AAIR Exam Prep

Free AAIR exam practice questions with answers and explanations, organized by domain and part.

Domain 3: AI Operations/Resilience / Part B - AI Risk Treatment Strategies

Q91 A compensating control for an AI risk should be used when:

Answer: B

Compensating controls provide equivalent mitigation when the primary control isn't fully feasible.

Domain 1: AI Governance / Part D - AI Policies, Procedures, and Organizational Training

Q92 When addressing AI acceptable use policy scope, an AI risk practitioner should FIRST:

Answer: C

An AI acceptable use policy should be explicit and enterprise-wide, not informal or narrowly scoped.

Domain 2: AI Lifecycle / Part A - AI Design, Development/Procurement, and Documentation

Q93 When addressing data lineage documentation during development, an AI risk practitioner should FIRST:

Answer: B

Full data lineage documentation supports traceability and risk management regardless of data source or incident history.

Domain 3: AI Operations/Resilience / Part F - AI Incident Response, BIA, Business Continuity, and Disaster Recovery

Q94 When addressing AI incident communication to affected stakeholders, an AI risk practitioner should FIRST:

Answer: C

Timely, accurate communication to all appropriately affected stakeholders is expected, not delayed, internal-only, or selectively positive.

Domain 2: AI Lifecycle / Part B - AI Model Training, Testing, and Validation

Q95 In the context of model performance benchmarking, which of the following represents sound AI risk management?

Answer: C

Formal benchmarking against acceptance criteria should precede release, not rely on marginal improvement or developer confidence alone.

Domain 2: AI Lifecycle / Part B - AI Model Training, Testing, and Validation

Q96 Independent model validation (separate from the model development team) is valuable PRIMARILY because it:

Answer: B

Independent validation provides unbiased challenge, reducing developer conflict-of-interest risk.

Domain 1: AI Governance / Part E - AI Regulatory Compliance and Legal Considerations

Q97 When addressing AI contractual compliance clauses, an AI risk practitioner should FIRST:

Answer: B

Contracts with AI vendors should proactively include compliance and audit-rights clauses, not rely on verbal assurance or reactive amendment.

Domain 1: AI Governance / Part E - AI Regulatory Compliance and Legal Considerations

Q98 When addressing AI-specific legal review for new deployments, an AI risk practitioner should FIRST:

Answer: D

Legal review before go-live should assess the specific deployment, not rely on assumptions from unrelated prior reviews.

Domain 2: AI Lifecycle / Part B - AI Model Training, Testing, and Validation

Q99 Backtesting an AI model against historical outcomes is MOST useful for:

Answer: A

Backtesting checks real-world generalization, though it does not replace ongoing monitoring.

Domain 3: AI Operations/Resilience / Part B - AI Risk Treatment Strategies

Q100 With respect to treatment plan monitoring and follow-up, which approach is MOST appropriate for an enterprise managing AI risk?

Answer: C

Treatment plans require tracked completion and verified effectiveness, not approval alone or unclear ownership.

‹ Prev
Next ›
Page 10 of 50 · 500 questions