Construct AI triage input and evidence gates

A hands-on CS0-004 lab. You produce the real artefact and 8 automated checks verify it behaves the way the exam expects.

Try this labAll CS0-004 practice

Certification
CS0-004
Format
Structured configuration
Difficulty
hard
Estimated time
35 min
Automated checks
8

The brief

Repair ai-triage-rules.json using hitPolicy unique or first and 1..24 distinct {id,when,then} rows. Inputs: data public,internal,restricted; purpose triage,model-training; provider approved,unreviewed; grounding corroborated,unsupported,injected. when nonempty category arrays combine by AND; omitted fields are wildcards. then must contain input (proceed,minimize,withhold), handling (purpose-review,provider-review,private-route,quarantine-output,analyst-review,verify-evidence), autonomy (boolean true or false). Apply this local policy in precedence order: model-training always yields withhold/purpose-review. For triage, unreviewed provider always yields withhold/provider-review. Triage at an approved provider with restricted data always yields withhold/private-route. For approved triage with public/internal data, injected grounding always yields withhold/quarantine-output. Remaining public data may proceed; remaining internal data must minimize. For both, corroborated grounding requires analyst-review; unsupported grounding requires verify-evidence. Earlier permission gates determine the handling reason even when grounding is injected; an input permission failure cannot be bypassed by a grounded-looking result. Autonomy is false for EVERY context. No row authorizes model-driven containment, incident closure or evidence deletion, including corroborated public input. A model-training opt-out or provider label cannot replace permitted purpose/classification. Evaluate all 36 contexts. Unique requires exactly one matching row. First permits deliberate overlap when earlier permission gates precede later evidence fallbacks. Every context needs exact outputs; every row must contribute. Use only supplied fields, typed values and meaningful reachable priority. Disjoint gates or ordered broad fallbacks are valid. Run tests, inspect actual input/handling/authority mismatches, save and repair without Reset.

What the checks verify

Your work is graded on 8 independent properties, not on matching one reference answer.

  • Distinct conditional records and explicit hit policy form an editable triage gate artifact.
  • Only supplied purpose, provider, classification, grounding and typed output facts are used.
  • Every permitted and denied context retains an explicit disposition.
  • Permission and evidence priorities resolve each context according to the selected policy.
  • Every permission or evidence gate can contribute under the chosen ordering.
  • Actual purpose, provider, data and injected grounding determine input admission.
  • Actual permission failure or evidence state determines the retained handling reason.
  • Generated output never acquires machine-action authority from a successful input or corroborated claim.

Where this sits in the CS0-004 blueprint

Domain
Security Operations
Objective
AI in Security Operations
Skill
AI Risks and Analyst Verification

Part of CS0-004 preparation

Labs are written by ExamNova to teach the decisions the exam tests. They are not reproductions of vendor lab content.