DLP flagged customer records pasted into an unsanctioned public AI chatbot
A easy Cybersecurity scenario on Shadow AI Sensitive-Data Exposure.
Start a graded attempt against this scenario. Your response is scored by the same deterministic rubric used across the catalog. Email and evidence content stay hidden until you start.
Launches this exact scenario. One of 6 templates in this Track + Difficulty pool.
catalog id · shadow-ai-sensitive-data-exposure
What this scenario practices, mapped to recognized frameworks.
Educational mapping only. Not a compliance attestation.
- Shadow-AI data-exposure triage
- Scope-before-notify discipline for third-party data leaks
- Exfiltration Over Web Service · ExfiltrationT1567 · TA0010PartialMedium confidence
Trains reasoning about sensitive data leaving to a public web AI service.
- Network Traffic AnalysisD3-NTAMappedHigh confidence
Trains use of DLP and web-proxy telemetry to scope the exposure.
- User Account PermissionsD3-UAPMappedMedium confidence
Trains restricting the unsanctioned-tool usage that caused the leak.
- Continuous Monitoring · DetectDE.CM · DEMappedHigh confidence
Trains detection from DLP and web-proxy telemetry.
- Data Security · ProtectPR.DS · PRMappedMedium confidence
Trains data-handling controls for sensitive records.
- IR lifecycle phaseDetection & AnalysisMappedHigh confidence
Trains scoping exactly what data was exposed before notifying.
- IR lifecycle phaseContainment, Eradication & RecoveryMappedHigh confidence
Trains containment via category blocking and vendor deletion requests.
- Vendor/Supplier Cybersecurity Requirements2.RMappedMedium confidence
Trains governance of an unsanctioned third-party AI tool.
- Detecting Relevant Threats and TTPs3.AMappedMedium confidence
Trains detection of unsanctioned data egress to GenAI services.
- Data ProtectionControl 3MappedHigh confidence
Trains the data-protection control the scenario exercises.
- Security Awareness and Skills TrainingControl 14MappedMedium confidence
Trains the awareness baseline that reduces shadow-AI pastes.