AAIR Exam Prep

Free AAIR exam practice questions with answers and explanations, organized by domain and part.

Domain 3: AI Operations/Resilience / Part A - AI Risk Scenario Identification and Assessment

Q101 An AI-specific risk taxonomy is valuable PRIMARILY because it:

Answer: B

A shared taxonomy enables consistent identification and comparison of AI risks.

Domain 2: AI Lifecycle / Part C - AI Implementation, Maintenance, and Decommissioning

Q102 In the context of rollback planning for AI deployments, which of the following represents sound AI risk management?

Answer: C

Rollback plans should be prepared proactively for deployments, not created reactively after failure.

Domain 1: AI Governance / Part C - AI Ownership, Oversight, and Accountability

Q103 Within an AI governance program, the chief AI officer (CAIO) role is BEST described as:

Answer: A

The CAIO role can be standalone or absorbed into an existing role; what matters is that it leads AI adoption and reports to executive management, not that it is a distinct legally mandated title.

Domain 3: AI Operations/Resilience / Part D - AI Risk Metrics, Monitoring, and Reporting

Q104 When addressing AI risk reporting to stakeholders, an AI risk practitioner should FIRST:

Answer: A

Reporting should be tailored to audience needs, not uniform, on-demand only, or restricted to technical teams.

Domain 2: AI Lifecycle / Part D - AI Data and Asset Management

Q105 With respect to AI training data access controls, which approach is MOST appropriate for an enterprise managing AI risk?

Answer: A

Access controls should follow data sensitivity classification across both training and production data, not informal trust.

Domain 3: AI Operations/Resilience / Part A - AI Risk Scenario Identification and Assessment

Q106 With respect to AI-specific risk scenario development, which approach is MOST appropriate for an enterprise managing AI risk?

Answer: A

AI risk scenarios should be tailored beyond generic IT risk and security-only scenarios, developed proactively.

Domain 1: AI Governance / Part D - AI Policies, Procedures, and Organizational Training

Q107 An enterprise evaluating employee AI training program design should PRIMARILY ensure that:

Answer: A

Role-tailored AI training addresses differing risk exposure better than one-size-fits-all or team-limited training.

Domain 3: AI Operations/Resilience / Part A - AI Risk Scenario Identification and Assessment

Q108 When addressing risk assessment scope for third-party AI components, an AI risk practitioner should FIRST:

Answer: B

Risk assessment scope must include third-party and embedded AI, not rely on vendor assessments or exclude 'minor' features.

Domain 2: AI Lifecycle / Part B - AI Model Training, Testing, and Validation

Q109 Maintaining strict separation between training, testing, and validation datasets is important to:

Answer: B

Separation prevents the model from being evaluated on data it has already seen, which would inflate apparent performance.

Domain 3: AI Operations/Resilience / Part B - AI Risk Treatment Strategies

Q110 With respect to risk treatment option selection, which approach is MOST appropriate for an enterprise managing AI risk?

Answer: A

Treatment choice should be a cost-benefit decision aligned with risk appetite, not a default to one option.

‹ Prev
Next ›
Page 11 of 50 · 500 questions