AAIR Exam Prep

Free AAIR exam practice questions with answers and explanations, organized by domain and part.

Domain 2: AI Lifecycle / Part C - AI Implementation, Maintenance, and Decommissioning

Q181 Deprecation notices to end users before retiring an AI-powered feature are PRIMARILY important because they:

Answer: A

Advance deprecation notices allow affected users time to adjust, reducing operational disruption; they are a user-communication step alongside, not a substitute for, the technical decommissioning plan.

Domain 1: AI Governance / Part A - AI Models, Frameworks, Strategies, and Use Cases

Q182 In the context of build vs buy AI strategy, which of the following represents sound AI risk management?

Answer: D

Build-vs-buy decisions require weighing risk, control, and cost, not defaulting to one option automatically.

Domain 3: AI Operations/Resilience / Part B - AI Risk Treatment Strategies

Q183 Regarding risk appetite application to AI decisions, the BEST practice is to:

Answer: A

Risk appetite should be defined upfront and applied consistently, not overridden by sponsorship or defined after the fact.

Domain 2: AI Lifecycle / Part B - AI Model Training, Testing, and Validation

Q184 Adversarial testing (red teaming) of an AI model is designed to:

Answer: B

Red teaming proactively surfaces weaknesses that standard testing may miss.

Domain 2: AI Lifecycle / Part D - AI Data and Asset Management

Q185 When training data contains outdated or stale records, the PRIMARY risk is:

Answer: B

Stale data can cause models to reflect outdated conditions, reducing output relevance/accuracy.

Domain 1: AI Governance / Part A - AI Models, Frameworks, Strategies, and Use Cases

Q186 In a build-versus-buy decision for an AI capability, which factor is MOST relevant to risk management?

Answer: B

Control/visibility over data and logic directly affects the organization's ability to manage AI risk.

Domain 3: AI Operations/Resilience / Part F - AI Incident Response, BIA, Business Continuity, and Disaster Recovery

Q187 In the context of business impact analysis for AI-dependent processes, which of the following represents sound AI risk management?

Answer: D

BIA should specifically assess AI-dependent processes and be kept current, not assumed equivalent to manual processes or updated only post-outage.

Domain 2: AI Lifecycle / Part A - AI Design, Development/Procurement, and Documentation

Q188 When evaluating a vendor's AI solution, which criterion is MOST relevant to risk management?

Answer: B

Risk-relevant criteria are substantive (validation, security, monitoring), not reputational.

Domain 1: AI Governance / Part E - AI Regulatory Compliance and Legal Considerations

Q189 Regarding extraterritorial AI regulation applicability, the BEST practice is to:

Answer: B

Extraterritorial applicability often depends on the location of affected individuals, not just company headquarters.

Domain 3: AI Operations/Resilience / Part C - AI Controls Management

Q190 In the context of control design for AI-specific risks, which of the following represents sound AI risk management?

Answer: C

AI risk requires purpose-built controls (bias, drift, explainability) beyond generic IT or security-only controls.

‹ Prev
Next ›
Page 19 of 50 · 500 questions