Construct AI triage input and evidence gates
A hands-on CS0-004 lab. You produce the real artefact and 8 automated checks verify it behaves the way the exam expects.
Try this labAll CS0-004 practice
- Certification
- CS0-004
- Format
- Structured configuration
- Difficulty
- hard
- Estimated time
- 35 min
- Automated checks
- 8
The brief
Repair ai-triage-rules.json using hitPolicy unique or first and 1..24 distinct {id,when,then} rows. Inputs: data public,internal,restricted; purpose triage,model-training; provider approved,unreviewed; grounding corroborated,unsupported,injected. when nonempty category arrays combine by AND; omitted fields are wildcards. then must contain input (proceed,minimize,withhold), handling (purpose-review,provider-review,private-route,quarantine-output,analyst-review,verify-evidence), autonomy (boolean true or false). Apply this local policy in precedence order: model-training always yields withhold/purpose-review. For triage, unreviewed provider always yields withhold/provider-review. Triage at an approved provider with restricted data always yields withhold/private-route. For approved triage with public/internal data, injected grounding always yields withhold/quarantine-output. Remaining public data may proceed; remaining internal data must minimize. For both, corroborated grounding requires analyst-review; unsupported grounding requires verify-evidence. Earlier permission gates determine the handling reason even when grounding is injected; an input permission failure cannot be bypassed by a grounded-looking result. Autonomy is false for EVERY context. No row authorizes model-driven containment, incident closure or evidence deletion, including corroborated public input. A model-training opt-out or provider label cannot replace permitted purpose/classification. Evaluate all 36 contexts. Unique requires exactly one matching row. First permits deliberate overlap when earlier permission gates precede later evidence fallbacks. Every context needs exact outputs; every row must contribute. Use only supplied fields, typed values and meaningful reachable priority. Disjoint gates or ordered broad fallbacks are valid. Run tests, inspect actual input/handling/authority mismatches, save and repair without Reset.
What the checks verify
Your work is graded on 8 independent properties, not on matching one reference answer.
- Distinct conditional records and explicit hit policy form an editable triage gate artifact.
- Only supplied purpose, provider, classification, grounding and typed output facts are used.
- Every permitted and denied context retains an explicit disposition.
- Permission and evidence priorities resolve each context according to the selected policy.
- Every permission or evidence gate can contribute under the chosen ordering.
- Actual purpose, provider, data and injected grounding determine input admission.
- Actual permission failure or evidence state determines the retained handling reason.
- Generated output never acquires machine-action authority from a successful input or corroborated claim.
Where this sits in the CS0-004 blueprint
- Domain
- Security Operations
- Objective
- AI in Security Operations
- Skill
- AI Risks and Analyst Verification
Part of CS0-004 preparation
Labs are written by ExamNova to teach the decisions the exam tests. They are not reproductions of vendor lab content.