AAIR Exam Prep

Free AAIR exam practice questions with answers and explanations, organized by domain and part.

Domain 1: AI Governance / Part F - AI Trustworthiness, Ethical, and Societal Implications

Q281 When selecting fairness metrics for an AI model, the enterprise should FIRST:

Answer: B

Fairness metric selection must be context-appropriate; no single metric fits all use cases.

Domain 3: AI Operations/Resilience / Part B - AI Risk Treatment Strategies

Q282 Transferring AI risk via insurance or contractual indemnification is MOST appropriate when:

Answer: B

Risk transfer shifts financial impact but does not eliminate the need to manage operational risk itself.

Domain 3: AI Operations/Resilience / Part F - AI Incident Response, BIA, Business Continuity, and Disaster Recovery

Q283 A Business Impact Analysis (BIA) for an AI system should PRIMARILY determine:

Answer: B

BIA determines criticality and tolerable downtime/impact, driving continuity planning priorities.

Domain 1: AI Governance / Part E - AI Regulatory Compliance and Legal Considerations

Q284 Liability for harm caused by an AI system is typically determined by:

Answer: A

Liability allocation depends on control, knowledge, and contractual/legal framework, not a fixed default party.

Domain 3: AI Operations/Resilience / Part C - AI Controls Management

Q285 When addressing control framework mapping for AI, an AI risk practitioner should FIRST:

Answer: C

Mapping to a recognized framework, kept current, supports completeness; ad hoc or one-time-only mapping risks gaps.

Domain 1: AI Governance / Part C - AI Ownership, Oversight, and Accountability

Q286 When no single owner can be identified for a deployed AI system, the MOST appropriate action is:

Answer: B

Ownership gaps must be closed promptly; unowned systems are an accountability and control gap.

Domain 1: AI Governance / Part C - AI Ownership, Oversight, and Accountability

Q287 "Second line of defense" oversight of AI risk typically refers to:

Answer: B

Second line provides independent risk oversight/challenge, distinct from first-line operations.

Domain 2: AI Lifecycle / Part A - AI Design, Development/Procurement, and Documentation

Q288 Regarding AI model documentation standards, the BEST practice is to:

Answer: C

Standardized documentation covering purpose, data, assumptions, and limitations supports consistent risk management.

Domain 1: AI Governance / Part D - AI Policies, Procedures, and Organizational Training

Q289 AI policies should be reviewed:

Answer: B

Periodic and trigger-based review keeps policies current with evolving AI risk and regulation.

Domain 3: AI Operations/Resilience / Part E - AI Supply Chain Risk Management

Q290 When addressing AI vendor security assessment, an AI risk practitioner should FIRST:

Answer: A

Vendor security assessment should be substantive and periodically refreshed, not based solely on self-certification or onboarding-only.

‹ Prev
Next ›
Page 29 of 50 · 500 questions