SC-500: AI Governance, Privacy & Responsible AI Flashcards
Microsoft Cloud and AI Security Engineer Associate SC-500 Flashcards

| Front | Back |
| Access controls for models | RBAC least privilege and API key rotation |
| Adversarial example mitigation | Use adversarial training detection and input preprocessing defenses |
| Audit trail requirements | Immutable records of model changes access and decision logs |
| Bias versus fairness difference | Bias is systematic error fairness is equitable outcomes |
| Common fairness metrics | Demographic parity equal opportunity equalized odds |
| Compliance evidence examples | Test results audit logs DPIAs and third party attestation reports |
| Concept drift detection method | Monitor input distribution and model performance over time |
| Consent management best practice | Granular opt in clear purposes and ability to withdraw consent |
| Continuous monitoring metrics | Data drift feature importance changes input distribution and error rates |
| Data anonymization limitation | De identification can be reversible via re identification attacks |
| Data minimization principle | Collect only necessary data and reduce identifiability |
| Data residency concern | Laws may require data to remain within a specific jurisdiction |
| Data retention policy purpose | Limit storage time to reduce exposure while meeting legal requirements |
| Datasheet for datasets | Metadata for dataset creation composition collection and maintenance |
| Define model governance | Policies and processes for model development deployment monitoring and decommissioning |
| Differential privacy basic idea | Add noise to outputs to protect individual records |
| Differential privacy epsilon meaning | Epsilon controls privacy loss lower means stronger privacy |
| Explainability technique example | SHAP and LIME provide feature level explanations |
| Explainability tool limitations | Local explanations may not reflect global model behavior and can mislead |
| Explainability versus interpretability difference | Explainability provides post hoc reasons interpretability is inherent model transparency |
| Federated learning definition | Train models on decentralized local data with aggregated updates |
| GDPR lawful basis for processing | Consent legitimate interest contract or legal obligation |
| Homomorphic encryption purpose | Compute on encrypted data without decrypting it |
| Inference logging privacy risk | Logged outputs may leak sensitive training data or user info |
| Logging for AI systems | Record inputs outputs metadata timestamps and model versions |
| Logging retention considerations | Balance forensic needs and privacy minimization for stored logs |
| Model approval board role | Review risk assessments testing and sign off before production deployment |
| Model card purpose | Document model details performance intended use and limitations |
| Model decommissioning steps | Revoke access archive artifacts update inventories and notify stakeholders |
| Model drift definition | Change in data distribution or relationships reducing model performance |
| Model provenance importance | Track data model training code and environment for reproducibility |
| Model testing for fairness | Evaluate performance across demographic groups and metrics |
| Model watermarking goal | Embed imperceptible signals to detect model misuse or theft |
| Privacy Impact Assessment purpose | Identify and mitigate privacy risks before deployment |
| Privacy preserving ML trade offs | Techniques like homomorphic encryption increase compute and latency |
| Prompt injection threat | Malicious inputs manipulating model behavior or leaking data |
| Rate limiting reason | Prevent abuse inference spikes and data exfiltration via APIs |
| Red team evaluation purpose | Simulate adversarial attacks to discover vulnerabilities and misuse paths |
| Regulatory frameworks relevant to AI | GDPR HIPAA CCPA and sector specific guidance like FDA for medical devices |
| Reidentification risk factors | Uniqueness of attributes linkage to external datasets and auxiliary info |
| Right to explanation concept | Provide meaningful information about automated decisions affecting individuals |
| Secure model deployment best practice | Use container isolation TLS authentication and secrets management |
| Secure model update practice | Validate retrained models with tests and version control before rollout |
| Secure multiparty computation goal | Joint computation over private inputs without revealing them |
| Secure training data pipeline controls | Input validation access restriction lineage and encryption at rest |
| Shared responsibility model cloud AI | Cloud secures infrastructure customer secures data models and configs |
| Synthetic data use case | Generate realistic non real user data to reduce privacy risk |
| Third party model risk | Vet vendors for data handling model updates security and compliance |
| Threat modeling for AI systems | Identify assets attackers goals vectors and mitigations specific to models |
| Trade off privacy and utility | Stronger privacy often reduces model accuracy or utility |
About the Flashcards
Flashcards for the Microsoft Cloud and AI Security Engineer Associate exam provide a focused review of terminology, concepts, and key ideas used to govern and secure machine learning systems. Cards cover model governance and lifecycle, privacy preserving techniques such as differential privacy, federated learning, homomorphic encryption, and secure multiparty computation, plus data controls like anonymization, synthetic data, consent management, and privacy impact assessments.
The deck also reinforces security, risk assessment, and evaluation topics including access controls, secure deployment, threat modeling, adversarial defenses, red team testing, model watermarking, logging and audit trails, continuous monitoring, fairness metrics, explainability methods, and regulatory compliance such as GDPR, HIPAA, CCPA, and data residency. Use the cards to drill definitions, trade-offs, and procedural controls commonly tested on the exam.
Topics covered in this flashcard deck:
- Model governance and lifecycle
- Privacy preserving techniques
- Fairness and explainability
- Security and threat mitigation
- Monitoring and audit trails
- Regulatory compliance and data residency