Your SOC team wants to use an external AI assistant to summarize phishing email bodies and SIEM alerts. Before uploading any data, what should the analyst do to reduce data leakage risk?
Select an answer to reveal the explanation.
Short Explanation
Think of an external AI service like a mailroom: if you hand over raw logs, you're sending private envelopes outside the building. Redact or tokenize customer identifiers and secrets first, then send only the minimum needed. Encryption won't save you if you're shipping sensitive content in the first place.
Full Explanation
Using external AI services introduces a data-leakage pathway because sensitive telemetry may leave the organization's control. The analyst should first classify the data, remove or tokenize customer identifiers, secrets, and other sensitive fields, and verify the provider's terms for retention, secondary use, and training on submitted content. Only the minimum necessary fields should be sent, ideally through a controlled gateway or approved enterprise tenant. Encryption in transit and at rest protects data from interception or storage exposure, but it does not prevent the provider from ingesting sensitive content into its service. Agreeing to standard terms of service is also insufficient, because default terms may allow data retention, model training, or subprocessor access without organization-specific safeguards. A vendor promise to delete logs after a response is not enough by itself; without contractual retention limits, training opt-outs, audit rights, and technical DLP controls, sensitive data may still be exposed. Exam caveat: the CS0-004 exam expects analysts to apply AI data-handling concepts, not memorize a particular AI vendor's interface. Operational check: create an AI usage runbook that lists allowed log fields, mandatory redactions, approved enterprise endpoints, and a ticket workflow for reviewing provider data-processing terms.