AI Security & Compliance interview questions

24 AI Security & Compliance questions from the MLOps & Integration bank, written for Indian campus drives and tech interviews. Every question has a verified answer and an AI-tutor explanation on placd.

Free to start: the 2-minute IT readiness check — six questions and a result.

Take the free IT readiness check

or take a mock interview set up for this area

1. What is Least privilege?

Junior
  1. A.mutual TLS where client and server both present certificates, authenticating service-to-service traffic
  2. B.masking, encrypting or tokenizing personally identifiable information to meet privacy regulation
  3. C.storing credentials in a vault and injecting them at runtime instead of hardcoding them
  4. D.granting an identity only the minimum permissions needed, limiting blast radius if compromised

Answer + AI explanation with Pro

2. Which term means: "granting an identity only the minimum permissions needed, limiting blast radius if compromised"?

Junior
  1. A.Prompt injection
  2. B.Least privilege
  3. C.Secrets management
  4. D.Network segmentation

Answer + AI explanation with Pro

3. Which statement is correct?

Junior
  1. A.Least privilege — mutual TLS where client and server both present certificates, authenticating service-to-service traffic
  2. B.Least privilege — an auditable record of which data and code produced a model, required for regulated AI governance
  3. C.Least privilege — an attack where crafted input overrides an LLM's instructions to leak data or perform unintended actions
  4. D.Least privilege — granting an identity only the minimum permissions needed, limiting blast radius if compromised

Answer + AI explanation with Pro

4. What is Secrets management?

Junior
  1. A.masking, encrypting or tokenizing personally identifiable information to meet privacy regulation
  2. B.granting an identity only the minimum permissions needed, limiting blast radius if compromised
  3. C.role-based access control granting permissions to roles that users or service accounts are bound to
  4. D.storing credentials in a vault and injecting them at runtime instead of hardcoding them

Answer + AI explanation with Pro

5. Which term means: "storing credentials in a vault and injecting them at runtime instead of hardcoding them"?

Junior
  1. A.PII handling
  2. B.Secrets management
  3. C.RBAC
  4. D.Model and data lineage

Answer + AI explanation with Pro

6. Which statement is correct?

Junior
  1. A.Secrets management — isolating workloads into separate subnets/zones so a breach in one cannot reach the others
  2. B.Secrets management — masking, encrypting or tokenizing personally identifiable information to meet privacy regulation
  3. C.Secrets management — granting an identity only the minimum permissions needed, limiting blast radius if compromised
  4. D.Secrets management — storing credentials in a vault and injecting them at runtime instead of hardcoding them

Answer + AI explanation with Pro

7. What is mTLS?

Mid
  1. A.masking, encrypting or tokenizing personally identifiable information to meet privacy regulation
  2. B.isolating workloads into separate subnets/zones so a breach in one cannot reach the others
  3. C.mutual TLS where client and server both present certificates, authenticating service-to-service traffic
  4. D.an auditable record of which data and code produced a model, required for regulated AI governance

Answer + AI explanation with Pro

8. Which term means: "mutual TLS where client and server both present certificates, authenticating service-to-service traffic"?

Mid
  1. A.Network segmentation
  2. B.Secrets management
  3. C.mTLS
  4. D.Prompt injection

Answer + AI explanation with Pro

9. Which statement is correct?

Mid
  1. A.mTLS — an auditable record of which data and code produced a model, required for regulated AI governance
  2. B.mTLS — mutual TLS where client and server both present certificates, authenticating service-to-service traffic
  3. C.mTLS — an attack where crafted input overrides an LLM's instructions to leak data or perform unintended actions
  4. D.mTLS — masking, encrypting or tokenizing personally identifiable information to meet privacy regulation

Answer + AI explanation with Pro

10. What is RBAC?

Mid
  1. A.an attack where crafted input overrides an LLM's instructions to leak data or perform unintended actions
  2. B.masking, encrypting or tokenizing personally identifiable information to meet privacy regulation
  3. C.role-based access control granting permissions to roles that users or service accounts are bound to
  4. D.an auditable record of which data and code produced a model, required for regulated AI governance

Answer + AI explanation with Pro

11. Which term means: "role-based access control granting permissions to roles that users or service accounts are bound to"?

Mid
  1. A.Least privilege
  2. B.Model and data lineage
  3. C.mTLS
  4. D.RBAC

Answer + AI explanation with Pro

12. Which statement is correct?

Mid
  1. A.RBAC — isolating workloads into separate subnets/zones so a breach in one cannot reach the others
  2. B.RBAC — role-based access control granting permissions to roles that users or service accounts are bound to
  3. C.RBAC — storing credentials in a vault and injecting them at runtime instead of hardcoding them
  4. D.RBAC — an auditable record of which data and code produced a model, required for regulated AI governance

Answer + AI explanation with Pro

13. What is PII handling?

Mid
  1. A.an auditable record of which data and code produced a model, required for regulated AI governance
  2. B.storing credentials in a vault and injecting them at runtime instead of hardcoding them
  3. C.masking, encrypting or tokenizing personally identifiable information to meet privacy regulation
  4. D.mutual TLS where client and server both present certificates, authenticating service-to-service traffic

Answer + AI explanation with Pro

14. Which term means: "masking, encrypting or tokenizing personally identifiable information to meet privacy regulation"?

Mid
  1. A.Network segmentation
  2. B.PII handling
  3. C.Least privilege
  4. D.mTLS

Answer + AI explanation with Pro

15. Which statement is correct?

Mid
  1. A.PII handling — mutual TLS where client and server both present certificates, authenticating service-to-service traffic
  2. B.PII handling — masking, encrypting or tokenizing personally identifiable information to meet privacy regulation
  3. C.PII handling — an auditable record of which data and code produced a model, required for regulated AI governance
  4. D.PII handling — storing credentials in a vault and injecting them at runtime instead of hardcoding them

Answer + AI explanation with Pro

16. What is Network segmentation?

Mid
  1. A.mutual TLS where client and server both present certificates, authenticating service-to-service traffic
  2. B.an auditable record of which data and code produced a model, required for regulated AI governance
  3. C.isolating workloads into separate subnets/zones so a breach in one cannot reach the others
  4. D.an attack where crafted input overrides an LLM's instructions to leak data or perform unintended actions

Answer + AI explanation with Pro

17. Which term means: "isolating workloads into separate subnets/zones so a breach in one cannot reach the others"?

Mid
  1. A.mTLS
  2. B.Least privilege
  3. C.Prompt injection
  4. D.Network segmentation

Answer + AI explanation with Pro

18. Which statement is correct?

Mid
  1. A.Network segmentation — role-based access control granting permissions to roles that users or service accounts are bound to
  2. B.Network segmentation — isolating workloads into separate subnets/zones so a breach in one cannot reach the others
  3. C.Network segmentation — mutual TLS where client and server both present certificates, authenticating service-to-service traffic
  4. D.Network segmentation — storing credentials in a vault and injecting them at runtime instead of hardcoding them

Answer + AI explanation with Pro

19. What is Prompt injection?

Senior
  1. A.an attack where crafted input overrides an LLM's instructions to leak data or perform unintended actions
  2. B.storing credentials in a vault and injecting them at runtime instead of hardcoding them
  3. C.mutual TLS where client and server both present certificates, authenticating service-to-service traffic
  4. D.an auditable record of which data and code produced a model, required for regulated AI governance

Answer + AI explanation with Pro

20. Which term means: "an attack where crafted input overrides an LLM's instructions to leak data or perform unintended actions"?

Senior
  1. A.Model and data lineage
  2. B.RBAC
  3. C.mTLS
  4. D.Prompt injection

Answer + AI explanation with Pro

21. Which statement is correct?

Senior
  1. A.Prompt injection — storing credentials in a vault and injecting them at runtime instead of hardcoding them
  2. B.Prompt injection — role-based access control granting permissions to roles that users or service accounts are bound to
  3. C.Prompt injection — an attack where crafted input overrides an LLM's instructions to leak data or perform unintended actions
  4. D.Prompt injection — an auditable record of which data and code produced a model, required for regulated AI governance

Answer + AI explanation with Pro

22. What is Model and data lineage?

Senior
  1. A.granting an identity only the minimum permissions needed, limiting blast radius if compromised
  2. B.an auditable record of which data and code produced a model, required for regulated AI governance
  3. C.role-based access control granting permissions to roles that users or service accounts are bound to
  4. D.storing credentials in a vault and injecting them at runtime instead of hardcoding them

Answer + AI explanation with Pro

23. Which term means: "an auditable record of which data and code produced a model, required for regulated AI governance"?

Senior
  1. A.RBAC
  2. B.Secrets management
  3. C.Model and data lineage
  4. D.Network segmentation

Answer + AI explanation with Pro

24. Which statement is correct?

Senior
  1. A.Model and data lineage — role-based access control granting permissions to roles that users or service accounts are bound to
  2. B.Model and data lineage — masking, encrypting or tokenizing personally identifiable information to meet privacy regulation
  3. C.Model and data lineage — an auditable record of which data and code produced a model, required for regulated AI governance
  4. D.Model and data lineage — mutual TLS where client and server both present certificates, authenticating service-to-service traffic

Answer + AI explanation with Pro

Free to start

Start with a free readiness check

Sign up free for the 2-minute IT readiness check and a scored result. Answers, explanations and the AI tutor on every AI Security & Compliance question come with Pro.

Take the free IT readiness check

or take a mock interview set up for this area

24,000+ questions & coding problemsSoftware & IT16,274 questionsGovernment jobs26 examsAptitudenew questions every timeAI practice interviewwith feedback65 topics to practiseMechanical1,149 questionsGATE ME9 papersEngineering Mathematics381 questions2-minute checkfreeDSA Problems1,422Civil1,005 questionsGATE CE9 papersCS Fundamentals1,209 questionsYour scores6 skillsSystem Design25Electrical / EEE1,047 questionsGATE EE9 papersRun your codeC++ · Java · PythonLow-Level Design144Electronics & Comm.975 questionsGATE EC9 papersAI help on every questionFull-Stack6,282Chemical1,005 questionsGATE CH9 papersAI whiteboardsystem designWork abroadEurope · remote · transfersESE ME1 paperGATE practice papers2019–2026ESE CE1 paperDate alertsbefore the last dateESE EE1 paperBehavioural courseHR round practiceESE ET1 paperResume optimizerProSSC JE ME1 paperApplication trackerSSC JE CE1 paperCompany-wise prepSSC JE EE1 paperRole roadmapsRRB JE1 subjectPriced in ₹UPI · cardsISRO SC1 paperGATE CS9 papersIBPS SO IT1 paperUGC NET CS1 paperSSC CGL26 papersIBPS PO26 papersRRB NTPC26 papersSSC CHSL26 papersIBPS Clerk26 papersSBI Clerk26 papersRRB Group D26 papersSSC CPO26 papersSSC GD26 papers