Winter Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: myex65

Home > Isaca > Advanced in AI Audit > AAIA

AAIA ISACA Advanced in AI Audit (AAIA) Question and Answers

Question # 4

When developing an audit plan, which of the following is MOST important specifically for the transparency of an AI application?

A.

Explainability testing

B.

Regression testing

C.

Compliance testing

D.

Validation testing

Full Access
Question # 5

When reviewing contracts or other lengthy documentation in the planning phase, which of the following tools would BEST extract relevant information?

A.

Robotic process automation (RPA)

B.

Autoregressive sequencing model

C.

Predictive analytics

D.

Natural language processing

Full Access
Question # 6

An IS auditor is auditing an AI system that predicts inventory needs. The system recently failed to predict a stock outage for a key product. Which of the following audit tests would BEST validate the system's accuracy?

A.

Unit testing of the forecasting algorithm

B.

Load testing during peak sales periods

C.

Sensitivity analysis on input variables

D.

Historical testing with past sales data

Full Access
Question # 7

Which of the following BEST detects model drift or unexpected changes in AI model outputs?

A.

Standardization of AI configurations

B.

Anomaly monitoring

C.

AI model documentation reviews

D.

AI model retraining

Full Access
Question # 8

What is the MOST important reason government organizations should provide regular AI training programs for all staff?

A.

To minimize the cost of AI deployment

B.

To ensure staff are up to date on ethical considerations

C.

To allow staff to understand the tools available

D.

To reduce learning using outdated information

Full Access
Question # 9

Which of the following BEST demonstrates effective coordination to ensure comprehensive oversight of an AI system deployed across multiple jurisdictions?

A.

Focusing oversight activities on technical anomaly detection metrics

B.

Establishing joint oversight plans and communication channels between agencies

C.

Centralizing responsibility under a single supervisory authority

D.

Relying on automated processes for anomaly detection and documentation

Full Access
Question # 10

Which of the following is the BEST recommendation to mitigate excessive agency when implementing an AI system as a browser extension?

A.

Minimize browser extension functionality.

B.

Remove user access to browser extensions.

C.

Maximize browser extension functionality.

D.

Use open-source browser extensions.

Full Access
Question # 11

Which of the following insider threats involving the use of AI would present the GREATEST risk?

A.

Leaking of system hyperparameters

B.

Launching social engineering attacks

C.

Destroying system backups

D.

Exfiltrating sensitive data

Full Access
Question # 12

Which of the following is the MOST important risk for an IS auditor to consider when reviewing the adoption of an AI system?

A.

Costs associated with AI system maintenance

B.

Immaturity of AI systems in the industry

C.

Bias in AI system decision making

D.

Resistance to the use of AI technology

Full Access
Question # 13

An AI developer notices that the labeling guidelines changed during the project and asks an IS auditor for advice. Which of the following is the auditor's BEST recommendation to perform prior to retraining?

A.

Augment the model with additional layers to capture old and new labeling policies.

B.

Increase class weights on recently labeled data only.

C.

Train a larger model to absorb guideline variance.

D.

Relabel stratified samples to estimate shift and adjust data sets accordingly.

Full Access
Question # 14

An AI audit reveals that a loan approval model has a significantly higher rejection rate for a specific demographic group. What should be management's PRIMARY response?

A.

Accept the audit findings as within risk tolerance.

B.

Determine if audit sampling is sufficient.

C.

Conduct comprehensive bias analysis.

D.

Synthesize more data of the affected demographic group.

Full Access
Question # 15

The PRIMARY purpose of utilizing neural networks in AI is to:

A.

Improve the user interface.

B.

Increase computational power.

C.

Mimic human decision making.

D.

Minimize maintenance costs.

Full Access
Question # 16

Which of the following controls would MOST effectively mitigate worst-case service disruption scenarios affecting an AI-based application system?

A.

Performing periodic tabletop exercises

B.

Implementing a kill chain process in the event of disruption

C.

Updating key risk indicators (KRIs) regularly

D.

Including a range of AI disruption scenarios in the disaster recovery plan (DRP)

Full Access
Question # 17

An IS auditor is interviewing management about implemented controls around machine learning (ML) models deployed in the production environment. Which of the following schedules for reviewing the performance of a deployed model would be of GREATEST concern to the auditor?

A.

After changes to hardware and software platforms

B.

After functionality changes

C.

One time prior to migrating to production

D.

On an annual recurring basis

Full Access
Question # 18

Which of the following is the PRIMARY advantage of using K-fold cross validation when evaluating the performance of a machine learning (ML) model?

A.

It facilitates performing regressions on smaller data sets.

B.

It helps minimize computational costs when evaluating complex models.

C.

It enables the reduction of model bias by setting the K variable to higher values.

D.

It uses multiple training and testing cycles to minimize overfitting.

Full Access
Question # 19

An IS auditor reviews an AI tool using K-means to cluster customers. One cluster shows very high spending but low product diversity. What should the auditor recommend?

A.

Document the algorithm failed because high spending customers did not exhibit high product diversity.

B.

Treat the cluster as a potentially valid segment of loyal customers with limited product interest.

C.

Increase the number of clusters to better capture variations in spending behavior.

D.

Replace K-means clustering with a supervised learning model for more accurate analysis.

Full Access
Question # 20

An IS auditor is testing an AI-based fraud detection system that flags suspicious transactions and finds that the system has a high false positive rate. Which of the following testing methods should be prioritized to BEST optimize the detection rate?

A.

Regression testing

B.

Cross-validation testing

C.

Substantive testing

D.

Benford's Law analysis

Full Access
Question # 21

Which of the following should be an IS auditor’s GREATEST concern when reviewing an anomaly detection process implemented for a high-risk AI system?

A.

Failure to identify anomalies that can bias training data

B.

Lack of regular quality reviews for training data

C.

Infrequent updates to anomaly detection algorithms

D.

Inadequate staff training on the use of the system

Full Access
Question # 22

Which of the following is the MOST effective control to safeguard a model’s architecture, weights, and hyperparameters?

A.

Provide training to employees on best practices for AI technical security

B.

Require users to sign a confidentiality agreement before accessing the model

C.

Maintain detailed data audit logs of deviations in training data

D.

Implement strict access controls and encryption for model components

Full Access
Question # 23

Which of the following is MOST important for an IS auditor to review during an AI system audit in order to determine compliance with intellectual property and data rights?

A.

Data performance metrics

B.

Data usage agreements

C.

Use of open-source intellectual property

D.

Model runtime efficiency logs

Full Access
Question # 24

An internal audit department notices that AI-generated audit reports are producing false conclusions. Which of the following is the BEST way to correct this issue?

A.

Increase the model context.

B.

Suspend utilization of the tool until resolved.

C.

Decrease the model's creativity score.

D.

Update service level agreements (SLAs).

Full Access
Question # 25

Which of the following should be of GREATEST concern to an IS auditor when reviewing ethical considerations for an AI solution?

A.

The decision-making process is unexplainable.

B.

The solution is hosted on a shared cloud environment.

C.

The model has not been retrained recently.

D.

The solution documentation is still in draft.

Full Access
Question # 26

An IS auditor is looking to expedite reporting for an audit with complex issues. Which of the following would be the MOST effective way for the auditor to use generative AI?

A.

Developing action items discussed in closing meetings for management action plans

B.

Developing a draft of an executive summary based on detailed findings and audit scope

C.

Revising audit conclusions with precise verbiage to describe the audit observations

D.

Revising audit background and scope information based on new information from management

Full Access
Question # 27

Which metric is MOST important to consider when reviewing the performance of a machine learning model in avoiding false positive results?

A.

Precision

B.

Accuracy

C.

F1 score

D.

Recall

Full Access
Question # 28

When an IS auditor is reviewing results from an AI system, which of the following would cause the GREATEST risk?

A.

Inability to identify where an AI system is housed

B.

System output not being checked for inconsistencies

C.

Cascading failures of AI system outputs

D.

Difficulty of documenting AI algorithm processes

Full Access
Question # 29

Which of the following is the GREATEST concern when an audit team relies on generative AI to create audit reports?

A.

The reports may be more likely to reflect outdated information.

B.

The reports may contain misstatements resulting from hallucinations.

C.

The reports may use inconsistent formatting from prior audit findings.

D.

The reports may tend to use generic language for audit issues.

Full Access
Question # 30

When auditing a machine learning (ML) solution, false positives can BEST be assessed by examining the level of:

A.

Precision

B.

Completeness

C.

Accuracy

D.

Recall

Full Access
Question # 31

When converting data categories before training an AI model, which of the following scenarios represents the GREATEST risk?

A.

One-hot encoding the data attribute car colors for the options red, blue, green, black, white

B.

Creating dummy variables for the data attribute dog breed for the options labrador, terrier, beagle

C.

One-hot encoding the data attribute customer rewards category for the options economy, business, first class

D.

Creating dummy variables for the data attribute product flavor for the options vanilla, chocolate, strawberry, banana

Full Access
Question # 32

Which metric should an IS auditor review to evaluate issues with data collection that could impact AI model training?

A.

Percentage of epochs used

B.

Percentage of missing values

C.

Percentage of data in training dataset

D.

Percentage of true positives on confusion matrix

Full Access
Question # 33

Which of the following BEST ensures representativeness in AI systems when assessing training data periodically?

A.

Training data is manually reviewed for bias.

B.

Data validation processes are automated and consistently performed.

C.

Training data remains relevant and reflects evolving real-world conditions.

D.

Synthetic data is used to train the AI systems.

Full Access
Question # 34

An organization is using information gathered from customer accounts to train its AI chatbot. Which of the following is the GREATEST risk associated with this practice?

A.

Disclosure of personal information

B.

AI bias

C.

Transparency

D.

AI model hallucinations

Full Access
Question # 35

Which of the following is the MOST effective way an IS auditor could use generative AI to plan an audit of a new database storing transactional data?

A.

Identifying separation of duties conflicts for database data changes

B.

Developing architecture diagrams

C.

Identifying technology-specific risk and considerations

D.

Summarizing meeting transcripts from interviews with database administrators (DBAs)

Full Access
Question # 36

From a data appropriateness and bias perspective, which of the following should be of GREATEST concern when reviewing an AI model used in a credit scoring system?

A.

The model incorporates the applicant's loan history to assess spending habits.

B.

The model utilizes historical credit data to predict future credit behavior.

C.

The model considers the applicant's income level as a key factor in the credit decision.

D.

The model uses postal codes as a primary factor in determining creditworthiness.

Full Access
Question # 37

A newly deployed fraud detection model is misclassifying transactions due to inconsistent formatting in the data stream. What is the BEST recommendation?

A.

Define and document the technical specifications for incoming data

B.

Enable real-time monitoring of transaction volumes

C.

Train staff on fraud patterns and alert handling

D.

Increase model complexity to handle more input types

Full Access
Question # 38

A retail organization uses an AI model to analyze customers' purchase history in order to offer personalized discounts. Which of the following practices represents the MOST ethical use of customer data?

A.

Utilizing customer purchase data only after obtaining explicit consent and allowing customers to opt out

B.

Retaining and analyzing all available customer data to ensure unbiased recommendations

C.

Providing the public with access to review and audit the data set of collected customer information

D.

Sharing customer purchase data with third-party vendors to improve advertising and communication

Full Access
Question # 39

For a sales promotion, an AI system sorts customer attributes into several categories by analyzing transaction history. Verifying which of the following would BEST validate the effectiveness of this process?

A.

Stress tests are regularly conducted to maintain consistent AI performance.

B.

The applied methodology adequately reflects business objectives.

C.

Sensitive attributes are converted to other data types prior to input.

D.

Sampling of AI output is conducted to identify unusual decisions.

Full Access
Question # 40

A car manufacturer uses an AI model to predict maintenance needs for its vehicles. Which of the following techniques can an IS auditor apply to MOST effectively verify the AI model's decisions to stakeholders?

A.

Using neural network visualization to show how the AI model processes data through its layers

B.

Using K-means algorithms to group vehicles based on mileage or engine temperature for maintenance patterns

C.

Utilizing support vector machines (SVM) to classify vehicles based on maintenance urgency

D.

Using local interpretable model-agnostic explanation (LIME) to analyze how specific features contribute to predictions

Full Access
Question # 41

While evaluating a complex machine learning (ML) model used for regulatory compliance in a financial institution, which of the following should the IS auditor do to BEST ensure transparency?

A.

Document sources and data processes.

B.

Create dashboards to show outputs.

C.

Provide periodic model audit reports.

D.

Use tools that explain model decisions.

Full Access
Question # 42

Which of the following would provide the BEST evidence to an IS auditor that an AI model’s outputs are effectively controlled for bias?

A.

Accuracy ranges for various demographic groups are similar.

B.

The organization’s AI policies include a clear definition of fairness.

C.

Model training is restricted to data containing real-world human decisions.

D.

Technical details of model development processes are transparent.

Full Access
Question # 43

A digital bank utilizes an AI system to generate credit scores. Which of the following would BEST mitigate the risk of sudden and unexplained changes in a borrower’s credit score?

A.

Ensuring the system is periodically reviewed and calibrated by human experts to maintain stability in predictions

B.

Using only data from the last six months to one year to avoid outdated information affecting the credit score

C.

Allowing the AI to operate fully autonomously to prevent processing delays

D.

Obtaining and validating the credit scores from third-party agencies to cross-check AI-generated results

Full Access
Question # 44

Which of the following is the GREATEST risk associated with using AI in audit planning?

A.

Increased planning costs

B.

Scope creep

C.

Incomplete data

D.

Limited knowledge

Full Access
Question # 45

Which of the following is the MOST important reason for applying regular software updates to AI systems operating in high-risk environments?

A.

To safeguard the systems against AI-powered zero-day exploits

B.

To accelerate model training cycles and enhance processing speed

C.

To reduce the need for human oversight of model outputs

D.

To address vulnerabilities and reduce the risk of output integrity attacks

Full Access
Question # 46

An IS auditor for a veterinary clinic was informed that the dog breed categorical variable is necessary for the predictive model. Which of the following introduces the MOST risk?

A.

Data scaling was not utilized.

B.

Clustering was not utilized.

C.

Ordinal label encoding was utilized.

D.

One-hot encoding was utilized.

Full Access
Question # 47

Which of the following is the MOST important step in an AI incident management process to ensure continuous improvement?

A.

Define ownership

B.

Root cause analysis

C.

Archive logs

D.

Assess severity

Full Access
Question # 48

Which of the following AI system characteristics would BEST help an IS auditor evaluate the system's algorithm?

A.

The AI system algorithm uses training data to inform decision output.

B.

The AI system provides multiple options for model training.

C.

The AI system provides transparent justification of decisions.

D.

The AI system uses archived transaction data to provide decisions.

Full Access
Question # 49

Which of the following presents the MOST significant barrier to generative AI model explainability?

A.

Bias within data sets used for model training

B.

Rapid evolution of algorithm capabilities

C.

Lack of alignment between stakeholder groups

D.

Insufficient staff experience with generative AI tools

Full Access
Question # 50

When utilizing a machine learning (ML) model to predict whether a wind turbine electricity generator will fail, which model evaluation metric should be the PRIMARY focus?

A.

Precision

B.

Specificity

C.

Accuracy

D.

Recall

Full Access
Question # 51

Which of the following is the GREATEST risk associated with deploying an AI system with ineffective anomaly detection?

A.

Inconsistent AI system configuration management

B.

Undetected data poisoning that impacts AI decision quality

C.

Delayed incident response to AI model drift

D.

Failure to comply with AI reporting standards

Full Access
Question # 52

Which of the following initially provides assurance that the developer correctly interprets and identifies numerical data for balancing prior to inserting into the model?

A.

Data dictionary

B.

Data computing library

C.

Statistical summary

D.

Confusion matrix

Full Access
Question # 53

Which of the following is the PRIMARY purpose of an AI acceptable use policy?

A.

Establishing guidance on the ethical use of AI

B.

Outlining AI usage monitoring procedures

C.

Educating employees on where to find and how to use AI tools

D.

Explaining the distinction between different types of AI

Full Access
Question # 54

Which of the following is the GREATEST data quality risk when using an AI tool to assist with audit procedures?

A.

Utilizing unstructured data sources without standardized preprocessing

B.

Training models on historical audit results generated prior to AI adoption

C.

Embedding AI audit tools in transactional systems without user training

D.

Applying automated anomaly detection without human oversight

Full Access