A SOC analyst asks an AI triage assistant to summarize alerts. The assistant sometimes proposes disabling hosts and includes internal ticket IDs in external vendor queries. Which control best constrains this AI security tool from unsafe actions and sensitive disclosure?
Select an answer to reveal the explanation.
Short Explanation
Think of AI guardrails like the seatbelt and airbag in a self-driving SOC tool: they don't make the model smarter, they stop it from doing something stupid. If your assistant can disable a host or leak ticket IDs, you need input and output guardrails to block dangerous actions and scrub sensitive data before results leave the tool. Don't confuse that with retraining or rate limits, which tune behavior but don't enforce safe boundaries.
Full Explanation
Guardrails are policy controls around an AI security tool that constrain what it may do and what it may reveal. For a triage assistant, action guardrails can block or require approval for high-risk commands, while data guardrails can filter, redact, or mask sensitive fields before output leaves the tool. Input validation can reject requests that try to bypass policy, and output validation can stop confidential identifiers from crossing trust boundaries. Retraining the model on curated incident data changes learned behavior and may reduce errors, but it does not provide deterministic enforcement against unsafe actions or disclosures. Rate-limiting outbound API calls can reduce abuse or flooding, yet it does not inspect payload content or stop a permitted request from exposing ticket identifiers. Prompt injection testing identifies weaknesses in prompt construction, but it is an assessment method rather than an enforced runtime control. Exam caveat: CS0-004 expects you to distinguish AI governance and safety controls from general model improvement or API management controls. Operational check: Review the assistant's allowed actions and submit a benign request containing a simulated ticket ID to confirm redaction and approval.