1. Exception & Waiver Management intermediate

    Your exception register has grown from 12 to 90 waivers in eighteen months and none have been closed. What does this tell you and what do you do?

    2 min answer governanceexceptionsstandardsrisk
  2. Model Documentation intermediate

    A model makes decisions affecting people. What documentation is actually required, and who is it for?

    2 min answer gustomodel-documentationlimitationsaccountability
  3. Model Documentation intermediate Multiple choice

    A support assistant answers questions by retrieving from an internal wiki and a ticket archive and passing the result to a hosted model. Your model documentation template has a training-data section you cannot fill because you did not train the model. Which section should replace it?

    2 min answer model-documentationragcorpus-provenanceretention
  4. Model Documentation intermediate

    What should model documentation contain, and who is it actually for?

    1 min answer model-documentationtransparencylimitationsreuse
  5. Model Documentation intermediate

    Your model documentation for a customer-facing assistant records the provider's model version it was validated against and the evaluation scores from that run. The Azure deployment of that hosted model is set to auto-update to the provider's default version. Overnight the provider's default changes. What happens next?

    3 min answer model-documentationversioningvalidationazure
  6. Risk Appetite intermediate

    A board sets a risk appetite statement: no production personal data in non-production environments, with no exceptions. Engineering accepts it. What has the organisation bought, what is it paying, and when does the cost surface?

    2 min answer risk-appetitetest-datasynthetic-datareproduction
  7. Risk Assessment Methods intermediate

    A risk register holds 34 risks scored on a 5x5 likelihood-by-impact grid. The top six are funded this year and the other 28 are "monitored". Six of the monitored risks describe different systems failing when the corporate identity provider is unavailable. Review the register. What would you change?

    3 min answer risk-registercommon-causecorrelationquantification
  8. Risk Assessment Methods intermediate

    How would you decide which of twenty identified risks to actually address?

    2 min answer riskprioritisationappetiteacceptance
  9. Security Design Review intermediate

    A security design review consistently produces findings that are expensive to act on. What is wrong with the process?

    2 min answer workosdesign-reviewtimingthreat-model
  10. Security Design Review intermediate

    Security reviews happen the week before launch. Findings are usually rejected as too late to fix. How do you change this?

    2 min answer securityprocessinfluence
  11. Security Design Review intermediate

    Your security design review template asks for data flows, trust boundaries, authentication and encryption. A team submits a support assistant that reads customer ticket text and calls three internal APIs with a service account, one of which issues refunds. The template produces no findings. What would you add to it, and what would you leave alone?

    3 min answer security-design-reviewprompt-injectionconfused-deputyagents
  12. Segregation of Duties intermediate

    An audit finds 40 engineers with permanent production database read access. The team says they need it for support. Resolve it.

    2 min answer accesscontrolsinsider-risk