AAIR Exam Prep

Free AAIR exam practice questions with answers and explanations, organized by domain and part.

Domain 1: AI Governance / Part A - AI Models, Frameworks, Strategies, and Use Cases

Q231 An AI maturity assessment is MOST useful for:

Answer: A

Maturity assessments gauge current vs. target capability, driving a prioritized roadmap.

Domain 3: AI Operations/Resilience / Part C - AI Controls Management

Q232 A control's operating effectiveness refers to:

Answer: B

Operating effectiveness is about real-world, ongoing performance of the control.

Domain 1: AI Governance / Part E - AI Regulatory Compliance and Legal Considerations

Q233 A "risk-based" AI regulatory approach (e.g., EU AI Act tiering) requires the enterprise to PRIMARILY:

Answer: B

Risk-based regulation requires tiered classification and proportionate control application.

Domain 3: AI Operations/Resilience / Part E - AI Supply Chain Risk Management

Q234 Ongoing vendor risk monitoring (not just pre-contract due diligence) is important PRIMARILY because:

Answer: B

Vendor risk can evolve, so monitoring must continue beyond the initial assessment.

Domain 1: AI Governance / Part A - AI Models, Frameworks, Strategies, and Use Cases

Q235 Comparing candidate AI frameworks, an enterprise should weigh "ease of integration with existing GRC tooling" because it:

Answer: B

Integration ease is a practical adoption factor, not a compliance guarantee.

Domain 1: AI Governance / Part A - AI Models, Frameworks, Strategies, and Use Cases

Q236 Regarding build vs buy AI strategy, the BEST practice is to:

Answer: C

Build-vs-buy decisions require weighing risk, control, and cost, not defaulting to one option automatically.

Domain 3: AI Operations/Resilience / Part F - AI Incident Response, BIA, Business Continuity, and Disaster Recovery

Q237 In the context of AI incident classification scheme, which of the following represents sound AI risk management?

Answer: C

Severity/type-based classification enables proportionate response, rather than uniform, after-the-fact, or security-only classification.

Domain 2: AI Lifecycle / Part C - AI Implementation, Maintenance, and Decommissioning

Q238 Scheduled maintenance/retraining of an AI model is driven PRIMARILY by:

Answer: B

Retraining cadence should track actual drift/conditions, not arbitrary calendar convenience.

Domain 1: AI Governance / Part F - AI Trustworthiness, Ethical, and Societal Implications

Q239 The distinction between "human-in-the-loop" and "human-on-the-loop" oversight models is BEST described as:

Answer: A

Human-in-the-loop gates each decision on human approval, whereas human-on-the-loop permits autonomous AI action with a human able to monitor and intervene; the choice should match the decision's stakes.

Domain 3: AI Operations/Resilience / Part A - AI Risk Scenario Identification and Assessment

Q240 Regarding AI risk register maintenance, the BEST practice is to:

Answer: D

The AI risk register should be actively maintained and updated, not static, partial, or infrequently reviewed.

‹ Prev
Next ›
Page 24 of 50 · 500 questions