Utilizing AI Threat-Modelling Resources
This lab is designed to provide hands-on experience that directly maps to several objectives of the CompTIA SecAI+ (CY0-001) certification exam. The table below details how each major task or concept covered in this lab aligns with the official exam objectives.
| Task/Concept | CompTIA SecAI+ (CY0-001) Exam Objective |
|---|---|
| Task 1: OWASP Top 10 for LLM (Prompt Injection) | 2.6: Given a scenario, analyze an attack and implement compensating controls |
| 3.1: Given a scenario, utilize AI tools for security tasks | |
| Task 2: MIT AI Risk Repository (Algorithmic Bias) | 2.4: Given a scenario, implement data security controls for AI systems |
| 4.2: Explain risks associated with AI | |
| Task 3: MITRE ATLAS (Adversarial Evasion) | 2.1: Given a scenario, use AI threat-modeling resources |
| 2.6: Given a scenario, analyze an attack and implement compensating controls | |
| Task 4: CVE/CWE Investigation | 1.3: Explain the importance of security in the AI life cycle |
| 2.2: Given a scenario, implement security controls for AI systems | |
| Task 5: STRIDE Threat Modeling | 2.1: Given a scenario, use AI threat-modeling resources |
| 2.2: Given a scenario, implement security controls for AI systems |
Overview
This lab provides a comprehensive, hands-on experience in using industry-leading resources for artificial intelligence (AI) threat modeling. Students will learn to navigate and apply frameworks such as the OWASP Top 10 for Large Language Model Applications, the MIT AI Risk Repository, and the MITRE Adversarial Threat Landscape for Artificial-Intelligence Systems (ATLAS). The primary objective is to equip students with the practical skills necessary to analyze a given AI scenario and effectively apply these threat-modeling resources to identify, classify, and mitigate potential risks.
Learning Objective: Given a scenario, use AI threat-modeling resources.
VM Credentials
Username: student
Password: student