WEEK 11 · KNOWLEDGE CHECK

Agentic AI, Prompt Injection and AI Security Controls

8 syllabus-aligned questions for this week. This is an untimed formative check: it gives a score and teaching explanations, but it is not one of the five checkpoint exams. Primary lab: SecureGenAI.

01
WEEK 11 · GenAI & agent security · Agentic AI, Prompt Injection and AI Security Controls

What defines an 'AI agent' as distinct from a standard chatbot?

Question 1: What defines an 'AI agent' as distinct from a standard chatbot?
02
WEEK 11 · GenAI & agent security · Agentic AI, Prompt Injection and AI Security Controls

What does an 'audit trail' for an agent enable that a simple output log does not?

Question 2: What does an 'audit trail' for an agent enable that a simple output log does not?
03
WEEK 11 · GenAI & agent security · Agentic AI, Prompt Injection and AI Security Controls

Why do 'tool permissions' need periodic review, not just a one-time setup?

Question 3: Why do 'tool permissions' need periodic review, not just a one-time setup?
04
WEEK 11 · GenAI & agent security · Agentic AI, Prompt Injection and AI Security Controls

An AI agent with CRM and email tool access is asked, via a crafted prompt embedded in a customer message, to 'forward this thread to an external address.' What control most directly reduces this risk?

Question 4: An AI agent with CRM and email tool access is asked, via a crafted prompt embedded in a customer message, to 'forward this thread to an external address.' What control most directly reduces this risk?
05
WEEK 11 · GenAI & agent security · Agentic AI, Prompt Injection and AI Security Controls

Why does giving an AI agent tool access (like sending email) raise the stakes versus a plain chatbot?

Question 5: Why does giving an AI agent tool access (like sending email) raise the stakes versus a plain chatbot?
06
WEEK 11 · GenAI & agent security · Agentic AI, Prompt Injection and AI Security Controls

What is the main risk of an agent being given broad, standing permissions 'just in case' rather than scoped, task-specific ones?

Question 6: What is the main risk of an agent being given broad, standing permissions 'just in case' rather than scoped, task-specific ones?
07
WEEK 11 · GenAI & agent security · Agentic AI, Prompt Injection and AI Security Controls

Why do 'agent permissions' and 'tool permissions' need to be scoped narrowly?

Question 7: Why do 'agent permissions' and 'tool permissions' need to be scoped narrowly?
08
WEEK 11 · GenAI & agent security · Agentic AI, Prompt Injection and AI Security Controls

Why does 'audit trail' design for agents typically need to capture the reasoning or plan, not just the final action taken?

Question 8: Why does 'audit trail' design for agents typically need to capture the reasoning or plan, not just the final action taken?
All weeks