AI Bot

SC-500: AI Governance, Privacy & Responsible AI Flashcards

Microsoft Cloud and AI Security Engineer Associate SC-500 Flashcards

Study our SC-500: AI Governance, Privacy & Responsible AI flashcards for the Microsoft Cloud and AI Security Engineer Associate SC-500 exam with 50+ flashcards. View as flashcards, a searchable table, or as a fun matching game.
Microsoft Cloud and AI Security Engineer Associate SC-500 Course Header Image
FrontBack
Access controls for modelsRBAC least privilege and API key rotation
Adversarial example mitigationUse adversarial training detection and input preprocessing defenses
Audit trail requirementsImmutable records of model changes access and decision logs
Bias versus fairness differenceBias is systematic error fairness is equitable outcomes
Common fairness metricsDemographic parity equal opportunity equalized odds
Compliance evidence examplesTest results audit logs DPIAs and third party attestation reports
Concept drift detection methodMonitor input distribution and model performance over time
Consent management best practiceGranular opt in clear purposes and ability to withdraw consent
Continuous monitoring metricsData drift feature importance changes input distribution and error rates
Data anonymization limitationDe identification can be reversible via re identification attacks
Data minimization principleCollect only necessary data and reduce identifiability
Data residency concernLaws may require data to remain within a specific jurisdiction
Data retention policy purposeLimit storage time to reduce exposure while meeting legal requirements
Datasheet for datasetsMetadata for dataset creation composition collection and maintenance
Define model governancePolicies and processes for model development deployment monitoring and decommissioning
Differential privacy basic ideaAdd noise to outputs to protect individual records
Differential privacy epsilon meaningEpsilon controls privacy loss lower means stronger privacy
Explainability technique exampleSHAP and LIME provide feature level explanations
Explainability tool limitationsLocal explanations may not reflect global model behavior and can mislead
Explainability versus interpretability differenceExplainability provides post hoc reasons interpretability is inherent model transparency
Federated learning definitionTrain models on decentralized local data with aggregated updates
GDPR lawful basis for processingConsent legitimate interest contract or legal obligation
Homomorphic encryption purposeCompute on encrypted data without decrypting it
Inference logging privacy riskLogged outputs may leak sensitive training data or user info
Logging for AI systemsRecord inputs outputs metadata timestamps and model versions
Logging retention considerationsBalance forensic needs and privacy minimization for stored logs
Model approval board roleReview risk assessments testing and sign off before production deployment
Model card purposeDocument model details performance intended use and limitations
Model decommissioning stepsRevoke access archive artifacts update inventories and notify stakeholders
Model drift definitionChange in data distribution or relationships reducing model performance
Model provenance importanceTrack data model training code and environment for reproducibility
Model testing for fairnessEvaluate performance across demographic groups and metrics
Model watermarking goalEmbed imperceptible signals to detect model misuse or theft
Privacy Impact Assessment purposeIdentify and mitigate privacy risks before deployment
Privacy preserving ML trade offsTechniques like homomorphic encryption increase compute and latency
Prompt injection threatMalicious inputs manipulating model behavior or leaking data
Rate limiting reasonPrevent abuse inference spikes and data exfiltration via APIs
Red team evaluation purposeSimulate adversarial attacks to discover vulnerabilities and misuse paths
Regulatory frameworks relevant to AIGDPR HIPAA CCPA and sector specific guidance like FDA for medical devices
Reidentification risk factorsUniqueness of attributes linkage to external datasets and auxiliary info
Right to explanation conceptProvide meaningful information about automated decisions affecting individuals
Secure model deployment best practiceUse container isolation TLS authentication and secrets management
Secure model update practiceValidate retrained models with tests and version control before rollout
Secure multiparty computation goalJoint computation over private inputs without revealing them
Secure training data pipeline controlsInput validation access restriction lineage and encryption at rest
Shared responsibility model cloud AICloud secures infrastructure customer secures data models and configs
Synthetic data use caseGenerate realistic non real user data to reduce privacy risk
Third party model riskVet vendors for data handling model updates security and compliance
Threat modeling for AI systemsIdentify assets attackers goals vectors and mitigations specific to models
Trade off privacy and utilityStronger privacy often reduces model accuracy or utility

About the Flashcards

Flashcards for the Microsoft Cloud and AI Security Engineer Associate exam provide a focused review of terminology, concepts, and key ideas used to govern and secure machine learning systems. Cards cover model governance and lifecycle, privacy preserving techniques such as differential privacy, federated learning, homomorphic encryption, and secure multiparty computation, plus data controls like anonymization, synthetic data, consent management, and privacy impact assessments.

The deck also reinforces security, risk assessment, and evaluation topics including access controls, secure deployment, threat modeling, adversarial defenses, red team testing, model watermarking, logging and audit trails, continuous monitoring, fairness metrics, explainability methods, and regulatory compliance such as GDPR, HIPAA, CCPA, and data residency. Use the cards to drill definitions, trade-offs, and procedural controls commonly tested on the exam.

Topics covered in this flashcard deck:

  • Model governance and lifecycle
  • Privacy preserving techniques
  • Fairness and explainability
  • Security and threat mitigation
  • Monitoring and audit trails
  • Regulatory compliance and data residency
Share on...
Follow us on...