ISACA AAIR Certification Sample Questions

AAIR Dumps, AAIR PDF, AAIR VCE, ISACA Advanced in AI Risk VCE, ISACA Advanced in AI Risk PDFThe purpose of this Sample Question Set is to provide you with information about the ISACA Advanced in AI Risk (AAIR) exam. These sample questions will make you very familiar with both the type and the difficulty level of the questions on the AAIR certification test. To get familiar with real exam environment, we suggest you try our Sample ISACA Advanced in AI Risk Certification Practice Exam. This sample practice exam gives you the feeling of reality and is a clue to the questions asked in the actual ISACA Advanced in AI Risk (AAIR) certification exam.

These sample questions are simple and basic questions that represent likeness to the real ISACA Advanced in AI Risk exam questions. To assess your readiness and performance with real-time scenario based questions, we suggest you prepare with our Premium ISACA AAIR Certification Practice Exam. When you solve real time scenario based questions practically, you come across many difficulties that give you an opportunity to improve.

ISACA AAIR Sample Questions:

01. Five business units have each identified a scenario in which a shared enterprise model produces outputs that are unreliable for a particular customer segment. Each unit has proposed its own local control to compensate for the effect in its own process.
Which approach should the risk professional recommend as the BEST treatment?
a) Require the units to agree a common local control and implement it consistently across their processes
b) Allow each unit to implement its own control, since each understands its own process and customers best
c) Consolidate the five scenarios into one enterprise entry and assign it to the largest affected unit
d) Treat the shared cause centrally, retaining local controls only where a unit has exposure the central fix leaves
 
02. A risk professional reviews entries proposed for an enterprise AI risk register. One entry reads: "Artificial intelligence poses significant risk to the organization and should be monitored closely."
Which characteristic does this entry MOST clearly lack?
a) A reference to the AI systems in the enterprise inventory that the entry is intended to cover
b) A specific threat event and affected asset, without which no owner, control or measure can be assigned
c) An assessment of likelihood and impact expressed on the enterprise's standard rating scale
d) A treatment plan setting out how the enterprise intends to respond to the risk described
 
03. To accelerate AI adoption, a financial services group has asked internal audit to design the control set for its AI systems and to help business teams implement it, on the basis that audit has the strongest understanding of control requirements. Audit will continue to provide annual assurance over AI controls.
Which concern should the risk professional raise as the PRIMARY issue?
a) Internal audit's involvement in implementation will consume audit resource planned for other areas of the annual plan
b) Internal audit does not have the operational knowledge of AI systems needed to design controls that teams can implement
c) Internal audit's control set may not align with the control framework the risk function maintains for other technology risks
d) Internal audit would be providing assurance over controls it designed and would lose the independence its opinion depends on
 
04. An assessment of an AI system records a high rating, noting that the enterprise has implemented input validation, output review and access restrictions that substantially reduce the exposure. The rating recorded does not reflect those controls.
Which statement BEST describes the rating recorded and what else should be reported?
a) Aggregate risk has been recorded, and the individual scenario ratings should also be reported
b) Residual risk has been recorded, and the inherent risk before controls should also be reported
c) Inherent risk has been recorded, and residual risk after the controls should also be reported
d) Target risk has been recorded, and the current level of risk should also be reported
 
05. A distribution business is documenting responsibilities for a demand-forecasting model. Monitoring has shown performance decay, and the data science team wants to retrain the model on more recent data, which will change the forecasts operations teams rely on for staffing.
Who should MOST appropriately be assigned accountability for approving the retraining decision?
a) The business owner of the forecasting process, who is answerable for the operational outcomes the forecasts drive
b) The AI governance forum, which maintains oversight of model changes across the enterprise portfolio
c) The data science team lead, whose team detected the decay and holds the expertise to judge the technical remedy
d) The platform operations manager, who controls the deployment pipeline through which the retrained model would be released
 
06. An enterprise assesses AI risk scenarios using historical incident frequency to set likelihood. For a newly deployed generative use case there is no incident history, and assessors have recorded likelihood as "low" on the basis that nothing has yet occurred.
Which flaw should the risk professional identify as the MOST significant?
a) Likelihood assessments should be reviewed periodically as operational experience with the system accumulates
b) Likelihood and impact should be assessed together, since a low likelihood may still warrant treatment
c) Absence of incidents in a newly deployed system is not evidence that the scenario is unlikely to occur
d) Likelihood should be assessed using the frequency of comparable incidents reported across the wider industry
 
07. A listed company's board has asked what its own role should be in relation to AI, given that management has established an AI governance function, assigned risk owners and implemented a control framework.
Which activity is MOST appropriately retained by the board itself?
a) Satisfying itself that management operates within a board-approved AI risk appetite
b) Approving individual high-consequence AI use cases before they are permitted to enter production
c) Reviewing the effectiveness of individual AI controls and directing remediation where testing identifies weaknesses
d) Approving the AI governance function's operating model, budget and reporting lines within the management structure
 
08. Six months after deploying a model that recommends inventory reorder quantities, a retailer finds that buyers accept its recommendations in most categories but routinely override them in two categories where they consider the model unreliable.
Which conclusion should a post-implementation review MOST reasonably draw?
a) The override rate should be added to the monitoring dashboard, so the trend can be tracked over time
b) The model should be retrained on data restricted to the categories where its recommendations are accepted
c) The model's effective scope is narrower than its deployed scope and the two categories require assessment
d) Buyers in the two categories require additional training to interpret and act on the model's recommendations
 
09. A software vendor operates one underlying model that it applies to two products: an internal tool that summarizes meeting notes for its own staff, and a product feature that screens job applicants for corporate customers. Management asks whether both attract the same regulatory obligations because they share a model.
Which statement BEST describes how obligations attach?
a) Obligations attach to the model, so both products carry the same requirements because the model is shared
b) Obligations attach to the vendor's sector, so both products are governed by the rules applying to software vendors
c) Obligations attach at the point of sale, so only the customer-facing screening feature is in scope at all
d) Obligations attach to the use case and its potential effect on people, so the screening feature carries more
 
10. An insurer reviews its AI policy set annually each October. In March, a supervisory authority issues expectations on the governance of automated decision-making that materially change what the insurer must document and demonstrate.
Which response is the BEST one for the risk professional to recommend?
a) Record the change on the compliance obligations register and address it at the scheduled October review
b) Trigger an out-of-cycle policy review because a material change in obligations is a defined review trigger
c) Assess whether existing policy wording can be read as consistent with the new expectations before amending it
d) Issue interim guidance to affected teams promptly and defer the policy amendment to the annual review

Answers:

Question: 01
Answer: d
Question: 02
Answer: b
Question: 03
Answer: d
Question: 04
Answer: c
Question: 05
Answer: a
Question: 06
Answer: c
Question: 07
Answer: a
Question: 08
Answer: c
Question: 09
Answer: d
Question: 10
Answer: b

Note: For any error in ISACA Advanced in AI Risk (AAIR) certification exam sample questions, please update us by writing an email on feedback@edusum.com.

Rating: 5 / 5 (1 vote)