AAIR Exam Prep

Free AAIR exam practice questions with answers and explanations, organized by domain and part.

Domain 3: AI Operations/Resilience / Part E - AI Supply Chain Risk Management

Q291 Vendor lock-in risk in AI supply chain management is BEST mitigated by:

Answer: A

Portability, documented interfaces, and contractual exit provisions preserve an enterprise's ability to switch providers, directly mitigating lock-in risk; single-vendor reliance increases it.

Domain 2: AI Lifecycle / Part B - AI Model Training, Testing, and Validation

Q292 When addressing documentation of validation results, an AI risk practitioner should FIRST:

Answer: B

Validation documentation, including limitations and failure modes, should be complete and recorded before go-live.

Domain 2: AI Lifecycle / Part B - AI Model Training, Testing, and Validation

Q293 Regarding holdout and cross-validation practices, the BEST practice is to:

Answer: B

Robust generalization assessment via holdout/cross-validation is needed, not training-only or convenience-sample evaluation.

Domain 1: AI Governance / Part A - AI Models, Frameworks, Strategies, and Use Cases

Q294 Regarding AI use-case prioritization, the BEST practice is to:

Answer: D

Use-case prioritization should balance value against risk exposure, not speed, order of request, or cost alone.

Domain 3: AI Operations/Resilience / Part C - AI Controls Management

Q295 A human-in-the-loop control is MOST effective when:

Answer: B

Meaningful human-in-the-loop controls require real authority and sufficient information/time to act.

Domain 3: AI Operations/Resilience / Part D - AI Risk Metrics, Monitoring, and Reporting

Q296 When addressing key risk indicator thresholds for AI, an AI risk practitioner should FIRST:

Answer: D

KRIs need defined, risk-appropriate thresholds with timely escalation, not undefined, uniform, or delayed review.

Domain 1: AI Governance / Part F - AI Trustworthiness, Ethical, and Societal Implications

Q297 Establishing clear ethical use boundaries for AI within an enterprise is BEST supported by:

Answer: C

Documented, stakeholder-reviewed policies establish consistent ethical boundaries proactively, rather than relying on ad hoc individual judgment, vendor terms alone, or reactive incident response.

Domain 3: AI Operations/Resilience / Part C - AI Controls Management

Q298 Regarding control testing frequency for AI systems, the BEST practice is to:

Answer: C

Control testing frequency should be risk-proportionate, not uniform, audit-triggered only, or one-time.

Domain 1: AI Governance / Part F - AI Trustworthiness, Ethical, and Societal Implications

Q299 Transparency to end users about AI involvement in a decision is important PRIMARILY to:

Answer: B

Transparency underpins informed trust and the ability to contest/appeal decisions.

Domain 2: AI Lifecycle / Part D - AI Data and Asset Management

Q300 When addressing data retention policy for AI systems, an AI risk practitioner should FIRST:

Answer: D

Formal retention/disposal schedules should govern AI data by policy, not default indefinite retention or informal decisions.

‹ Prev
Next ›
Page 30 of 50 · 500 questions