Pre-Summer Sale Special - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: mxmas70

Home > Isaca > AI Risk > AAIR

AAIR ISACA Advanced in AI Risk Question and Answers

Question # 4

Which of the following AI system considerations BEST mitigates risk associated with model drift?

A.

Conducting regular retraining with new relevant datasets

B.

Restricting the use of automated data validation to low-risk models

C.

Maintaining existing levels of variance within datasets during preprocessing

D.

Implementing strong access controls based on roles and responsibilities

Full Access
Question # 5

Which of the following is the PRIMARY benefit of integrating AI risk processes into an enterprise risk framework?

A.

More accurate benchmarking of AI key performance indicators (KPIs)

B.

Improved compliance with regulatory requirements

C.

Rapid identification of cyber threats and risks

D.

Organization-level oversight and strategic alignment

Full Access
Question # 6

Which of the following is the PRIMARY benefit of aligning AI risk management with existing organizational governance frameworks?

A.

It emphasizes the development of specialized functional roles and clarifies AI risk responsibility boundaries.

B.

It expedites approval processes for compliance with AI laws and regulations.

C.

It promotes consistent enterprise-level oversight of AI activities and aligns decisioning with strategic objectives.

D.

It standardizes AI acquisition processes across organizational business units.

Full Access
Question # 7

Which of the following is the BEST course of action to mitigate risk during model selection of supervised or unsupervised algorithms?

A.

Emphasize the generalization capability of algorithms.

B.

Require the use of supervised learning for model training projects.

C.

Prioritize cost reductions related to computational requirements.

D.

Align algorithmic capabilities to intended use cases.

Full Access
Question # 8

Which of the following is a risk practitioner's BEST recommendation to establish accountability for AI system outputs and decisions?

A.

Centralized governance task force for model decision authority

B.

Continuous monitoring and key performance indicators (KPIs)

C.

Regular reviews of resource allocation for AI projects

D.

Formal documented role assignments with named owners

Full Access
Question # 9

An organization has deployed an AI system that initially performs well but whose outputs deteriorate over time despite stable input characteristics. Which of the following is the BEST course of action?

A.

Engage periodic external audits of model source code and implement peer code reviews.

B.

Replace the system's predictive capability with static rule-based controls and fixed decision logic.

C.

Focus efforts on dataset cleansing and documentation prior to further system updates.

D.

Establish continuous performance monitoring and scheduled system recalibration.

Full Access
Question # 10

Which of the following should be the MOST important area of focus during the development of data security risk scenarios specific to AI?

A.

Attack vectors enabled by techniques for malicious alteration of AI system outputs

B.

Documentation of business unit readiness for secure adoption of AI for general operations

C.

Development and communication of need-based access policies for the use of AI applications

D.

Quantum encryption methods for the protection of proprietary organizational data assets

Full Access
Question # 11

Which of the following is the GREATEST concern when an organization cannot clearly explain an AI system's decision-making process and the origin of its inputs?

A.

Increased dependence on external AI service providers for managing AI system risk throughout its life cycle

B.

Decrease in AI adoption rates within business units who are regularly responsible for critical decisions

C.

Inability to detect discriminatory or inaccurate outputs that expose the organization to regulatory and reputational risk

D.

Heightened reliance on manual review resulting in approval bottlenecks and slower response times

Full Access
Question # 12

An organization uses multiple external data sources to train its AI models. Which of the following is the risk practitioner's BEST recommendation to protect the organization from data poisoning attacks?

A.

Data integrity reviews in response to indications that significant model drift has occurred

B.

Continuous monitoring and anomaly detection for data ingestion pipelines

C.

Stringent controls over model code and deployment artifacts

D.

Enhanced regularization and training techniques to limit the influence of anomalies

Full Access
Question # 13

Which of the following is the MOST important reason for a risk practitioner to classify AI risk using threat actor profiles?

A.

To align AI threat and vulnerability risk with the overall IT control taxonomy

B.

To tailor controls to adversary motivations and capabilities

C.

To develop response metrics for AI cybersecurity incidents

D.

To ensure external threats to corporate assets are given highest priority

Full Access
Question # 14

Which of the following is the PRIMARY benefit of integrating AI-driven business intelligence into enterprise risk processes?

A.

Reduced costs through elimination of redundant business risk oversight mechanisms

B.

Enhanced alignment of analysis outputs with organizational risk thresholds

C.

Automated production of technical performance reports for AI business tools

D.

Centralized governance of AI inventory and classification activities

Full Access
Question # 15

Risk practitioners use automated tools to generate potential AI risk scenarios. Which of the following represents the GREATEST risk from that approach?

A.

Likelihood and impact scoring may be more complex.

B.

Emerging adversarial attack vectors may be overlooked.

C.

Impacts from model changes may be underestimated.

D.

Scenarios may not account for all process interdependencies.

Full Access
Question # 16

Which of the following is the MOST important consideration when managing changes to an AI model in production?

A.

Allowing operational teams to adjust configuration parameters for real-time performance tuning

B.

Implementing stringent approval processes for user access to new model functionalities

C.

Conducting rigorous validation to assess effects on predictive accuracy and model bias

D.

Expediting rollout of changes in production to ensure service continuity and minimize downtime

Full Access
Question # 17

A manufacturing organization has implemented an autonomous navigation system for warehouse operations. Which of the following should a risk practitioner regard as the MOST significant concern?

A.

The system is unable to learn from complex situations not encountered during training.

B.

The deep neural network used by the system contains datasets with proprietary information.

C.

The system is used to accelerate just-in-time warehouse processes.

D.

The organization uses outside contractors to address the lack of in-house AI knowledge.

Full Access
Question # 18

An organization uses an AI model that learns from live data streams. Which of the following is the BEST course of action to manage the risk of an adaptive model?

A.

Utilize a defense-in-depth control approach for model access.

B.

Restrict data sources and perform periodic data quality inspections.

C.

Apply dynamic performance thresholds and conduct scheduled recalibrations.

D.

Implement automated monitoring to detect data drift and data poisoning.

Full Access
Question # 19

Which of the following BEST mitigates risk associated with evasion attacks on AI models?

A.

API rate limiting

B.

Anomaly detection

C.

Predictive analytics

D.

Feature importance weighting

Full Access
Question # 20

Which of the following is the MOST important consideration when determining mitigation controls for an AI system?

A.

Providing comprehensive AI risk awareness training to security and technical personnel

B.

Determining control performance baselines and reporting requirements for regulatory compliance

C.

Evaluating control effectiveness and costs against potential business losses from unmitigated AI risk

D.

Prioritizing controls based on the complexity and computational requirements of the AI system

Full Access
Question # 21

A risk practitioner reviews an AI model that ingests diverse external feeds and determines that their reliability is not consistent. Which of the following BEST mitigates this risk?

A.

Weighting historical records over recent samples to limit induced variance

B.

Updating to the latest model version to accurately reflect real-world data changes

C.

Establishing data provenance and implementing stage gate quality reviews

D.

Reducing the diversity of the external feeds and the number of classes

Full Access
Question # 22

Which of the following should be the PRIMARY consideration when determining the priority for restoration of AI systems following a model exfiltration attack?

A.

Reliance on the AI system for critical business requirements

B.

AI-specific expertise among business continuity team members

C.

Cost of AI system vulnerability testing and patch deployment

D.

Availability of externally vetted datasets for AI model retraining

Full Access
Question # 23

An organization integrates multiple AI services using APIs to enhance a customer support chatbot. Which of the following is the GREATEST risk?

A.

Greater likelihood of bias or inaccuracy in chatbot responses

B.

Unauthorized disclosure of sensitive records via insecure external connections

C.

Customer dissatisfaction from operational delays

D.

Insufficient training datasets due to outdated or limited sample coverage

Full Access
Question # 24

Which of the following poses the GREATEST challenge related to the protection of intellectual property generated by AI solutions?

A.

Use of third-party AI service providers that have zero-data retention policies

B.

Difficulty in customizing training materials for users on confidential data handling in AI environments

C.

Lack of regulatory clarity regarding the copyright status of AI-generated content

D.

Inherent risk in fundamental AI use cases such as general inquiries or administrative tasks

Full Access
Question # 25

Which of the following BEST enables an organization adopting AI solutions to foster an ethical and risk-aware culture?

A.

All business units use checklists to ensure AI risk and ethical concerns are addressed.

B.

Senior management representatives actively participate in industry conferences related to AI ethics.

C.

AI policies include clear disciplinary actions for violations of risk and ethical standards.

D.

Leadership consistently models ethical behavior and values for AI development and use.

Full Access
Question # 26

Which of the following is the BEST governance approach for balancing risk management and operational flexibility across diverse AI applications?

A.

Control approaches for AI solutions that prioritize compliance on a single regulation

B.

Frameworks that can be adapted to business-relevant AI use cases

C.

External consultants who conduct independent AI governance reviews

D.

Risk ownership processes that focus on ensuring centralized decision-making

Full Access
Question # 27

A risk practitioner is performing a post-implementation review for an AI system used for credit scoring. Which of the following is MOST important for the risk practitioner to confirm?

A.

Access token runtime is logged and timestamped.

B.

The AI system's decisions are explainable and fair.

C.

Performance metrics are frequently communicated to stakeholders.

D.

Employees find the AI system easy to learn and use.

Full Access