Skip to content
Tech Interview Prep home
Technical interview guide

AI Security, Governance & Responsible AI

The security and governance concerns specific to LLM systems: prompt injection, data leakage, access control over retrieved content, and responsible-use practices.

Read
45 min
Practice MCQs
25
Interview QA
25
Edition
v4
Editorial status
Reviewed

Scope: NIST AI RMF 1.0 (revision underway as of 2026-09-04), NIST AI 600-1, NIST Privacy Framework 1.0, Regulation (EU) 2024/1689, MITRE ATLAS reviewed 2026-09-04, OWASP GenAI risks, OECD AI Principles updated 2024, C2PA 2.2, Model Cards, Datasheets, and NIST SSDF 1.1.

Interview QA

Treat each question like a live interview question: answer out loud first (structure, assumptions, tradeoffs), then open the model answer to spot gaps and rehearse a tighter follow-up.

Curated: · Written: · Reviewed:

QA-1

Threat-model indirect prompt injection in a RAG agent.

QA-2

How do you define risk tiering and threshold criteria to classify generative AI systems across safety, bias, and compliance domains?

QA-3

Assess an AI feature under the EU AI Act.

QA-4

Design tenant-safe RAG authorization.

QA-5

Map NIST AI RMF to organizational controls.

QA-6

Design privacy-preserving AI observability.

QA-7

How do cryptographic provenance standards like C2PA and robust watermarking differ in tamper-resistance and verification for generative AI outputs?

QA-8

Review a dataset before AI use.

QA-9

How do you establish governance gates, monitoring, and fallback protocols for model degradation, concept drift, and continuous fine-tuning in production?

QA-10

Design a fairness evaluation for a high-impact classifier.

QA-11

Design effective human oversight.

QA-12

Run an AI system red-team program.

QA-13

Secure a write-capable AI agent.

QA-14

Design an AI supply-chain control plane.

QA-15

How do you triage, contain, and remediate an active prompt injection or model hallucination security incident in production?

QA-16

Write an AI incident-response runbook.

QA-17

Create an AI risk register entry.

QA-18

Perform AI vendor due diligence.

QA-19

Design layered AI transparency.

QA-20

Design AI production monitoring and stop criteria.

QA-21

Define a misuse evaluation suite.

QA-22

Handle sparse fairness-evaluation slices.

QA-23

Plan retirement of an AI feature.

QA-24

Build AI authorization regression tests.

QA-25

Conduct a final AI security and governance review.