AAIR ISACA Advanced in AI Risk Questions and Answers
Which of the following should be the PRIMARY consideration when determining the priority for restoration of AI systems following a model exfiltration attack?
Risk practitioners use automated tools to generate potential AI risk scenarios. Which of the following represents the GREATEST risk from that approach?
Which of the following AI system considerations BEST mitigates risk associated with model drift?
Which of the following is the BEST way to integrate AI risk management into operational procedures?
Which of the following is the BEST course of action to mitigate risk during model selection of supervised or unsupervised algorithms?
A risk practitioner learns that an AI system used by a manufacturer for quality control (QC) has produced inaccurate responses that could potentially impact user safety. Which of the following is the risk practitioner's BEST recommendation to mitigate this risk?
Which of the following would be of GREATEST concern to a risk practitioner reviewing the testing and validation of an AI-driven technical support system?
Which of the following is the PRIMARY benefit of incorporating new AI-specific controls?
Which of the following is the GREATEST organizational risk when AI performance alerts are not escalated to decision-makers for review and decisioning?
Which of the following BEST helps to ensure adherence to data minimization principles when using an AI model whose training dataset contains personal information?
An organization has identified a moderate AI exposure from potential model inaccuracies that could affect internal reporting. The risk falls within the organization's defined tolerance. Which of the following is the BEST course of action?
An organization deploys an AI credit scoring model trained on historical financial data that underrepresents certain demographic groups. Which of the following is the risk practitioner's BEST recommendation to mitigate this risk?
A risk practitioner learns that a credit-scoring AI system is exhibiting bias that cannot be eliminated through further training. Which of the following is the risk practitioner's BEST recommendation?
Which of the following is the GREATEST risk when an organization relies only on adversarial training to protect a private AI model in a testing environment?
An organization embeds AI into existing processes without integrating AI risk practices into enterprise governance. Which of the following should a risk practitioner regard as the GREATEST organizational risk?
An organization depends on multiple external suppliers for AI models and training datasets. Which of the following is MOST important to have in place in order to reduce supply chain risk?
To reinforce organization-wide ethical norms and risk recognition, which of the following is MOST important to integrate into AI user training?
An organization has developed an AI code of conduct outlining ethical use, data privacy, and transparency principles. Which of the following is the BEST approach to integrate the code of conduct into workforce training?
Which of the following poses the GREATEST challenge related to the protection of intellectual property generated by AI solutions?
Which of the following is the PRIMARY benefit of integrating AI-driven business intelligence into enterprise risk processes?
A credit-scoring AI solution exhibits steadily declining accuracy despite unchanged input distributions. Which of the following should a risk practitioner consider to be the GREATEST risk?
Which of the following is the PRIMARY benefit of implementing a comprehensive data pipeline for AI model training, testing, and validation?
Which of the following BEST helps to ensure AI model outputs can be reproduced in other environments?
An organization deploys an autonomous system that makes decisions affecting compliance with regulations. If those decisions could potentially produce regulatory breaches, which of the following BEST helps to manage associated liability exposures?