
GIAC AI Security Automation Engineer
Domain 3Objective 1
Artificial Intelligence Fundamentals GASAE Practice Questions (Page 1)
Part of the AI and Adversary Emulation domain, which makes up ~19% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~13–23 in this domain), expect 7–12 from this objective — we provide 36 practice questions to prepare you well beyond it. (estimate)
36questions here
8free pages
5concepts
Questions 1–5
- 1
A red team is tasked with evaluating an AI-based intrusion detection system (IDS) that uses a neural network to classify network traffic. The team wants to determine whether the IDS can be evaded by an attacker who has no knowledge of the model's internals but can query it with crafted inputs. Which approach best matches this objective?
Select an answer first - 2
A security operations center uses an AI-based email gateway that flags phishing attempts. The team notices that the model's detection rate drops sharply after a legitimate marketing campaign uses a new email template with unusual HTML structure. Which action best addresses the model's performance gap while minimizing disruption to operations?
Select an answer first - 3
A security operations center (SOC) receives thousands of low-fidelity alerts daily. Analysts are overwhelmed and miss critical incidents. The SOC manager wants to use AI to improve detection without increasing headcount. Which approach best leverages AI for this goal?
Select an answer first - 4
A security team wants to automate the initial triage of security alerts using AI. They have a large volume of historical alerts, some of which were confirmed as true positives and others as false positives. The team wants the system to learn from these past decisions to prioritize new alerts. Which AI approach should they use?
Select an answer first - 5
A security team is planning an adversary emulation exercise against their AI-based endpoint detection and response (EDR) system. The goal is to test whether the EDR can detect a known attacker technique that uses PowerShell to download and execute a payload. The team has limited time and cannot modify the EDR's training data. Which approach best aligns with adversary emulation principles?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GASAE” is a trademark of its owner, used for identification only.