01 · Mental model
An LLM predicts a useful continuation
A large language model receives tokens representing the current context and estimates which tokens are useful to produce next. The result can be fluent, structured, and surprisingly capable without being a database lookup or a proof engine.
For cybersecurity work, separate three questions: what the model can infer, what evidence the application supplied, and what the control plane allows the system to do. A persuasive answer may still be unsupported; a grounded answer should carry inspectable evidence.
02 · Visual explanation
03 · Compare and decide
Fluent is not the same as grounded
| Decision lens | Model capability | System assurance |
|---|---|---|
| Answer generation | Produces a plausible continuation | Checks the answer against trusted evidence |
| Knowledge | Patterns learned plus current context | Approved sources, freshness, and citations |
| Confidence | May sound certain | Uses explicit uncertainty and verification |
| Security | Can interpret untrusted text | Keeps untrusted text outside the authority boundary |
04 · Cybersecurity example
SOC example: explain an unfamiliar alert
An analyst pastes an alert payload and asks for a likely explanation.
The model interprets entities and sequence.
Retrieval supplies the current product documentation.
A tool checks asset and identity context.
The analyst validates the conclusion before action.
Outcome: The LLM accelerates interpretation; evidence and the analyst own the decision.
05 · What to remember
The 60-second recall
An LLM generates; it does not automatically verify.
Context quality changes the answer, not the model weights.
Grounding, policy, and review belong to the surrounding system.
Teach-back prompt: Explain this concept to a teammate using the diagram, then name one failure mode and the control that stops it.
06 · Questions people ask
FAQ
07 · Primary sources