Skip to content

312-52 Practice Questions

Prepare for 312-52 with more than an answer.

155 questions in the full set12 sample questionsUpdated Mar 12, 2026
Time limit
360 minutes
Questions on the exam
70
Passing score
70-80%
Level
Professional
Valid for
3 years
Domains covered on the exam 10
  1. Offensive AI and AI System Hacking Methodology10%
  2. AI Reconnaissance and Attack Surface Mapping10%
  3. AI Vulnerability Scanning and Fuzzing10%
  4. Prompt Injection and LLM Application Attacks12%
  5. Adversarial Machine Learning and Model Privacy Attacks12%
  6. Data and Training Pipeline Attacks10%
  7. Agentic AI and Model-to-Model Attacks10%
  8. AI Infrastructure and Supply Chain Attacks10%
  9. AI Security Testing, Evaluation, and Hardening8%
  10. AI Incident Response and Forensics8%
  1. 1

    In the context of AI Incident Response, what is 'Model Drift' and why can it be an Indicator of Compromise (IoC)?

    Show answer details

    Correct answer: A

    Model drift refers to the change in the relationship between input data and target variables over time. While often natural, a sudden, unexplained spike in drift (performance degradation or output shift) is a strong IoC for Data Poisoning attacks or a sustained Adversarial Evasion campaign modifying the input distribution.

  2. 2

    Select TWO methods that are effective for hardening an LLM application against Prompt Injection attacks. (Select TWO)

    Show answer details

    Correct answer: A, C

    Requiring human approval before the agent executes high-impact actions (like database writes or email sends) mitigates the impact of a successful injection.

    Using delimiters (like ...) helps the model distinguish between instructions and data, reducing the success rate of injection.

  3. 3

    True or False: The 'Dan' (Do Anything Now) jailbreak technique relies on creating a hypothetical persona that ignores the model's safety training constraints.

    Show answer details

    Correct answer: A

    True. The DAN jailbreak works by role-playing a persona ('DAN') that is explicitly instructed to disregard all safety filters and policies, effectively bypassing the RLHF (Reinforcement Learning from Human Feedback) safety alignment.

  4. 4

    You are leading a Red Team engagement against a financial institution's new customer service chatbot, which utilizes a Retrieval-Augmented Generation (RAG) architecture. During the reconnaissance phase, you identify that the chatbot retrieves context from unauthenticated public PDF documents hosted on the company's marketing CDN. You plan to execute an Indirect Prompt Injection attack. According to the MITRE ATLAS framework, which specific technique describes this approach where the adversary modifies external data sources to influence the model's behavior?

    Show answer details

    Correct answer: C

    While the attack involves poisoning data, the specific execution mechanism against the LLM via the retrieved context is classified under LLM Prompt Injection (AML.T0051) in MITRE ATLAS, specifically the 'Indirect' sub-technique where the prompt is injected via the data channel rather than the user channel.

  5. 5

    A security analyst is mapping the attack surface of an organization's AI infrastructure. The organization uses a vector database to store embeddings for their internal knowledge base. The analyst discovers that the vector database API port is exposed to the internet without authentication. Which specific component of the AI architecture is most directly compromised, and what is the primary risk associated with this exposure?

    Show answer details

    Correct answer: A

    Vector databases (like Pinecone, Weaviate, Chroma) act as the semantic memory for AI applications. Exposing this allows attackers to query embeddings. Research has shown that original text can often be reconstructed from embeddings (embedding inversion), leading to massive sensitive data leakage.

  6. 6

    You are configuring NVIDIA Garak to scan a deployed LLM for hallucinations and misinformation vulnerabilities. You want to specifically test if the model can be coerced into fabricating citations for non-existent legal cases. Which Garak probe family should you prioritize for this specific assessment?

    Show answer details

    Correct answer: E

    While 'hallucinations' seems correct, Garak specifically organizes probes for fabricating facts and misleading content under the misleading or hallucination families depending on version, but for legal fabrication specifically, the misleading family often contains the relevant tests for creating false narratives. However, hallucinations is the direct category for pure fabrication. In the context of Garak v0.9+, garak.probes.hallucinations is the precise answer for checking fabrication.

Create an account to continue.