Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC AI Security Automation Engineer

Domain 3Objective 1

Artificial Intelligence Fundamentals GASAE Practice Questions (Page 6)

Part of the AI and Adversary Emulation domain, which makes up ~19% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~13–23 in this domain), expect 7–12 from this objective — we provide 36 practice questions to prepare you well beyond it. (estimate)

36questions here
8free pages
5concepts

Questions 26–30

  1. 26expert · hard

    A red team is tasked with evaluating the security of an AI-based authentication system that uses behavioral biometrics. The team has access to the system's API but not its internal model. They want to test whether an attacker can impersonate a legitimate user. Which approach best tests this?

    Select an answer first
  2. 27application · medium

    A red team is conducting an adversary emulation exercise against a company's AI-based security automation platform. The goal is to test whether the platform's automated response actions can be tricked into performing harmful actions. Which technique best simulates a realistic adversary?

    Select an answer first
  3. 28expert · hard

    A security team is evaluating two AI-based intrusion detection systems. System A has a high detection rate but generates many false positives. System B has a lower detection rate but very few false positives. The team's SOC has limited staff and cannot afford to investigate many false alarms. Which system should they choose, and why?

    Select an answer first
  4. 29application · medium

    A SOC wants to reduce the time to detect and respond to incidents. They plan to use AI to automate the correlation of alerts from multiple sources and suggest response actions. Which AI capability is most directly relevant?

    Select an answer first
  5. 30application · medium

    A security team has deployed an AI model that classifies URLs as malicious or benign. They want to measure how well the model performs on real-world data, where malicious URLs are rare. Which evaluation metric is most appropriate to assess the model's ability to correctly identify malicious URLs without overwhelming analysts with false alarms?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GASAE” is a trademark of its owner, used for identification only.