18 cards · Foundations, Practitioner, Applied, Advanced, Expert
AI security interview questions and practice topics
AI security: prompt injection, jailbreaks, data poisoning, model and agent supply-chain risk, and securing LLM applications in production, including the OWASP Top 10 for LLMs.
Each card is a topic to explain out loud against the clock: 8 are real interview questions, the rest are concepts, live incidents and deep dives. Open one to see what a strong answer covers, or open cardosec and pick AI security as a focus.
L1 Foundations What it is
L2 Practitioner How it works
- Chatbot Promises a Refund PolicyA jailbroken support chatbot output is trending on social media. What are your first moves?Incident · Interview
- Excessive AgencyAn LLM agent is being given access to company tools. What is excessive agency and how do you limit it?Explain · Interview
- Improper Output HandlingExplain
- JailbreaksWhat is the difference between a jailbreak and a prompt injection? Give examples of jailbreak techniques.Explain · Interview
L3 Applied Abuse and defence in real systems
- AI Supply Chain RiskYour team wants to download open models from a public hub. What supply chain risks exist and what controls would you require?Explain · Interview
- API Bill Spikes 40x OvernightIncident
- Copilot Forwards the InboxYour AI email assistant forwarded executive mail to an outside address. Walk me through your response.Incident · Interview
- Data and Model PoisoningExplain · Deep dive
- Indirect Prompt InjectionExplain indirect prompt injection and how you would defend an LLM assistant that reads email and browses the web.Explain · Interview · Deep dive
- Model Extraction AttacksExplain
- OWASP LLM Top 10 Threat ModelingExplain · Deep dive
- Training Data LeakageExplain
L4 Advanced Edge cases, bypasses, trade-offs
L5 Expert Research-grade, architecture-level
Other domains
Web AppSec · Network · Identity & AD · Cloud · Cryptography · Blue team / DFIR · Malware & intel · Famous breaches · GRC