Incident Response, AI Security, and OT Questions
Incident Response
- A public repository contains a cloud token. Lead the first 30 minutes.
- A critical alert fires during a major customer launch. How do you balance containment?
- Build a timeline when endpoint, cloud, and application clocks disagree.
- An executive asks whether customer data was accessed before evidence is complete.
- Decide when to isolate a host, disable an identity, rotate keys, or rebuild.
- A detection rule produces 500 alerts a day. How do you tune it safely?
- Explain chain of custody to an engineering team during an urgent incident.
- Write the structure of a useful post-incident review.
- Distinguish root cause, trigger, contributing factors, and control failures.
- Turn one incident into a prioritized detection and prevention backlog.
AI and Agent Security
- Threat-model an assistant that reads email and creates calendar events.
- Prevent a malicious retrieved document from causing tool execution.
- Design a policy gateway for an agent with cloud read and ticket-write tools.
- Where should human approval occur, and what must the user see?
- Detect cross-tenant RAG leakage and prove deletion.
- Evaluate hallucinated remediation that could cause an outage.
- Secure an AI code-fix workflow from repository input through merge.
- Manage model, plugin, connector, prompt, embedding, and document supply chains.
- Compare sandboxing, egress control, credentials, and output validation.
- Measure task quality, leakage, unsafe action, false refusal, cost, and latency.
ICS/OT
- A Windows engineering workstation is suspected compromised. Who decides containment?
- Design remote vendor access for a plant.
- Connect a historian to cloud analytics safely.
- Prioritize a critical CVE on an unpatchable PLC.
- Explain passive inventory and its blind spots.
- Design zones and conduits for a water treatment environment.
- How can an IT security control create a physical safety risk?
- Plan recovery when replacement hardware has a long lead time.
Executive Drill
For any scenario, give a 90-second update:
- what is known and with what confidence;
- plausible business/safety exposure;
- action already taken;
- decision or resource needed;
- next update time.