正解:D
The GREATEST insider threat is exfiltrating sensitive data (D). AI systems often contain rich datasets including personal, financial, operational, and proprietary information. If an insider extracts or leaks this data, the result can be severe legal, regulatory, and reputational consequences.
Destroying backups (C) affects availability but not confidentiality. Social engineering attacks (B) are serious but indirect. Hyperparameter leakage (A) exposes model configuration but usually does not endanger sensitive data directly. AAIA stresses that data confidentiality risks are the most severe category in AI governance.
References:
ISACA, AAIA Exam Content Outline - Domain 5: Ethical and Legal Risks; Data Protection and Confidentiality.