Microsoft AB-100 Agent Model and Grounding Security Practice Test

 

Topic 15 covers Agent, Model and Grounding Security for Microsoft AB-100, using the current skills measured as of July 22, 2026 and primary Microsoft documentation. For broader exam preparation, review the AB-100 Exam Dumps page. These are original practice questions, and every option includes a scenario-specific explanation.

Question 1

A pilot for agent, model and grounding security reaches a decision point for the grounding security team. The current solution leaves identity context for delegated agent actions unresolved, and the gap is now affecting the stated business or technical requirement. Which approach best fits the requirement?

  1. Prevent exfiltration through an overprivileged action.
  2. Choose identity context for delegated agent actions.
  3. Assess an untrusted model dependency before adoption.
  4. Treat external website content as untrusted during computer use.
  5. Restrict publication to an approved audience.

Correct Answer: B

 

Correct Answer

Answer B is correct because This is correct because it applies the reserved architecture decision—choose identity context for delegated agent actions—to the decisive constraint in the scenario. It keeps the action at the appropriate agent, model and grounding security boundary and produces a result that can be verified before wider deployment.

Incorrect Answers

Answer A is incorrect because This is not the best choice because it addresses the adjacent decision ‘prevent exfiltration through an overprivileged action’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer C is incorrect because This is not the best choice because it addresses the adjacent decision ‘assess an untrusted model dependency before adoption’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer D is incorrect because This is not the best choice because it addresses the adjacent decision ‘treat external website content as untrusted during computer use’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer E is incorrect because This is not the best choice because it addresses the adjacent decision ‘restrict publication to an approved audience’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

 

Question 2

An AI security architecture review is reviewing agent, model and grounding security. The review has identified a specific issue: scope tool permissions to required business operations. Which decision is most appropriate?

  1. Constrain model exposure to approved network paths.
  2. Mitigate unbounded execution caused by repeated agent delegation.
  3. Revoke access for a retired agent without disabling shared services.
  4. Treat output filtering separately from authorization enforcement and evaluate each with its own evidence.
  5. Scope tool permissions to required business operations.

Correct Answer: E

 

Correct Answer

Answer E is correct because This is correct because it applies the reserved architecture decision—scope tool permissions to required business operations—to the decisive constraint in the scenario. It keeps the action at the appropriate agent, model and grounding security boundary and produces a result that can be verified before wider deployment.

Incorrect Answers

Answer A is incorrect because This is not the best choice because it addresses the adjacent decision ‘constrain model exposure to approved network paths’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer B is incorrect because This is not the best choice because it addresses the adjacent decision ‘mitigate unbounded execution caused by repeated agent delegation’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer C is incorrect because This is not the best choice because it addresses the adjacent decision ‘revoke access for a retired agent without disabling shared services’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer D is incorrect because This is not the best choice because it addresses the adjacent decision ‘separate output filtering from authorization enforcement’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

 

Question 3

A pilot for agent, model and grounding security reaches a decision point for the AI security architecture review. Stakeholders are treating maker privileges and runtime agent permissions as the same decision, which is obscuring the actual control boundary. What is the best design choice?

  1. Limit resource exhaustion from adversarially large inputs.
  2. Protect secrets used in model-serving infrastructure.
  3. Separate maker privileges from runtime agent permissions.
  4. Reject a user attempt to override an approval requirement.
  5. Restrict access to a deployed model endpoint.

Correct Answer: C

 

Correct Answer

Answer C is correct because This is correct because it applies the reserved architecture decision—separate maker privileges from runtime agent permissions—to the decisive constraint in the scenario. It keeps the action at the appropriate agent, model and grounding security boundary and produces a result that can be verified before wider deployment.

Incorrect Answers

Answer A is incorrect because This is not the best choice because it addresses the adjacent decision ‘limit resource exhaustion from adversarially large inputs’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer B is incorrect because This is not the best choice because it addresses the adjacent decision ‘protect secrets used in model-serving infrastructure’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer D is incorrect because This is not the best choice because it addresses the adjacent decision ‘reject a user attempt to override an approval requirement’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer E is incorrect because This is not the best choice because it addresses the adjacent decision ‘restrict access to a deployed model endpoint’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

 

Question 4

Before a wider rollout of agent, model and grounding security, the agent trust-boundary review reviews the current evidence. The current solution leaves credentials used by external connectors unresolved, and the gap is now affecting the stated business or technical requirement. Which decision is most appropriate?

  1. Validate tool arguments before executing a destructive operation.
  2. Protect credentials used by external connectors.
  3. Treat model-management rights separately from inference rights and evaluate each with its own evidence.
  4. Verify integrity before promoting a model artifact.
  5. Threat-model the agent, model, tools, and grounding boundary, then verify least-privilege access and data-flow controls.

Correct Answer: B

 

Correct Answer

Answer B is correct because This is correct because it applies the reserved architecture decision—protect credentials used by external connectors—to the decisive constraint in the scenario. It keeps the action at the appropriate agent, model and grounding security boundary and produces a result that can be verified before wider deployment.

Incorrect Answers

Answer A is incorrect because This is not the best choice because it addresses the adjacent decision ‘validate tool arguments before executing a destructive operation’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer C is incorrect because This is not the best choice because it addresses the adjacent decision ‘separate model-management rights from inference rights’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer D is incorrect because This is not the best choice because it addresses the adjacent decision ‘verify integrity before promoting a model artifact’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer E is incorrect because This is a useful verification step after the primary architecture decision, but it does not by itself resolve the decision the scenario asks for. The design choice must be made first, and this evidence can then confirm that the chosen approach behaves as intended.

 

Question 5

A production-readiness review of agent, model and grounding security gives the AI security architecture review new evidence. The review has identified a specific issue: constrain agent access to approved network destinations. What should the architect recommend?

  1. Constrain agent access to approved network destinations.
  2. Treat external website content as untrusted during computer use.
  3. Preserve user-specific permissions during grounding retrieval.
  4. Handle malicious instructions embedded in a retrieved document.
  5. Protect a custom model artifact from unauthorized replacement.

Correct Answer: A

 

Correct Answer

Answer A is correct because This is correct because it applies the reserved architecture decision—constrain agent access to approved network destinations—to the decisive constraint in the scenario. It keeps the action at the appropriate agent, model and grounding security boundary and produces a result that can be verified before wider deployment.

Incorrect Answers

Answer B is incorrect because This is not the best choice because it addresses the adjacent decision ‘treat external website content as untrusted during computer use’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer C is incorrect because This is not the best choice because it addresses the adjacent decision ‘preserve user-specific permissions during grounding retrieval’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer D is incorrect because This is not the best choice because it addresses the adjacent decision ‘handle malicious instructions embedded in a retrieved document’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer E is incorrect because This is not the best choice because it addresses the adjacent decision ‘protect a custom model artifact from unauthorized replacement’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

 

Question 6

A production-readiness review of agent, model and grounding security gives the model security group new evidence. The current solution leaves explicit approval for a high-impact action unresolved, and the gap is now affecting the stated business or technical requirement. What is the best design choice?

  1. Constrain a tool response that requests unrelated data access.
  2. Limit access to sensitive training material.
  3. Treat model-tuning access separately from production inference access and evaluate each with its own evidence.
  4. Require explicit approval for a high-impact action.
  5. Treat output filtering separately from authorization enforcement and evaluate each with its own evidence.

Correct Answer: D

 

Correct Answer

Answer D is correct because This is correct because it applies the reserved architecture decision—require explicit approval for a high-impact action—to the decisive constraint in the scenario. It keeps the action at the appropriate agent, model and grounding security boundary and produces a result that can be verified before wider deployment.

Incorrect Answers

Answer A is incorrect because This is not the best choice because it addresses the adjacent decision ‘constrain a tool response that requests unrelated data access’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer B is incorrect because This is not the best choice because it addresses the adjacent decision ‘limit access to sensitive training material’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer C is incorrect because This is not the best choice because it addresses the adjacent decision ‘separate model-tuning access from production inference access’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer E is incorrect because This is not the best choice because it addresses the adjacent decision ‘separate output filtering from authorization enforcement’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

 

Question 7

The architecture council wants a testable decision for one agent from inheriting another agent’s authority. Which option should it approve?

  1. Prevent one agent from inheriting another agent’s authority.
  2. Prevent exfiltration through an overprivileged action.
  3. Prevent a shared index from exposing restricted records.
  4. Assess an untrusted model dependency before adoption.
  5. Limit resource exhaustion from adversarially large inputs.

Correct Answer: A

 

Correct Answer

Answer A is correct because This is correct because it applies the reserved architecture decision—prevent one agent from inheriting another agent’s authority—to the decisive constraint in the scenario. It keeps the action at the appropriate agent, model and grounding security boundary and produces a result that can be verified before wider deployment.

Incorrect Answers

Answer B is incorrect because This is not the best choice because it addresses the adjacent decision ‘prevent exfiltration through an overprivileged action’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer C is incorrect because This is not the best choice because it addresses the adjacent decision ‘prevent a shared index from exposing restricted records’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer D is incorrect because This is not the best choice because it addresses the adjacent decision ‘assess an untrusted model dependency before adoption’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer E is incorrect because This is not the best choice because it addresses the adjacent decision ‘limit resource exhaustion from adversarially large inputs’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

 

Question 8

An agent trust-boundary review is reviewing agent, model and grounding security. The review has identified a specific issue: restrict publication to an approved audience. What should the architect recommend?

  1. Restrict publication to an approved audience.
  2. Constrain model exposure to approved network paths.
  3. Mitigate unbounded execution caused by repeated agent delegation.
  4. Threat-model the agent, model, tools, and grounding boundary, then verify least-privilege access and data-flow controls.
  5. Prioritize a mitigation using the identified trust boundary.

Correct Answer: A

 

Correct Answer

Answer A is correct because This is correct because it applies the reserved architecture decision—restrict publication to an approved audience—to the decisive constraint in the scenario. It keeps the action at the appropriate agent, model and grounding security boundary and produces a result that can be verified before wider deployment.

Incorrect Answers

Answer B is incorrect because This is not the best choice because it addresses the adjacent decision ‘constrain model exposure to approved network paths’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer C is incorrect because This is not the best choice because it addresses the adjacent decision ‘mitigate unbounded execution caused by repeated agent delegation’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer D is incorrect because This is a useful verification step after the primary architecture decision, but it does not by itself resolve the decision the scenario asks for. The design choice must be made first, and this evidence can then confirm that the chosen approach behaves as intended.

Answer E is incorrect because This is not the best choice because it addresses the adjacent decision ‘prioritize a mitigation using the identified trust boundary’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

 

Question 9

A production-readiness review of agent, model and grounding security gives the red-team remediation program new evidence. The review has identified a specific issue: revoke access for a retired agent without disabling shared services. Which action should the team take next?

  1. Preserve user-specific permissions during grounding retrieval.
  2. Protect secrets used in model-serving infrastructure.
  3. Scope data access for a background autonomous process.
  4. Reject a user attempt to override an approval requirement.
  5. Revoke access for a retired agent without disabling shared services.

Correct Answer: E

 

Correct Answer

Answer E is correct because This is correct because it applies the reserved architecture decision—revoke access for a retired agent without disabling shared services—to the decisive constraint in the scenario. It keeps the action at the appropriate agent, model and grounding security boundary and produces a result that can be verified before wider deployment.

Incorrect Answers

Answer A is incorrect because This is not the best choice because it addresses the adjacent decision ‘preserve user-specific permissions during grounding retrieval’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer B is incorrect because This is not the best choice because it addresses the adjacent decision ‘protect secrets used in model-serving infrastructure’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer C is incorrect because This is not the best choice because it addresses the adjacent decision ‘scope data access for a background autonomous process’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer D is incorrect because This is not the best choice because it addresses the adjacent decision ‘reject a user attempt to override an approval requirement’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

 

Question 10

The architecture team must document a decision about restrict access to a deployed model endpoint. A prior pilot did not resolve this point. Which action is most appropriate?

  1. Verify integrity before promoting a model artifact.
  2. Use least privilege for training-data preparation.
  3. Restrict access to a deployed model endpoint.
  4. Validate tool arguments before executing a destructive operation.
  5. Treat model-tuning access separately from production inference access and evaluate each with its own evidence.

Correct Answer: C

 

Correct Answer

Answer C is correct because This is correct because it applies the reserved architecture decision—restrict access to a deployed model endpoint—to the decisive constraint in the scenario. It keeps the action at the appropriate agent, model and grounding security boundary and produces a result that can be verified before wider deployment.

Incorrect Answers

Answer A is incorrect because This is not the best choice because it addresses the adjacent decision ‘verify integrity before promoting a model artifact’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer B is incorrect because This is not the best choice because it addresses the adjacent decision ‘use least privilege for training-data preparation’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer D is incorrect because This is not the best choice because it addresses the adjacent decision ‘validate tool arguments before executing a destructive operation’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer E is incorrect because This is not the best choice because it addresses the adjacent decision ‘separate model-tuning access from production inference access’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

 

Question 11

During a design workshop on agent, model and grounding security, the agent trust-boundary review identifies a constraint. Stakeholders are treating model-management rights and inference rights as the same decision, which is obscuring the actual control boundary. What should the architect recommend?

  1. Treat external website content as untrusted during computer use.
  2. Prevent a shared index from exposing restricted records.
  3. Handle malicious instructions embedded in a retrieved document.
  4. Separate model-management rights from inference rights.
  5. Separate business-unit access in a shared knowledge system.

Correct Answer: D

 

Correct Answer

Answer D is correct because This is correct because it applies the reserved architecture decision—separate model-management rights from inference rights—to the decisive constraint in the scenario. It keeps the action at the appropriate agent, model and grounding security boundary and produces a result that can be verified before wider deployment.

Incorrect Answers

Answer A is incorrect because This is not the best choice because it addresses the adjacent decision ‘treat external website content as untrusted during computer use’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer B is incorrect because This is not the best choice because it addresses the adjacent decision ‘prevent a shared index from exposing restricted records’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer C is incorrect because This is not the best choice because it addresses the adjacent decision ‘handle malicious instructions embedded in a retrieved document’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer E is incorrect because This is not the best choice because it addresses the adjacent decision ‘separate business-unit access in a shared knowledge system’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

 

Question 12

Before a wider rollout of agent, model and grounding security, the grounding security team reviews the current evidence. The current solution leaves a custom model artifact from unauthorized replacement unresolved, and the gap is now affecting the stated business or technical requirement. Which approach best fits the requirement?

  1. Treat output filtering separately from authorization enforcement and evaluate each with its own evidence.
  2. Protect a custom model artifact from unauthorized replacement.
  3. Threat-model the agent, model, tools, and grounding boundary, then verify least-privilege access and data-flow controls.
  4. Revalidate access after a source document permission change.
  5. Constrain a tool response that requests unrelated data access.

Correct Answer: B

 

Correct Answer

Answer B is correct because This is correct because it applies the reserved architecture decision—protect a custom model artifact from unauthorized replacement—to the decisive constraint in the scenario. It keeps the action at the appropriate agent, model and grounding security boundary and produces a result that can be verified before wider deployment.

Incorrect Answers

Answer A is incorrect because This is not the best choice because it addresses the adjacent decision ‘separate output filtering from authorization enforcement’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer C is incorrect because This is a useful verification step after the primary architecture decision, but it does not by itself resolve the decision the scenario asks for. The design choice must be made first, and this evidence can then confirm that the chosen approach behaves as intended.

Answer D is incorrect because This is not the best choice because it addresses the adjacent decision ‘revalidate access after a source document permission change’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer E is incorrect because This is not the best choice because it addresses the adjacent decision ‘constrain a tool response that requests unrelated data access’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

 

Question 13

A model security group is reviewing agent, model and grounding security. The unresolved requirement concerns sensitive training material. The current design does not yet establish how access should be handled. What is the best design choice?

  1. Scope data access for a background autonomous process.
  2. Limit resource exhaustion from adversarially large inputs.
  3. Choose identity context for delegated agent actions.
  4. Limit access to sensitive training material.
  5. Prevent exfiltration through an overprivileged action.

Correct Answer: D

 

Correct Answer

Answer D is correct because This is correct because it applies the reserved architecture decision—limit access to sensitive training material—to the decisive constraint in the scenario. It keeps the action at the appropriate agent, model and grounding security boundary and produces a result that can be verified before wider deployment.

Incorrect Answers

Answer A is incorrect because This is not the best choice because it addresses the adjacent decision ‘scope data access for a background autonomous process’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer B is incorrect because This is not the best choice because it addresses the adjacent decision ‘limit resource exhaustion from adversarially large inputs’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer C is incorrect because This is not the best choice because it addresses the adjacent decision ‘choose identity context for delegated agent actions’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer E is incorrect because This is not the best choice because it addresses the adjacent decision ‘prevent exfiltration through an overprivileged action’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

 

Question 14

Before a wider rollout of agent, model and grounding security, the agent trust-boundary review reviews the current evidence. Existing evidence is insufficient to make a safe release or architecture decision about an untrusted model dependency before adoption. Which action should the team take next?

  1. Scope tool permissions to required business operations.
  2. Mitigate unbounded execution caused by repeated agent delegation.
  3. Prioritize a mitigation using the identified trust boundary.
  4. Use least privilege for training-data preparation.
  5. Assess an untrusted model dependency before adoption.

Correct Answer: E

 

Correct Answer

Answer E is correct because This is correct because it applies the reserved architecture decision—assess an untrusted model dependency before adoption—to the decisive constraint in the scenario. It keeps the action at the appropriate agent, model and grounding security boundary and produces a result that can be verified before wider deployment.

Incorrect Answers

Answer A is incorrect because This is not the best choice because it addresses the adjacent decision ‘scope tool permissions to required business operations’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer B is incorrect because This is not the best choice because it addresses the adjacent decision ‘mitigate unbounded execution caused by repeated agent delegation’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer C is incorrect because This is not the best choice because it addresses the adjacent decision ‘prioritize a mitigation using the identified trust boundary’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer D is incorrect because This is not the best choice because it addresses the adjacent decision ‘use least privilege for training-data preparation’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

 

Question 15

A pilot for agent, model and grounding security reaches a decision point for the AI security architecture review. The review has identified a specific issue: constrain model exposure to approved network paths. Which decision is most appropriate?

  1. Treat maker privileges separately from runtime agent permissions and evaluate each with its own evidence.
  2. Separate business-unit access in a shared knowledge system.
  3. Constrain model exposure to approved network paths.
  4. Preserve user-specific permissions during grounding retrieval.
  5. Reject a user attempt to override an approval requirement.

Correct Answer: C

 

Correct Answer

Answer C is correct because This is correct because it applies the reserved architecture decision—constrain model exposure to approved network paths—to the decisive constraint in the scenario. It keeps the action at the appropriate agent, model and grounding security boundary and produces a result that can be verified before wider deployment.

Incorrect Answers

Answer A is incorrect because This is not the best choice because it addresses the adjacent decision ‘separate maker privileges from runtime agent permissions’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer B is incorrect because This is not the best choice because it addresses the adjacent decision ‘separate business-unit access in a shared knowledge system’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer D is incorrect because This is not the best choice because it addresses the adjacent decision ‘preserve user-specific permissions during grounding retrieval’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer E is incorrect because This is not the best choice because it addresses the adjacent decision ‘reject a user attempt to override an approval requirement’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

 

Question 16

During a design workshop on agent, model and grounding security, the model security group identifies a constraint. The current solution leaves secrets used in model-serving infrastructure unresolved, and the gap is now affecting the stated business or technical requirement. What should the architect recommend?

  1. Threat-model the agent, model, tools, and grounding boundary, then verify least-privilege access and data-flow controls.
  2. Protect secrets used in model-serving infrastructure.
  3. Treat model-tuning access separately from production inference access and evaluate each with its own evidence.
  4. Validate tool arguments before executing a destructive operation.
  5. Verify downstream data controls after connector delegation.

Correct Answer: B

 

Correct Answer

Answer B is correct because This is correct because it applies the reserved architecture decision—protect secrets used in model-serving infrastructure—to the decisive constraint in the scenario. It keeps the action at the appropriate agent, model and grounding security boundary and produces a result that can be verified before wider deployment.

Incorrect Answers

Answer A is incorrect because This is a useful verification step after the primary architecture decision, but it does not by itself resolve the decision the scenario asks for. The design choice must be made first, and this evidence can then confirm that the chosen approach behaves as intended.

Answer C is incorrect because This is not the best choice because it addresses the adjacent decision ‘separate model-tuning access from production inference access’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer D is incorrect because This is not the best choice because it addresses the adjacent decision ‘validate tool arguments before executing a destructive operation’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer E is incorrect because This is not the best choice because it addresses the adjacent decision ‘verify downstream data controls after connector delegation’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

 

Question 17

During a design workshop on agent, model and grounding security, the red-team remediation program identifies a constraint. The review has identified a specific issue: verify integrity before promoting a model artifact. What is the best design choice?

  1. Verify integrity before promoting a model artifact.
  2. Prevent a shared index from exposing restricted records.
  3. Constrain agent access to approved network destinations.
  4. Choose identity context for delegated agent actions.
  5. Treat external website content as untrusted during computer use.

Correct Answer: A

 

Correct Answer

Answer A is correct because This is correct because it applies the reserved architecture decision—verify integrity before promoting a model artifact—to the decisive constraint in the scenario. It keeps the action at the appropriate agent, model and grounding security boundary and produces a result that can be verified before wider deployment.

Incorrect Answers

Answer B is incorrect because This is not the best choice because it addresses the adjacent decision ‘prevent a shared index from exposing restricted records’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer C is incorrect because This is not the best choice because it addresses the adjacent decision ‘constrain agent access to approved network destinations’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer D is incorrect because This is not the best choice because it addresses the adjacent decision ‘choose identity context for delegated agent actions’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer E is incorrect because This is not the best choice because it addresses the adjacent decision ‘treat external website content as untrusted during computer use’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

 

Question 18

The operating model needs an explicit rule for malicious instructions embedded in a retrieved document. Which design decision should be recorded?

  1. Scope tool permissions to required business operations.
  2. Require explicit approval for a high-impact action.
  3. Revalidate access after a source document permission change.
  4. Handle malicious instructions embedded in a retrieved document.
  5. Treat output filtering separately from authorization enforcement and evaluate each with its own evidence.

Correct Answer: D

 

Correct Answer

Answer D is correct because This is correct because it applies the reserved architecture decision—handle malicious instructions embedded in a retrieved document—to the decisive constraint in the scenario. It keeps the action at the appropriate agent, model and grounding security boundary and produces a result that can be verified before wider deployment.

Incorrect Answers

Answer A is incorrect because This is not the best choice because it addresses the adjacent decision ‘scope tool permissions to required business operations’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer B is incorrect because This is not the best choice because it addresses the adjacent decision ‘require explicit approval for a high-impact action’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer C is incorrect because This is not the best choice because it addresses the adjacent decision ‘revalidate access after a source document permission change’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer E is incorrect because This is not the best choice because it addresses the adjacent decision ‘separate output filtering from authorization enforcement’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

 

Question 19

The grounding security team is preparing an architecture decision record for agent, model and grounding security. The review has identified a specific issue: constrain a tool response that requests unrelated data access. What is the best design choice?

  1. Prevent one agent from inheriting another agent’s authority.
  2. Limit resource exhaustion from adversarially large inputs.
  3. Constrain a tool response that requests unrelated data access.
  4. Treat maker privileges separately from runtime agent permissions and evaluate each with its own evidence.
  5. Scope data access for a background autonomous process.

Correct Answer: C

 

Correct Answer

Answer C is correct because This is correct because it applies the reserved architecture decision—constrain a tool response that requests unrelated data access—to the decisive constraint in the scenario. It keeps the action at the appropriate agent, model and grounding security boundary and produces a result that can be verified before wider deployment.

Incorrect Answers

Answer A is incorrect because This is not the best choice because it addresses the adjacent decision ‘prevent one agent from inheriting another agent’s authority’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer B is incorrect because This is not the best choice because it addresses the adjacent decision ‘limit resource exhaustion from adversarially large inputs’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer D is incorrect because This is not the best choice because it addresses the adjacent decision ‘separate maker privileges from runtime agent permissions’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer E is incorrect because This is not the best choice because it addresses the adjacent decision ‘scope data access for a background autonomous process’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

 

Question 20

A red-team remediation program is reviewing agent, model and grounding security. The current solution leaves exfiltration through an overprivileged action unresolved, and the gap is now affecting the stated business or technical requirement. Which decision is most appropriate?

  1. Treat retrieved content and tool outputs as untrusted inputs unless the architecture explicitly validates and constrains them.
  2. Threat-model the agent, model, tools, and grounding boundary, then verify least-privilege access and data-flow controls.
  3. Prevent exfiltration through an overprivileged action.
  4. Use least privilege for training-data preparation.
  5. Prioritize a mitigation using the identified trust boundary.

Correct Answer: C

 

Correct Answer

Answer C is correct because This is correct because it applies the reserved architecture decision—prevent exfiltration through an overprivileged action—to the decisive constraint in the scenario. It keeps the action at the appropriate agent, model and grounding security boundary and produces a result that can be verified before wider deployment.

Incorrect Answers

Answer A is incorrect because This safeguard can be important in a broader production design, but it is a supporting control rather than the primary decision required by this scenario. Selecting it alone would leave the core architecture choice unresolved.

Answer B is incorrect because This is a useful verification step after the primary architecture decision, but it does not by itself resolve the decision the scenario asks for. The design choice must be made first, and this evidence can then confirm that the chosen approach behaves as intended.

Answer D is incorrect because This is not the best choice because it addresses the adjacent decision ‘use least privilege for training-data preparation’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer E is incorrect because This is not the best choice because it addresses the adjacent decision ‘prioritize a mitigation using the identified trust boundary’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

 

Question 21

A production-readiness review of agent, model and grounding security gives the model security group new evidence. The review has identified a specific issue: mitigate unbounded execution caused by repeated agent delegation. Which action should the team take next?

  1. Preserve user-specific permissions during grounding retrieval.
  2. Mitigate unbounded execution caused by repeated agent delegation.
  3. Revoke access for a retired agent without disabling shared services.
  4. Constrain agent access to approved network destinations.
  5. Separate business-unit access in a shared knowledge system.

Correct Answer: B

 

Correct Answer

Answer B is correct because This is correct because it applies the reserved architecture decision—mitigate unbounded execution caused by repeated agent delegation—to the decisive constraint in the scenario. It keeps the action at the appropriate agent, model and grounding security boundary and produces a result that can be verified before wider deployment.

Incorrect Answers

Answer A is incorrect because This is not the best choice because it addresses the adjacent decision ‘preserve user-specific permissions during grounding retrieval’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer C is incorrect because This is not the best choice because it addresses the adjacent decision ‘revoke access for a retired agent without disabling shared services’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer D is incorrect because This is not the best choice because it addresses the adjacent decision ‘constrain agent access to approved network destinations’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer E is incorrect because This is not the best choice because it addresses the adjacent decision ‘separate business-unit access in a shared knowledge system’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

 

Question 22

A red-team remediation program is reviewing agent, model and grounding security. The review has identified a specific issue: reject a user attempt to override an approval requirement. What should the architect recommend?

  1. Treat model-tuning access separately from production inference access and evaluate each with its own evidence.
  2. Require explicit approval for a high-impact action.
  3. Verify downstream data controls after connector delegation.
  4. Reject a user attempt to override an approval requirement.
  5. Restrict access to a deployed model endpoint.

Correct Answer: D

 

Correct Answer

Answer D is correct because This is correct because it applies the reserved architecture decision—reject a user attempt to override an approval requirement—to the decisive constraint in the scenario. It keeps the action at the appropriate agent, model and grounding security boundary and produces a result that can be verified before wider deployment.

Incorrect Answers

Answer A is incorrect because This is not the best choice because it addresses the adjacent decision ‘separate model-tuning access from production inference access’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer B is incorrect because This is not the best choice because it addresses the adjacent decision ‘require explicit approval for a high-impact action’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer C is incorrect because This is not the best choice because it addresses the adjacent decision ‘verify downstream data controls after connector delegation’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer E is incorrect because This is not the best choice because it addresses the adjacent decision ‘restrict access to a deployed model endpoint’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

 

Question 23

A pilot for agent, model and grounding security reaches a decision point for the grounding security team. Existing evidence is insufficient to make a safe release or architecture decision about tool arguments before executing a destructive operation. Which action should the team take next?

  1. Validate tool arguments before executing a destructive operation.
  2. Choose identity context for delegated agent actions.
  3. Treat model-management rights separately from inference rights and evaluate each with its own evidence.
  4. Prevent one agent from inheriting another agent’s authority.
  5. Prevent a shared index from exposing restricted records.

Correct Answer: A

 

Correct Answer

Answer A is correct because This is correct because it applies the reserved architecture decision—validate tool arguments before executing a destructive operation—to the decisive constraint in the scenario. It keeps the action at the appropriate agent, model and grounding security boundary and produces a result that can be verified before wider deployment.

Incorrect Answers

Answer B is incorrect because This is not the best choice because it addresses the adjacent decision ‘choose identity context for delegated agent actions’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer C is incorrect because This is not the best choice because it addresses the adjacent decision ‘separate model-management rights from inference rights’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer D is incorrect because This is not the best choice because it addresses the adjacent decision ‘prevent one agent from inheriting another agent’s authority’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer E is incorrect because This is not the best choice because it addresses the adjacent decision ‘prevent a shared index from exposing restricted records’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

 

Question 24

A pilot for agent, model and grounding security reaches a decision point for the model security group. The review has identified a specific issue: treat external website content as untrusted during computer use. What is the best design choice?

  1. Threat-model the agent, model, tools, and grounding boundary, then verify least-privilege access and data-flow controls.
  2. Restrict publication to an approved audience.
  3. Treat external website content as untrusted during computer use.
  4. Scope tool permissions to required business operations.
  5. Revalidate access after a source document permission change.

Correct Answer: C

 

Correct Answer

Answer C is correct because This is correct because it applies the reserved architecture decision—treat external website content as untrusted during computer use—to the decisive constraint in the scenario. It keeps the action at the appropriate agent, model and grounding security boundary and produces a result that can be verified before wider deployment.

Incorrect Answers

Answer A is incorrect because This is a useful verification step after the primary architecture decision, but it does not by itself resolve the decision the scenario asks for. The design choice must be made first, and this evidence can then confirm that the chosen approach behaves as intended.

Answer B is incorrect because This is not the best choice because it addresses the adjacent decision ‘restrict publication to an approved audience’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer D is incorrect because This is not the best choice because it addresses the adjacent decision ‘scope tool permissions to required business operations’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer E is incorrect because This is not the best choice because it addresses the adjacent decision ‘revalidate access after a source document permission change’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

 

Question 25

Before a wider rollout of agent, model and grounding security, the red-team remediation program reviews the current evidence. Stakeholders are treating output filtering and authorization enforcement as the same decision, which is obscuring the actual control boundary. Which action should the team take next?

  1. Limit access to sensitive training material.
  2. Separate output filtering from authorization enforcement.
  3. Revoke access for a retired agent without disabling shared services.
  4. Scope data access for a background autonomous process.
  5. Treat maker privileges separately from runtime agent permissions and evaluate each with its own evidence.

Correct Answer: B

 

Correct Answer

Answer B is correct because This is correct because it applies the reserved architecture decision—separate output filtering from authorization enforcement—to the decisive constraint in the scenario. It keeps the action at the appropriate agent, model and grounding security boundary and produces a result that can be verified before wider deployment.

Incorrect Answers

Answer A is incorrect because This is not the best choice because it addresses the adjacent decision ‘limit access to sensitive training material’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer C is incorrect because This is not the best choice because it addresses the adjacent decision ‘revoke access for a retired agent without disabling shared services’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer D is incorrect because This is not the best choice because it addresses the adjacent decision ‘scope data access for a background autonomous process’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer E is incorrect because This is not the best choice because it addresses the adjacent decision ‘separate maker privileges from runtime agent permissions’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

 

Question 26

The operating model needs an explicit rule for resource exhaustion from adversarially large inputs. Which design decision should be recorded?

  1. Use least privilege for training-data preparation.
  2. Protect credentials used by external connectors.
  3. Limit resource exhaustion from adversarially large inputs.
  4. Restrict access to a deployed model endpoint.
  5. Assess an untrusted model dependency before adoption.

Correct Answer: C

 

Correct Answer

Answer C is correct because This is correct because it applies the reserved architecture decision—limit resource exhaustion from adversarially large inputs—to the decisive constraint in the scenario. It keeps the action at the appropriate agent, model and grounding security boundary and produces a result that can be verified before wider deployment.

Incorrect Answers

Answer A is incorrect because This is not the best choice because it addresses the adjacent decision ‘use least privilege for training-data preparation’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer B is incorrect because This is not the best choice because it addresses the adjacent decision ‘protect credentials used by external connectors’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer D is incorrect because This is not the best choice because it addresses the adjacent decision ‘restrict access to a deployed model endpoint’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer E is incorrect because This is not the best choice because it addresses the adjacent decision ‘assess an untrusted model dependency before adoption’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

 

Question 27

The agent trust-boundary review is preparing an architecture decision record for agent, model and grounding security. The current solution leaves a mitigation using the identified trust boundary unresolved, and the gap is now affecting the stated business or technical requirement. Which action should the team take next?

  1. Prioritize a mitigation using the identified trust boundary.
  2. Constrain model exposure to approved network paths.
  3. Constrain agent access to approved network destinations.
  4. Treat model-management rights separately from inference rights and evaluate each with its own evidence.
  5. Separate business-unit access in a shared knowledge system.

Correct Answer: A

 

Correct Answer

Answer A is correct because This is correct because it applies the reserved architecture decision—prioritize a mitigation using the identified trust boundary—to the decisive constraint in the scenario. It keeps the action at the appropriate agent, model and grounding security boundary and produces a result that can be verified before wider deployment.

Incorrect Answers

Answer B is incorrect because This is not the best choice because it addresses the adjacent decision ‘constrain model exposure to approved network paths’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer C is incorrect because This is not the best choice because it addresses the adjacent decision ‘constrain agent access to approved network destinations’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer D is incorrect because This is not the best choice because it addresses the adjacent decision ‘separate model-management rights from inference rights’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer E is incorrect because This is not the best choice because it addresses the adjacent decision ‘separate business-unit access in a shared knowledge system’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

 

Question 28

A production-readiness review of agent, model and grounding security gives the AI security architecture review new evidence. The current solution leaves user-specific permissions during grounding retrieval unresolved, and the gap is now affecting the stated business or technical requirement. What should the architect recommend?

  1. Verify downstream data controls after connector delegation.
  2. Protect a custom model artifact from unauthorized replacement.
  3. Preserve user-specific permissions during grounding retrieval.
  4. Require explicit approval for a high-impact action.
  5. Threat-model the agent, model, tools, and grounding boundary, then verify least-privilege access and data-flow controls.

Correct Answer: C

 

Correct Answer

Answer C is correct because This is correct because it applies the reserved architecture decision—preserve user-specific permissions during grounding retrieval—to the decisive constraint in the scenario. It keeps the action at the appropriate agent, model and grounding security boundary and produces a result that can be verified before wider deployment.

Incorrect Answers

Answer A is incorrect because This is not the best choice because it addresses the adjacent decision ‘verify downstream data controls after connector delegation’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer B is incorrect because This is not the best choice because it addresses the adjacent decision ‘protect a custom model artifact from unauthorized replacement’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer D is incorrect because This is not the best choice because it addresses the adjacent decision ‘require explicit approval for a high-impact action’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer E is incorrect because This is a useful verification step after the primary architecture decision, but it does not by itself resolve the decision the scenario asks for. The design choice must be made first, and this evidence can then confirm that the chosen approach behaves as intended.

 

Question 29

The agent trust-boundary review is preparing an architecture decision record for agent, model and grounding security. Stakeholders are treating model-tuning access and production inference access as the same decision, which is obscuring the actual control boundary. Which decision is most appropriate?

  1. Choose identity context for delegated agent actions.
  2. Prevent one agent from inheriting another agent’s authority.
  3. Separate model-tuning access from production inference access.
  4. Verify integrity before promoting a model artifact.
  5. Limit access to sensitive training material.

Correct Answer: C

 

Correct Answer

Answer C is correct because This is correct because it applies the reserved architecture decision—separate model-tuning access from production inference access—to the decisive constraint in the scenario. It keeps the action at the appropriate agent, model and grounding security boundary and produces a result that can be verified before wider deployment.

Incorrect Answers

Answer A is incorrect because This is not the best choice because it addresses the adjacent decision ‘choose identity context for delegated agent actions’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer B is incorrect because This is not the best choice because it addresses the adjacent decision ‘prevent one agent from inheriting another agent’s authority’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer D is incorrect because This is not the best choice because it addresses the adjacent decision ‘verify integrity before promoting a model artifact’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer E is incorrect because This is not the best choice because it addresses the adjacent decision ‘limit access to sensitive training material’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

 

Question 30

Before a wider rollout of agent, model and grounding security, the model security group reviews the current evidence. The current solution leaves a shared index from exposing restricted records unresolved, and the gap is now affecting the stated business or technical requirement. What should the architect recommend?

  1. Scope tool permissions to required business operations.
  2. Handle malicious instructions embedded in a retrieved document.
  3. Assess an untrusted model dependency before adoption.
  4. Prevent a shared index from exposing restricted records.
  5. Restrict publication to an approved audience.

Correct Answer: D

 

Correct Answer

Answer D is correct because This is correct because it applies the reserved architecture decision—prevent a shared index from exposing restricted records—to the decisive constraint in the scenario. It keeps the action at the appropriate agent, model and grounding security boundary and produces a result that can be verified before wider deployment.

Incorrect Answers

Answer A is incorrect because This is not the best choice because it addresses the adjacent decision ‘scope tool permissions to required business operations’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer B is incorrect because This is not the best choice because it addresses the adjacent decision ‘handle malicious instructions embedded in a retrieved document’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer C is incorrect because This is not the best choice because it addresses the adjacent decision ‘assess an untrusted model dependency before adoption’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer E is incorrect because This is not the best choice because it addresses the adjacent decision ‘restrict publication to an approved audience’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

 

Question 31

The AI security architecture review is preparing an architecture decision record for agent, model and grounding security. The review has identified a specific issue: revalidate access after a source document permission change. Which action should the team take next?

  1. Treat maker privileges separately from runtime agent permissions and evaluate each with its own evidence.
  2. Revalidate access after a source document permission change.
  3. Revoke access for a retired agent without disabling shared services.
  4. Constrain a tool response that requests unrelated data access.
  5. Constrain model exposure to approved network paths.

Correct Answer: B

 

Correct Answer

Answer B is correct because This is correct because it applies the reserved architecture decision—revalidate access after a source document permission change—to the decisive constraint in the scenario. It keeps the action at the appropriate agent, model and grounding security boundary and produces a result that can be verified before wider deployment.

Incorrect Answers

Answer A is incorrect because This is not the best choice because it addresses the adjacent decision ‘separate maker privileges from runtime agent permissions’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer C is incorrect because This is not the best choice because it addresses the adjacent decision ‘revoke access for a retired agent without disabling shared services’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer D is incorrect because This is not the best choice because it addresses the adjacent decision ‘constrain a tool response that requests unrelated data access’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer E is incorrect because This is not the best choice because it addresses the adjacent decision ‘constrain model exposure to approved network paths’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

 

Question 32

An earlier design assumed the wrong thing about scope data access for a background autonomous process. Which decision should replace that assumption?

  1. Scope data access for a background autonomous process.
  2. Protect secrets used in model-serving infrastructure.
  3. Restrict access to a deployed model endpoint.
  4. Threat-model the agent, model, tools, and grounding boundary, then verify least-privilege access and data-flow controls.
  5. Protect credentials used by external connectors.

Correct Answer: A

 

Correct Answer

Answer A is correct because This is correct because it applies the reserved architecture decision—scope data access for a background autonomous process—to the decisive constraint in the scenario. It keeps the action at the appropriate agent, model and grounding security boundary and produces a result that can be verified before wider deployment.

Incorrect Answers

Answer B is incorrect because This is not the best choice because it addresses the adjacent decision ‘protect secrets used in model-serving infrastructure’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer C is incorrect because This is not the best choice because it addresses the adjacent decision ‘restrict access to a deployed model endpoint’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer D is incorrect because This is a useful verification step after the primary architecture decision, but it does not by itself resolve the decision the scenario asks for. The design choice must be made first, and this evidence can then confirm that the chosen approach behaves as intended.

Answer E is incorrect because This is not the best choice because it addresses the adjacent decision ‘protect credentials used by external connectors’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

 

Question 33

A model security group is reviewing agent, model and grounding security. The current solution leaves least privilege for training-data preparation unresolved, and the gap is now affecting the stated business or technical requirement. What is the best design choice?

  1. Mitigate unbounded execution caused by repeated agent delegation.
  2. Constrain agent access to approved network destinations.
  3. Verify integrity before promoting a model artifact.
  4. Treat model-management rights separately from inference rights and evaluate each with its own evidence.
  5. Use least privilege for training-data preparation.

Correct Answer: E

 

Correct Answer

Answer E is correct because This is correct because it applies the reserved architecture decision—use least privilege for training-data preparation—to the decisive constraint in the scenario. It keeps the action at the appropriate agent, model and grounding security boundary and produces a result that can be verified before wider deployment.

Incorrect Answers

Answer A is incorrect because This is not the best choice because it addresses the adjacent decision ‘mitigate unbounded execution caused by repeated agent delegation’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer B is incorrect because This is not the best choice because it addresses the adjacent decision ‘constrain agent access to approved network destinations’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer C is incorrect because This is not the best choice because it addresses the adjacent decision ‘verify integrity before promoting a model artifact’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer D is incorrect because This is not the best choice because it addresses the adjacent decision ‘separate model-management rights from inference rights’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

 

Question 34

A production-readiness review of agent, model and grounding security gives the model security group new evidence. The review has identified a specific issue: separate business-unit access in a shared knowledge system. What should the architect recommend?

  1. Separate business-unit access in a shared knowledge system.
  2. Handle malicious instructions embedded in a retrieved document.
  3. Reject a user attempt to override an approval requirement.
  4. Protect a custom model artifact from unauthorized replacement.
  5. Require explicit approval for a high-impact action.

Correct Answer: A

 

Correct Answer

Answer A is correct because This is correct because it applies the reserved architecture decision—separate business-unit access in a shared knowledge system—to the decisive constraint in the scenario. It keeps the action at the appropriate agent, model and grounding security boundary and produces a result that can be verified before wider deployment.

Incorrect Answers

Answer B is incorrect because This is not the best choice because it addresses the adjacent decision ‘handle malicious instructions embedded in a retrieved document’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer C is incorrect because This is not the best choice because it addresses the adjacent decision ‘reject a user attempt to override an approval requirement’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer D is incorrect because This is not the best choice because it addresses the adjacent decision ‘protect a custom model artifact from unauthorized replacement’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer E is incorrect because This is not the best choice because it addresses the adjacent decision ‘require explicit approval for a high-impact action’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

 

Question 35

An agent trust-boundary review is reviewing agent, model and grounding security. The review has identified a specific issue: verify downstream data controls after connector delegation. Which action should the team take next?

  1. Limit access to sensitive training material.
  2. Prevent one agent from inheriting another agent’s authority.
  3. Constrain a tool response that requests unrelated data access.
  4. Validate tool arguments before executing a destructive operation.
  5. Verify downstream data controls after connector delegation.

Correct Answer: E

 

Correct Answer

Answer E is correct because This is correct because it applies the reserved architecture decision—verify downstream data controls after connector delegation—to the decisive constraint in the scenario. It keeps the action at the appropriate agent, model and grounding security boundary and produces a result that can be verified before wider deployment.

Incorrect Answers

Answer A is incorrect because This is not the best choice because it addresses the adjacent decision ‘limit access to sensitive training material’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer B is incorrect because This is not the best choice because it addresses the adjacent decision ‘prevent one agent from inheriting another agent’s authority’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer C is incorrect because This is not the best choice because it addresses the adjacent decision ‘constrain a tool response that requests unrelated data access’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer D is incorrect because This is not the best choice because it addresses the adjacent decision ‘validate tool arguments before executing a destructive operation’ rather than the scenario’s decisive requirement. Although that action can be valid within agent, model and grounding security, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

img