AAIR Exam Prep

Free AAIR exam practice questions with answers and explanations, organized by domain and part.

Domain 3: AI Operations/Resilience / Part C - AI Controls Management

Q241 A control's design effectiveness refers to:

Answer: B

Design effectiveness is about whether the control's design would address the risk if executed properly.

Domain 3: AI Operations/Resilience / Part A - AI Risk Scenario Identification and Assessment

Q242 Regarding emerging AI risk identification, the BEST practice is to:

Answer: C

Continuous, enterprise-driven identification is needed for emerging AI risk, not one-time, audit-only, or peer-limited approaches.

Domain 3: AI Operations/Resilience / Part A - AI Risk Scenario Identification and Assessment

Q243 When addressing likelihood and impact estimation for AI risk, an AI risk practitioner should FIRST:

Answer: D

Risk estimation should use available evidence and judgment across multiple impact types, not uniform assumptions or financial-only framing.

Domain 1: AI Governance / Part F - AI Trustworthiness, Ethical, and Societal Implications

Q244 In the context of ethical use boundaries for AI, which of the following represents sound AI risk management?

Answer: C

Ethical boundaries should be defined proactively and formally, not left to feasibility alone or individual discretion.

Domain 3: AI Operations/Resilience / Part C - AI Controls Management

Q245 When multiple control gaps are identified for an AI system, remediation should be prioritized by:

Answer: B

Remediation priority should track risk severity, not cost or arbitrary order alone.

Domain 3: AI Operations/Resilience / Part D - AI Risk Metrics, Monitoring, and Reporting

Q246 In the context of integration of AI risk metrics into enterprise reporting, which of the following represents sound AI risk management?

Answer: A

AI risk metrics should feed into integrated enterprise reporting, not remain isolated, team-limited, or overly compressed.

Domain 3: AI Operations/Resilience / Part E - AI Supply Chain Risk Management

Q247 Regarding concentration risk in AI supply chains, the BEST practice is to:

Answer: D

Concentration risk should be proactively evaluated regardless of vendor reputation or whether functions are customer-facing.

Domain 1: AI Governance / Part B - AI Organizational Processes and Alignment

Q248 When AI initiatives are run as "shadow IT" outside formal governance, the GREATEST risk is:

Answer: B

Shadow AI evades the governance process entirely, removing visibility and control consistency.

Domain 1: AI Governance / Part D - AI Policies, Procedures, and Organizational Training

Q249 Exceptions to an AI policy should be:

Answer: B

Exceptions require a controlled approval process with documented risk acceptance, not informal or unilateral decisions.

Domain 1: AI Governance / Part A - AI Models, Frameworks, Strategies, and Use Cases

Q250 When addressing AI strategy use-case feasibility review, an AI risk practitioner should FIRST:

Answer: C

Feasibility review of data, risk, and resourcing should precede use-case approval regardless of sponsorship or pilot size.

‹ Prev
Next ›
Page 25 of 50 · 500 questions