Free AAIR exam practice questions with answers and explanations, organized by domain and part.
Domain 3: AI Operations/Resilience / Part A - AI Risk Scenario Identification and Assessment
Q121 A risk scenario involving malicious manipulation of an AI model's input prompts to bypass its intended restrictions is an example of:
- A. Data retention risk
- B. Prompt injection risk
- C. Vendor concentration risk
- D. Societal impact risk
Answer: B
This describes prompt injection, a specific AI security risk scenario.
Domain 3: AI Operations/Resilience / Part F - AI Incident Response, BIA, Business Continuity, and Disaster Recovery
Q122 Recovery Time Objective (RTO) for a critical AI system should be set based on:
- A. Arbitrary preference with no analysis
- B. The maximum downtime the business can tolerate before unacceptable impact occurs
- C. The vendor's convenience
- D. The shortest possible time regardless of cost
Answer: B
RTO should reflect actual tolerable downtime derived from business impact, not arbitrary choice.
Domain 2: AI Lifecycle / Part C - AI Implementation, Maintenance, and Decommissioning
Q123 When piloting a new AI model before full production rollout, the MOST appropriate approach is to:
- A. Pilot only with internal IT staff regardless of the model's intended user base
- B. Skip piloting for models built on well-established algorithms
- C. Deploy directly to all users and monitor for issues afterward
- D. Run the model in a limited pilot with a representative user subset and defined success criteria before scaling
Answer: D
A limited pilot with representative users and clear success criteria validates real-world performance and surfaces issues before enterprise-wide exposure.
Domain 3: AI Operations/Resilience / Part E - AI Supply Chain Risk Management
Q124 When addressing fourth-party AI risk exposure, an AI risk practitioner should FIRST:
- A. Limit risk assessment strictly to contracted first-party vendors
- B. Assume fourth-party risk is the vendor's sole responsibility to manage
- C. Ignore fourth-party risk unless specifically disclosed by the vendor
- D. Assess risk exposure from fourth parties (a vendor's own subcontractors/suppliers) in the AI supply chain
Answer: D
Fourth-party exposure should be actively assessed, not assumed to be fully covered by the vendor or ignored absent disclosure.
Domain 1: AI Governance / Part B - AI Organizational Processes and Alignment
Q125 Insufficient resource allocation for AI oversight MOST likely results in:
- A. Faster AI deployment with no downside
- B. Governance processes that cannot keep pace with AI risk growth
- C. Lower regulatory scrutiny
- D. Reduced need for policies
Answer: B
Under-resourced oversight functions fail to scale with growing AI risk.
Domain 1: AI Governance / Part C - AI Ownership, Oversight, and Accountability
Q126 When addressing three lines of defense for AI oversight, an AI risk practitioner should FIRST:
- A. Rely solely on the development team for AI oversight
- B. Rely solely on external auditors for ongoing AI oversight
- C. Combine all oversight functions into one team to save cost
- D. Apply three lines of defense (business, risk/compliance, audit) to AI oversight
Answer: D
The three lines of defense model separates execution, risk oversight, and independent assurance for AI.
Domain 3: AI Operations/Resilience / Part E - AI Supply Chain Risk Management
Q127 In the context of AI supply chain risk mapping, which of the following represents sound AI risk management?
- A. Assume sub-vendor risk is immaterial if not contractually visible
- B. Map the supply chain only once at initial vendor onboarding
- C. Map the full AI supply chain, including sub-vendors and third-party data/model providers, not just direct vendors
- D. Assess risk only for the primary contracted vendor
Answer: C
Full supply chain mapping, including sub-vendors, is needed and should be kept current, not limited to direct vendors or a one-time exercise.
Domain 1: AI Governance / Part D - AI Policies, Procedures, and Organizational Training
Q128 A policy exception process for AI controls should require:
- A. No documentation, to keep things fast
- B. Documented risk acceptance by an appropriately authorized owner, with an expiry/review date
- C. Permanent exceptions with no review
- D. Approval only from the requesting team itself
Answer: B
Exceptions need documented, time-bound, appropriately authorized risk acceptance.
Domain 3: AI Operations/Resilience / Part E - AI Supply Chain Risk Management
Q129 Regarding supply chain AI model provenance verification, the BEST practice is to:
- A. Verify the provenance and integrity of third-party AI models and components before integration
- B. Integrate third-party models without verifying their origin or integrity
- C. Assume open-source AI components carry no provenance risk
- D. Verify provenance only for models used in regulated use cases
Answer: A
Provenance/integrity verification should apply broadly, including to open-source components, not be skipped or scoped only to regulated cases.
Domain 3: AI Operations/Resilience / Part E - AI Supply Chain Risk Management
Q130 A documented vendor exit strategy for a critical AI supplier is important PRIMARILY to:
- A. Avoid ever needing to switch vendors
- B. Ensure continuity of the business function if the vendor relationship must end
- C. Reduce the vendor's negotiating leverage only
- D. Satisfy only legal department preference
Answer: B
Exit strategies protect business continuity if a critical vendor relationship ends.