SAI-110 knowledge check
Verify that threat scenarios are complete, traceable, prioritized, and connected to controls and evidence.
Assessment instructions
Answer the scenarios, then use the guidance to improve the threat-model workshop package. This public assessment verifies method understanding; it does not award a professional certification.
Questions
1. Threat list versus threat model
Why is “prompt injection” insufficient as a complete threat scenario?
2. Authorized actor
An employee has legitimate access to the assistant but repeatedly reformulates queries to reconstruct a restricted policy. Which actor, assets, boundary, and consequence belong in the scenario?
3. Supply-chain scope
The runtime is air-gapped. Explain why model, package, container, driver, and removable-media surfaces remain in scope.
4. Planned control
A team plans to deploy permission filtering next quarter and lowers current residual risk immediately. What is wrong with the assessment?
5. Evidence integrity
The same administrator can deploy an unapproved model and delete the corresponding logs. Which assets and control properties are affected?
6. Detection bias
No incidents have been observed because the system records only successful requests. Why should this not be treated as evidence of low likelihood?
7. Scenario traceability
What identifiers should connect a scenario to architecture, controls, tests, and evidence?
8. Review trigger
Name four changes that require threat-model reassessment.
Answer guidance
- It omits actor, access, entry surface, sequence, boundary, affected asset, consequence, controls, evidence, and recovery.
- Model an authorized user, document permissions and restricted content, the application-to-retrieval boundary, iterative extraction, and confidentiality or authorization impact.
- Disconnection changes delivery paths; it does not eliminate artifacts. Compromise can enter through import, approval, build, maintenance, and update processes.
- Planned controls do not change current residual risk until implemented and verified.
- Deployment authority, model identity, approval evidence, audit integrity, separation of duties, and non-repudiation are affected.
- Missing telemetry reduces detectability and increases uncertainty. Absence of observed incidents is not evidence of absence.
- Use scenario, actor, asset, boundary, flow, control-objective, test, evidence, decision, and backlog IDs.
- Examples include purpose, data, model, prompt, tool, permission, interface, provider, deployment, incident, control, or evidence changes.
Completion rubric
SAI-110 is complete when:
- Scope and exclusions are explicit.
- Important assets and lifecycle surfaces are represented.
- Actor capability and starting access are credible.
- Scenarios are end-to-end and traceable.
- Prioritization criteria are defined and consistent.
- Planned and implemented controls are distinguished.
- Residual risk has an owner and review condition.
- High-priority scenarios have positive, negative, evidence, containment, and recovery tests.