Free AAIR exam practice questions with answers and explanations, organized by domain and part.
Domain 2: AI Lifecycle / Part C - AI Implementation, Maintenance, and Decommissioning
Q181 Deprecation notices to end users before retiring an AI-powered feature are PRIMARILY important because they:
- A. Give users time to adapt workflows and reduce disruption from the feature's discontinuation
- B. Are optional if the feature was rarely used
- C. Replace the need for a technical decommissioning plan
- D. Are only required for consumer-facing, not internal, AI tools
Answer: A
Advance deprecation notices allow affected users time to adjust, reducing operational disruption; they are a user-communication step alongside, not a substitute for, the technical decommissioning plan.
Domain 1: AI Governance / Part A - AI Models, Frameworks, Strategies, and Use Cases
Q182 In the context of build vs buy AI strategy, which of the following represents sound AI risk management?
- A. Always build in-house for control reasons alone
- B. Always buy to minimize effort
- C. Decide based on vendor relationship history only
- D. Assess risk, control, and total cost of ownership differences between building and buying AI
Answer: D
Build-vs-buy decisions require weighing risk, control, and cost, not defaulting to one option automatically.
Domain 3: AI Operations/Resilience / Part B - AI Risk Treatment Strategies
Q183 Regarding risk appetite application to AI decisions, the BEST practice is to:
- A. Apply the enterprise's defined risk appetite consistently when deciding on AI risk treatment
- B. Apply different undocumented risk appetites across business units
- C. Ignore risk appetite when a use case has strong business sponsorship
- D. Define risk appetite only after treatment decisions are made
Answer: A
Risk appetite should be defined upfront and applied consistently, not overridden by sponsorship or defined after the fact.
Domain 2: AI Lifecycle / Part B - AI Model Training, Testing, and Validation
Q184 Adversarial testing (red teaming) of an AI model is designed to:
- A. Confirm the model never fails
- B. Proactively identify vulnerabilities or failure modes before attackers or edge cases do
- C. Replace functional testing entirely
- D. Satisfy only regulatory checkbox requirements
Answer: B
Red teaming proactively surfaces weaknesses that standard testing may miss.
Domain 2: AI Lifecycle / Part D - AI Data and Asset Management
Q185 When training data contains outdated or stale records, the PRIMARY risk is:
- A. Improved model relevance
- B. The model producing outputs misaligned with current real-world conditions
- C. No risk, since more data is always better
- D. Reduced training time only
Answer: B
Stale data can cause models to reflect outdated conditions, reducing output relevance/accuracy.
Domain 1: AI Governance / Part A - AI Models, Frameworks, Strategies, and Use Cases
Q186 In a build-versus-buy decision for an AI capability, which factor is MOST relevant to risk management?
- A. Marketing appeal of the vendor
- B. Internal control and visibility over the model's data and logic
- C. Speed of procurement paperwork
- D. Vendor's office location
Answer: B
Control/visibility over data and logic directly affects the organization's ability to manage AI risk.
Domain 3: AI Operations/Resilience / Part F - AI Incident Response, BIA, Business Continuity, and Disaster Recovery
Q187 In the context of business impact analysis for AI-dependent processes, which of the following represents sound AI risk management?
- A. Assume AI-dependent processes have the same impact profile as manual processes
- B. Perform BIA only for processes classified as mission-critical by IT alone
- C. Update BIA only after an AI-related outage occurs
- D. Conduct business impact analysis for critical processes that depend on AI systems
Answer: D
BIA should specifically assess AI-dependent processes and be kept current, not assumed equivalent to manual processes or updated only post-outage.
Domain 2: AI Lifecycle / Part A - AI Design, Development/Procurement, and Documentation
Q188 When evaluating a vendor's AI solution, which criterion is MOST relevant to risk management?
- A. Brand recognition
- B. Evidence of model validation, security testing, and ongoing monitoring capability
- C. Number of existing customers
- D. Marketing awards received
Answer: B
Risk-relevant criteria are substantive (validation, security, monitoring), not reputational.
Domain 1: AI Governance / Part E - AI Regulatory Compliance and Legal Considerations
Q189 Regarding extraterritorial AI regulation applicability, the BEST practice is to:
- A. Apply only the most lenient jurisdiction's rules globally
- B. Assess whether AI regulations apply extraterritorially based on where affected individuals are located
- C. Assume regulations only apply where the company is headquartered
- D. Ignore extraterritorial reach until a regulator intervenes
Answer: B
Extraterritorial applicability often depends on the location of affected individuals, not just company headquarters.
Domain 3: AI Operations/Resilience / Part C - AI Controls Management
Q190 In the context of control design for AI-specific risks, which of the following represents sound AI risk management?
- A. Design AI-specific controls only after a compliance finding
- B. Limit AI controls to data security measures alone
- C. Design controls specifically addressing AI risks such as bias, drift, and explainability gaps, not only generic IT controls
- D. Rely only on generic IT general controls for AI risk
Answer: C
AI risk requires purpose-built controls (bias, drift, explainability) beyond generic IT or security-only controls.