AAIR Exam Prep

Free AAIR exam practice questions with answers and explanations, organized by domain and part.

Domain 3: AI Operations/Resilience / Part E - AI Supply Chain Risk Management

Q1 Right-to-audit clauses in AI vendor contracts are valuable PRIMARILY because they:

Answer: A

Audit rights provide independent verification of controls; they don't guarantee zero incidents, transfer liability (addressed by indemnification/liability clauses), or remove the enterprise's own due-diligence obligations.

Domain 2: AI Lifecycle / Part C - AI Implementation, Maintenance, and Decommissioning

Q2 A rollback plan for a failed AI deployment should BEST ensure:

Answer: B

Rollback is a containment control that limits impact by reverting to a known-good state; it does not itself fix the root cause, hide failures, or remove the need for further testing.

Domain 1: AI Governance / Part A - AI Models, Frameworks, Strategies, and Use Cases

Q3 An enterprise evaluating AI use-case prioritization should PRIMARILY ensure that:

Answer: C

Prioritization must weigh value against risk exposure together; ROI alone ignores risk, and cost- or request-order-driven prioritization ignores both value and risk.

Domain 1: AI Governance / Part A - AI Models, Frameworks, Strategies, and Use Cases

Q4 When selecting an AI governance framework, what should an enterprise consider FIRST?

Answer: D

Framework selection should serve the enterprise's actual strategy and risk appetite; breadth of coverage without fit, peer popularity, and certification cost are secondary or irrelevant.

Domain 3: AI Operations/Resilience / Part F - AI Incident Response, BIA, Business Continuity, and Disaster Recovery

Q5 An enterprise evaluating AI incident response team composition should PRIMARILY ensure that:

Answer: A

Effective incident response needs cross-functional composition from the start, not a narrow team expanded only once an incident becomes public, nor a technical- or developer-only team.

Domain 3: AI Operations/Resilience / Part D - AI Risk Metrics, Monitoring, and Reporting

Q6 An enterprise evaluating integration of AI risk metrics into enterprise reporting should PRIMARILY ensure that:

Answer: B

AI risk metrics should be integrated into enterprise reporting, not kept in a parallel report, confined to the development team, or compressed into an unexplained score.

Domain 2: AI Lifecycle / Part D - AI Data and Asset Management

Q7 Data lineage tracking for AI training data is valuable PRIMARILY because it:

Answer: C

Lineage tracking supports traceability for audit and quality control; it does not itself clean data or improve accuracy, and it is not limited to storage savings or marketing use.

Domain 3: AI Operations/Resilience / Part C - AI Controls Management

Q8 In the context of segregation of duties in AI operations, which of the following represents sound AI risk management?

Answer: D

Segregation of duties requires different people performing development, validation, and approval concurrently; rotating one person through all three over time does not achieve segregation.

Domain 3: AI Operations/Resilience / Part C - AI Controls Management

Q9 In the context of control testing frequency for AI systems, which of the following represents sound AI risk management?

Answer: A

Testing frequency should scale with risk; a uniform annual cycle, audit-triggered testing, and one-time testing all fail to reflect risk-proportionate oversight.

Domain 1: AI Governance / Part B - AI Organizational Processes and Alignment

Q10 In the context of process alignment for AI change management, which of the following represents sound AI risk management?

Answer: B

AI changes should flow through existing, integrated change management; a parallel AI-only process, exemption, and ad hoc approval all undermine consistent governance.

‹ Prev
Next ›
Page 1 of 50 · 500 questions