Question 1
Q1A Security Operations Center (SOC) is evaluating a new Generative AI (GenAI) tool to automatically summarize incident tickets and propose remediation steps. The SOC manager is developing the governance framework for this implementation. Which of the following represents the MOST significant operational risk that must be addressed in the governance policy before deployment?
Show answer & explanation
Correct answer: C
When utilizing public or cloud-based GenAI tools, the primary governance risk is data leakage. Submitting proprietary incident data, PII, or internal network architecture details to a public LLM can result in that sensitive data being absorbed into the model's training set and potentially exposed to unauthorized parties. The other options represent technical or workflow issues, but data privacy/leakage is the paramount governance risk.