AAIR Exam Prep

Free AAIR exam practice questions with answers and explanations, organized by domain and part.

Domain 3: AI Operations/Resilience / Part F - AI Incident Response, BIA, Business Continuity, and Disaster Recovery

Q131 With respect to AI incident classification scheme, which approach is MOST appropriate for an enterprise managing AI risk?

Answer: A

Severity/type-based classification enables proportionate response, rather than uniform, after-the-fact, or security-only classification.

Domain 1: AI Governance / Part B - AI Organizational Processes and Alignment

Q132 Regarding cross-functional AI committee composition, the BEST practice is to:

Answer: C

Effective AI governance requires cross-functional representation, not a single-function decision group.

Domain 3: AI Operations/Resilience / Part F - AI Incident Response, BIA, Business Continuity, and Disaster Recovery

Q133 With respect to AI incident response team composition, which approach is MOST appropriate for an enterprise managing AI risk?

Answer: B

Cross-functional incident response composition is needed, not technical-only, reactive, or single-developer-reliant.

Domain 1: AI Governance / Part E - AI Regulatory Compliance and Legal Considerations

Q134 An enterprise evaluating regulatory horizon scanning for AI should PRIMARILY ensure that:

Answer: D

Ongoing horizon scanning across relevant jurisdictions is needed, not infrequent, vendor-dependent, or single-jurisdiction monitoring.

Domain 1: AI Governance / Part A - AI Models, Frameworks, Strategies, and Use Cases

Q135 When addressing enterprise AI strategy documentation, an AI risk practitioner should FIRST:

Answer: B

AI strategy documentation should explicitly tie to risk appetite and business objectives to guide consistent decisions.

Domain 1: AI Governance / Part E - AI Regulatory Compliance and Legal Considerations

Q136 In the context of documentation for regulatory AI audits, which of the following represents sound AI risk management?

Answer: D

Audit-ready AI documentation must be maintained proactively and substantively, not assembled reactively or kept informally.

Domain 3: AI Operations/Resilience / Part A - AI Risk Scenario Identification and Assessment

Q137 In the context of AI-specific risk scenario development, which of the following represents sound AI risk management?

Answer: C

AI risk scenarios should be tailored beyond generic IT risk and security-only scenarios, developed proactively.

Domain 2: AI Lifecycle / Part A - AI Design, Development/Procurement, and Documentation

Q138 With respect to explainability requirements at design stage, which approach is MOST appropriate for an enterprise managing AI risk?

Answer: C

Explainability requirements should be risk-based and considered during design, not uniform or deferred.

Domain 3: AI Operations/Resilience / Part D - AI Risk Metrics, Monitoring, and Reporting

Q139 Trend analysis of AI risk KRIs over time is MOST useful for:

Answer: A

Trend analysis surfaces gradual deterioration that single-point-in-time metrics might miss.

Domain 3: AI Operations/Resilience / Part C - AI Controls Management

Q140 With respect to control framework mapping for AI, which approach is MOST appropriate for an enterprise managing AI risk?

Answer: A

Mapping to a recognized framework, kept current, supports completeness; ad hoc or one-time-only mapping risks gaps.

‹ Prev
Next ›
Page 14 of 50 · 500 questions