Scoping a RAG poisoning test, how do you price which of several feeding sources to attempt?
answer
- weakest review is only one axis
- durable write, not just accepted
- will the owner notice and revert
- does the source even get retrieved
- cost in time and burned identities
basics
~20 sThe weakest-reviewed source is not automatically the best target. Price each on three things together: how loose its review is, how likely its owner is to notice and revert, and whether its content actually reaches readers. A loose source nobody retrieves, or one whose owner reverts within a day, is a poor foothold.
solid answer
~60 sConsider a compliance-answering assistant whose corpus unions three outside-fed sources - a standards body's errata page, a vendor FAQ, and a partner intake queue. As a red-teamer you can attempt any of them, and the temptation is to pick whichever reviews least. That is only one axis. Weakest review lowers the cost of getting a write accepted, but the payoff is a *durable* write into a store other people's questions read, and durability depends on more. How likely is that source's owner to notice an anomalous entry and revert it? A loose source that is closely watched after the fact gives a short-lived foothold. Does that source's content plausibly reach the queries you care about, or is it rarely surfaced? A write nobody retrieves is worthless however easily it landed. And what does each attempt cost you in time and in burned identities - a queue that ties a submission to a vetted filer is expensive even if its review is light. You price the attempt as review-cost against durability, reach, and identity cost, and the weakest source is often not the best buy.
go deeper
You are not expected to price a multi-source engagement; recognising that some sources are easier to write to than others is enough at this level.
Be able to name the axes beyond review strength - durability, reach, cost - even if you do not weigh them in a live scoping call.
Demonstrate the full pricing: weigh review cost against durability, retrieval reach and identity cost, and give a case where the weakest source is the wrong buy.
Own the tradeoff framing and the reporting - what a landed write does and does not prove, and how the attempt's cost is communicated as a priced finding.
## Reframing the choice as a purchase A junior framing is: find the source with the weakest review and write there. A senior framing prices the whole attempt, because the goal is not "a write got accepted" but "a durable write into a store real queries read." Weak review is one input to that price, not the whole of it. Take the concrete setting: a compliance-answering assistant whose index is built by ingesting three outside-fed sources - a standards body's public errata page, a vendor-maintained product FAQ, and a partner intake queue that accepts filings for review. A red-teamer scoping the engagement can attempt any of the three. Which is the best buy? ## The axes to price **Review cost.** How hard is it to get a write accepted at this source? This is the axis the weak-review proxies measure. It sets the up-front cost of the attempt. **Durability.** Once accepted, how long does the write survive? A source whose owner watches for and reverts anomalies gives a short-lived foothold even if the initial write was trivial. The relevant question is not just "will review let it in" but "will anyone notice and pull it later." A loosely-reviewed but closely-audited source can be a worse target than a moderately-reviewed but unwatched one. **Reach.** Does this source's content plausibly get retrieved for the queries that matter? Sources are not equal contributors to answers; some are rarely surfaced. A write that lands easily into a source nobody's questions retrieve is worthless. The best target is one whose content is both easy to write and actually reaches readers. **Identity and time cost.** What does the attempt cost the attacker? A queue that ties every submission to a vetted, named filer imposes an identity cost - the attacker spends a credential or a persona they may not get back - even if the review itself is light. An open page costs almost nothing. Time matters too: a source that only rebuilds occasionally stretches the engagement. ## Why weakest review is often not the answer Put those together and the weakest-reviewed source frequently loses. The errata page might publish instantly (cheap review) but be closely watched by an editor who reverts oddities (poor durability). The vendor FAQ might review lightly and rarely change but almost never be retrieved for the queries in scope (poor reach). The partner queue might have a real moderator (higher review cost) but, once past it, produce a document nobody re-reads and that answers exactly the queries of interest (high durability and reach). The best buy is the one that maximises durable, reaching foothold per unit of cost - not the one that is simply easiest to write to. ## What the red-teamer reports The engagement chair has to report not just "it worked" but what the attempt cost: which source was chosen and why, how many identities or credentials were spent, how long the write survived, and whether it demonstrably reached answers. That report is the deliverable, and it is framed in exactly these axes. ## Discipline about what a success proves A landed write proves the source's review was passable and the write is currently present. It does not prove permanence - the owner may revert tomorrow - and it does not, on its own, prove reach unless retrieval was demonstrated. A careful red-teamer separates "accepted at the source" from "durable" from "reaches answers," because conflating them overstates the finding. ## Why interviewers ask it This is production judgment: given several viable sources, choose and justify. A candidate who says "pick the weakest review" has priced one axis. The stronger answer weighs durability, reach and cost, and can explain a case where the weakest-reviewed source is the wrong buy. That reasoning is what a red-team scoping decision actually looks like, and it is what a defender must anticipate about how targets are selected.
- Why can a moderately-reviewed source be a better target than the weakest-reviewed one?Because the payoff is a durable, reaching write, not just an accepted one. A weak-review source that is closely audited and reverted, or whose content is rarely retrieved, yields a short-lived or invisible foothold. A moderately-reviewed source that nobody re-reads and whose content answers the queries in scope can deliver far more durable reach per unit of cost.
- What does a red-teamer's report on this attempt have to state beyond that it worked?Which source was chosen and the reasoning, the cost paid in time and in identities or credentials burned, how long the write survived before any reversion, and whether it was shown to actually reach answers. Those axes turn a one-off success into a priced finding a defender can act on, rather than a claim that a write was once accepted.
saying these in an interview costs you the question
- Picks the weakest-reviewed source with no other consideration
- Ignores whether the source's content is ever retrieved
- Treats an accepted write as a permanent foothold
- Omits identity and time cost from the decision