
GIAC AI Security Automation Engineer
Domain 3Objective 1
Artificial Intelligence Fundamentals GASAE Practice Questions (Page 7)
Part of the AI and Adversary Emulation domain, which makes up ~19% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~13–23 in this domain), expect 7–12 from this objective — we provide 36 practice questions to prepare you well beyond it. (estimate)
36questions here
8free pages
5concepts
Questions 31–35
- 31
Which metric is commonly used to evaluate the effectiveness of an AI security tool in terms of false positives?
Select an answer first - 32
A red team is planning an adversary emulation exercise against an AI-driven endpoint detection and response (EDR) platform. The goal is to test whether the EDR's AI model can be evaded by an attacker who has access to the model's architecture and weights. Which attack technique is most appropriate?
Select an answer first - 33
A security engineer wants to build a system that automatically categorizes network traffic as normal or suspicious. The engineer has a large dataset of labeled traffic samples. Which machine learning approach is most appropriate for this task?
Select an answer first - 34
Which statement best describes the relationship between machine learning and security automation?
Select an answer first - 35
During an adversary emulation exercise, a red team successfully crafts a malicious file that the AI-based antivirus classifies as benign. The team did not have access to the model's internals but used a separate model trained on similar data to generate the file. Which attack technique did the red team employ?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GASAE” is a trademark of its owner, used for identification only.