Free Isaca AAISM Actual Exam Questions - Question 2 Discussion

Question No. 2
Which of the following BEST reduces the risk of exposing sensitive data through the output of large
language models (LLMs) in applications?
Select one option, then reveal solution.
US
IR
Irfan R.
2026-01-30

B—finding hidden vulnerabilities before deployment seems most proactive here.

0
IR
Irfan R.
2026-01-27

D – limiting access post-output definitely cuts down exposure chances.

0
IR
Irfan R.
2026-01-22

Option B is worth considering since adversarial testing helps identify hidden vulnerabilities that might cause leaks before the model is used widely, which is a proactive way to reduce risk.

0
IR
Irfan R.
2026-01-22

C/D? Sanitization cuts out sensitive info upfront, but least privilege limits who can even see the output, so both reduce risk differently. In terms of output exposure though, C feels slightly stronger.

0
IR
Irfan R.
2026-01-21

Makes sense that sanitization is key, but I think B helps too since adversarial testing can reveal hidden leaks before deployment. I’d go with B to catch issues proactively.

0
IR
Irfan R.
2026-01-15

C imo, sanitizing data before training or output is key here.

0