Before launching a resident chatbot that answers tax questions, what security activity should the team perform early in design?
Select an answer to reveal the explanation.
Short Explanation
Chatbots get weird prompts and leaky memories if you never threat-model them. Sketch the abuse cases—prompt injection, data bleed—while you're still designing, not after residents are chatting about taxes. Early modeling is cheaper than apologizing.
Full Explanation
Threat modeling applies structured thinking about adversaries, entry points, and undesirable outcomes during design. For conversational systems, abuse cases include prompt injection, unauthorized disclosure, and social engineering of the bot. Performing this work before deployment reduces costly retrofit and aligns with secure design expectations in Domain 1.