Foundation

AI Security Foundations

Proves a working grasp of the AI attack surface, core risks, and the baseline controls every AI deployment needs.

6 modules 43 min of reading 16 questions 70% to pass Free
About this course

This foundation exam assesses whether a candidate understands how AI systems change the security picture: where the attack surface sits, how classic security properties map onto models, and which responsibilities stay with the builder. It is aimed at engineers, architects and security staff who are starting to build or review AI features. Passing demonstrates readiness for the practitioner-level tracks.

What it covers
  • The AI attack surface: how natural-language interfaces collapse the code/data distinction
  • CIA triad for models: confidentiality, integrity and availability applied to weights, data and serving
  • Training-time versus inference-time risk: poisoning, backdoors, jailbreaks and injection
  • Model and data supply chain: pretrained artefacts, datasets, serialisation and annotation
  • Data handling: PII in prompts and outputs, secrets, and the shared-responsibility split for hosted models
  • Operational baselines: layered defence, output handling, logging and auditability
Part 1

Learn the material

6 modules, about 43 minutes of reading. Work through them in order, or jump to whatever you need. The assessment is drawn from exactly this material.

  1. 01 What Changes When You Put a Model in the Loop Why adding a language model to an application creates new trust boundaries, and why the collapse of the code/data distinction is the root of almost everything else in this course. 8 min
  2. 02 The Attack Surface Across the AI Lifecycle Where risk enters at each stage from data collection to retirement, and the load-bearing distinction between attacks that change the model and attacks that change one session. 7 min
  3. 03 Confidentiality, Integrity and Availability for Models and Data How the classic triad maps onto model weights, training data, prompts, outputs and serving capacity, and the classification traps that catch people. 6 min
  4. 04 The Model and Data Supply Chain The borrowed artefacts every AI system depends on, why loading a model file can compromise a host before any inference happens, and what provenance you can realistically establish. 7 min
  5. 05 Prompt Injection, and Why It Is Not a Filtering Problem A precise definition of direct and indirect injection, the reason the analogy with parameterised SQL breaks down, and why filtering inputs or outputs cannot be the primary defence. 7 min
  6. 06 Data, Secrets, Shared Responsibility and the Audit Trail The baseline operational controls every AI deployment needs: minimising personal data in prompts and outputs, keeping secrets out of the context window, knowing which duties a hosted provider does not take on, and logging enough to investigate. 8 min

Start the course

Part 2

Take the assessment

16 questions drawn from the material above. Pass and you can put your name to a certificate with a serial anyone can verify.

How it is marked

  • Questions and answer options are shuffled for every sitting.
  • Multi-answer questions are marked as a set: you need all of the correct options and none of the wrong ones. There is no partial credit.
  • You need 70% to pass.
  • You can revisit and change any answer until you submit.
  • Afterwards you see every question, the answer you gave, and whether it was right. The answer key is never printed.
  • The reasoning behind each answer is released once you pass. Held back on a fail, it would hand over most of the key to anyone willing to sit the paper once and read it, which is why the taught material above is the intended route back.
  • You can re-sit the paper, but not immediately: there is a ten minute wait between attempts on the same course.