing is wrong -- broader OWASP coverage is exactly how deployment order should be decided > Coverage is a reasonable starting heuristic, but it counts categories a layer is named in, not what the layer does about them. Two layers with the same count can have very different stopping power. - [x] Layer 3 detects and never intercepts, so it cannot substitute for a build-time control > Correct! Layer 3 is a detective control: AI-SPM reports misconfigurations and anomalous access, and blocks nothing. Layer 2 is preventive and acts before the model serves traffic. If a backdoored or unsigned model is deployed, Layer 3 may eventually surface odd behavior, but the compromise is already inside the system every other layer is protecting. The layers are not substitutes, so a coverage count cannot rank them on its own. - [ ] Layer 2's coverage number is understated, and it really defends more categories than three > Three is the correct count from the chapter's master mapping table -- LLM04, LLM05 and ASI04. The problem is the inference drawn from the numbers, not the numbers. - [ ] Layer 2 should always be deployed before Layer 3 because it has the lower layer number > Layer numbering labels protection domains; it is not a deployment order. The section makes this explicit -- dependencies run in both directions across the numbering. ## Your assistant is protected by Layer 3 (AI-SPM), Layer 6 (anomaly detection and threat intelligence), and Layer 4 (human-in-the-loop approval on sensitive actions). Leadership notes this covers 16 of the 20 OWASP categories. What is the most significant remaining exposure? > Hint: Sort the three deployed layers by control type before counting anything. - [ ] Coverage of the four remaining categories, which no deployed layer addresses > Four uncovered categories is a real gap, but it is the smaller problem. The larger one is visible in what the 16 covered categories are actually getting. - [ ] Alert volume from three layers reporting on the same underlying events > Correlation load is a genuine operational cost and the reason unified platforms exist, but it is a consequence of the architecture rather than the exposure itself. - [x] Nothing in the deployed set can refuse a request, so no attack is ever intercepted > Correct! Layers 3 and 6 are detective and Layer 4 acts on the human at the far end -- none of them is in the request path. The deployment will observe a prompt injection, alert on it, and deliver the response anyway, because Layer 5 is the only layer that filters requests and responses. The 16-of-20 figure is accurate and misleading: high coverage assembled entirely from detective layers is observability, not defense. - [ ] Layer 4's human approval step will not scale to the request volume of an assistant > Human-in-the-loop is deliberately reserved for sensitive actions rather than every request, so volume is manageable. The gap is the absence of any in-path control at all. ## A startup is deploying its first LLM application and can only implement ONE Blueprint layer initially due to limited security budget. The application is a customer-facing chatbot with access to a product knowledge base. Which layer should they prioritize FIRST? > Hint: Consider which layer intercepts the most attack categories for a customer-facing chatbot, and think about what the most immediate runtime threats are for this deployment scenario. - [ ] Layer 1 (Data) -- data is the foundation of the stack, so it should always be built first > Layer 1 is foundational in the architecture diagram, but "foundational" doesn't mean "implement first." For a customer-facing chatbot, the immediate threats are prompt injection, data leakage through responses, and abuse -- all runtime attacks at the access boundary. Data classification can wait until after the live attack surface is controlled. - [ ] Layer 6 (Zero-Day) -- novel attacks are the most dangerous, so this defense comes first > Zero-day defense catches novel threats, but most attacks against a new chatbot will use known techniques (prompt injection, jailbreaking, PII extraction). Layer 6 is most valuable after other layers generate the threat intelligence baselines it depends on. Without Layer 5 feeding it blocked-attack data, Layer 6 has limited anomaly detection context. - [x] Layer 5 (Access) -- it is the only in-path layer and the broadest, at 11 of 20 categories > Correct! Layer 5 wins on both axes at once for this deployment. It has the widest coverage of any single layer, and it is the only one that can refuse a request or redact a response while it is happening -- which matters because a customer-facing chatbot's live exposure is prompt injection (LLM01), sensitive information disclosure (LLM02) and hidden context exposure (LLM08), all of them Layer 5 rows. It also feeds the others: blocked-attack data is what Layer 6 builds its anomaly baselines from. Deploying any detective layer first would surface these attacks without stopping any of them. - [ ] Layer 3 (Infrastructure) -- posture management prevents the misconfigurations that expose everything > AI-SPM is important for mature deployments, but a startup's first priority is defending the live customer interaction boundary. Infrastructure posture management monitors configurations and risk -- it doesn't intercept prompt injection or filter PII from responses. For a single chatbot deployment, Layer 3's value grows after the basic access controls are in place.