Module 4 Knowledge Check (Self‑Check)
Confirm you understand safe inputs, safe outputs, and incident response.
Questions
-
Which is the safest default approach for sensitive client information?
- A. Paste into any AI tool if you trust the vendor
- B. Minimize and de‑identify; use only approved tools with known controls
- C. Paste everything and ask the tool to “keep it confidential”
- D. Email the prompt to the whole team for review
Suggested answer: B.
Why: Confidentiality controls are procedural and technical; “trust” alone is not a safeguard. -
True or False: If an output is labeled “draft,” it is safe to send to a client without review.
- True
- False
Suggested answer: False.
Why: Drafts can still contain errors or sensitive disclosures. -
What is the first step in AI incident response?
- A. Publish a blog post
- B. Stop the spread and preserve evidence
- C. Delete everything immediately
- D. Ignore it and move on
Suggested answer: B.
Why: You need containment and evidence to assess scope and remediation. -
Which vendor feature most directly supports defensibility?
- A. Fun chat stickers
- B. Configurable retention + audit logs + admin controls
- C. Viral marketing
- D. Unlimited prompt length
Suggested answer: B.
Why: Governance depends on traceability and control.
Action item: Identify your firm’s incident owner and write a one-page AI incident playbook.