AAIR Exam Prep

Free AAIR exam practice questions with answers and explanations, organized by domain and part.

Domain 3: AI Operations/Resilience / Part A - AI Risk Scenario Identification and Assessment

Q121 A risk scenario involving malicious manipulation of an AI model's input prompts to bypass its intended restrictions is an example of:

Answer: B

This describes prompt injection, a specific AI security risk scenario.

Domain 3: AI Operations/Resilience / Part F - AI Incident Response, BIA, Business Continuity, and Disaster Recovery

Q122 Recovery Time Objective (RTO) for a critical AI system should be set based on:

Answer: B

RTO should reflect actual tolerable downtime derived from business impact, not arbitrary choice.

Domain 2: AI Lifecycle / Part C - AI Implementation, Maintenance, and Decommissioning

Q123 When piloting a new AI model before full production rollout, the MOST appropriate approach is to:

Answer: D

A limited pilot with representative users and clear success criteria validates real-world performance and surfaces issues before enterprise-wide exposure.

Domain 3: AI Operations/Resilience / Part E - AI Supply Chain Risk Management

Q124 When addressing fourth-party AI risk exposure, an AI risk practitioner should FIRST:

Answer: D

Fourth-party exposure should be actively assessed, not assumed to be fully covered by the vendor or ignored absent disclosure.

Domain 1: AI Governance / Part B - AI Organizational Processes and Alignment

Q125 Insufficient resource allocation for AI oversight MOST likely results in:

Answer: B

Under-resourced oversight functions fail to scale with growing AI risk.

Domain 1: AI Governance / Part C - AI Ownership, Oversight, and Accountability

Q126 When addressing three lines of defense for AI oversight, an AI risk practitioner should FIRST:

Answer: D

The three lines of defense model separates execution, risk oversight, and independent assurance for AI.

Domain 3: AI Operations/Resilience / Part E - AI Supply Chain Risk Management

Q127 In the context of AI supply chain risk mapping, which of the following represents sound AI risk management?

Answer: C

Full supply chain mapping, including sub-vendors, is needed and should be kept current, not limited to direct vendors or a one-time exercise.

Domain 1: AI Governance / Part D - AI Policies, Procedures, and Organizational Training

Q128 A policy exception process for AI controls should require:

Answer: B

Exceptions need documented, time-bound, appropriately authorized risk acceptance.

Domain 3: AI Operations/Resilience / Part E - AI Supply Chain Risk Management

Q129 Regarding supply chain AI model provenance verification, the BEST practice is to:

Answer: A

Provenance/integrity verification should apply broadly, including to open-source components, not be skipped or scoped only to regulated cases.

Domain 3: AI Operations/Resilience / Part E - AI Supply Chain Risk Management

Q130 A documented vendor exit strategy for a critical AI supplier is important PRIMARILY to:

Answer: B

Exit strategies protect business continuity if a critical vendor relationship ends.

‹ Prev
Next ›
Page 13 of 50 · 500 questions