AAIR Exam Prep

Free AAIR exam practice questions with answers and explanations, organized by domain and part.

Domain 3: AI Operations/Resilience / Part D - AI Risk Metrics, Monitoring, and Reporting

Q11 An enterprise evaluating key risk indicator thresholds for AI should PRIMARILY ensure that:

Answer: C

KRI thresholds should be risk-appropriate per system and trigger timely escalation; a single uniform threshold, no threshold, and quarterly-only review all fall short.

Domain 2: AI Lifecycle / Part D - AI Data and Asset Management

Q12 With respect to data retention policy for AI systems, which approach is MOST appropriate for an enterprise managing AI risk?

Answer: D

AI data needs retention/disposal schedules tailored to its specific risks; an unmodified general policy, indefinite retention, and ad hoc individual decisions do not provide this.

Domain 1: AI Governance / Part B - AI Organizational Processes and Alignment

Q13 An enterprise evaluating cross-functional AI committee composition should PRIMARILY ensure that:

Answer: A

Effective governance committees need full cross-functional representation from the start, not legal/risk added reactively, nor decisions confined to one function.

Domain 1: AI Governance / Part D - AI Policies, Procedures, and Organizational Training

Q14 When addressing new-hire AI onboarding training, an AI risk practitioner should FIRST:

Answer: B

AI risk awareness needs dedicated onboarding content; generic security training alone, technical-only scope, and optional participation all leave gaps.

Domain 1: AI Governance / Part B - AI Organizational Processes and Alignment

Q15 An enterprise evaluating AI center of excellence role should PRIMARILY ensure that:

Answer: C

A central coordinating function standardizes practices across the enterprise; informal unit-level coordination, independent standards, and avoiding centralization all leave practices fragmented.

Domain 3: AI Operations/Resilience / Part F - AI Incident Response, BIA, Business Continuity, and Disaster Recovery

Q16 Lessons learned from an AI incident should PRIMARILY be used to:

Answer: D

Lessons learned should feed back into controls, policy, and training; reporting without a mandate to act, filing away, and public blame-assignment all fail to close the loop.

Domain 1: AI Governance / Part B - AI Organizational Processes and Alignment

Q17 A RACI matrix for AI risk governance is MOST useful for:

Answer: A

RACI clarifies decision roles (R/A/C/I), which is distinct from an org chart of titles/hierarchy, and unrelated to licensing costs or automation.

Domain 3: AI Operations/Resilience / Part F - AI Incident Response, BIA, Business Continuity, and Disaster Recovery

Q18 Regarding business continuity planning for AI outages, the BEST practice is to:

Answer: B

Continuity plans need AI-specific failure scenarios (e.g., model degradation, not just infrastructure loss); extending only a data-center failover plan, assuming generic coverage, or limiting scope to infrastructure all miss AI-specific failure modes.

Domain 2: AI Lifecycle / Part A - AI Design, Development/Procurement, and Documentation

Q19 Design-stage threat modeling for an AI system should PRIMARILY identify:

Answer: C

Design-stage threat modeling targets risks inherent to the AI system's design (adversarial, data, misuse), not generic infrastructure vulnerabilities, which are covered by standard IT security processes.

Domain 1: AI Governance / Part E - AI Regulatory Compliance and Legal Considerations

Q20 When AI regulations conflict across jurisdictions where the enterprise operates, legal counsel should be engaged to:

Answer: D

Legal counsel should determine actual applicability and recommend a defensible path; choosing by cost alone, ignoring rules, or avoiding documentation are not substitutes for that analysis.

‹ Prev
Next ›
Page 2 of 50 · 500 questions