AAIR Exam Prep

Free AAIR exam practice questions with answers and explanations, organized by domain and part.

Domain 3: AI Operations/Resilience / Part E - AI Supply Chain Risk Management

Q311 When a critical AI vendor experiences a security breach, the enterprise's FIRST priority should be:

Answer: B

Immediate priority is assessing actual impact and responding, not premature termination or public statements.

Domain 3: AI Operations/Resilience / Part A - AI Risk Scenario Identification and Assessment

Q312 Developing AI risk scenarios (e.g., biased lending decisions) is MOST useful for:

Answer: B

Concrete scenarios make abstract AI risk assessable and actionable.

Domain 1: AI Governance / Part C - AI Ownership, Oversight, and Accountability

Q313 Information security and privacy's responsibility within AI oversight is BEST described as:

Answer: C

Information security and privacy focuses on security and privacy concerns across the AI life cycle; audit assurance and HR job classification are separate, distinct functions.

Domain 1: AI Governance / Part A - AI Models, Frameworks, Strategies, and Use Cases

Q314 An AI use case inventory lacking a "data sensitivity" field would MOST hinder:

Answer: B

Data sensitivity drives risk-based prioritization of which use cases need assessment first.

Domain 3: AI Operations/Resilience / Part A - AI Risk Scenario Identification and Assessment

Q315 In the context of risk assessment stakeholder involvement, which of the following represents sound AI risk management?

Answer: B

Joint stakeholder involvement produces more complete risk assessment than single-function or fully outsourced judgment.

Domain 3: AI Operations/Resilience / Part B - AI Risk Treatment Strategies

Q316 Choosing to deploy additional human review ("human-in-the-loop") for high-stakes AI decisions is an example of:

Answer: B

Adding human review reduces risk through an additional control, i.e., mitigation.

Domain 1: AI Governance / Part E - AI Regulatory Compliance and Legal Considerations

Q317 Before transferring AI training data across borders, the enterprise should FIRST:

Answer: A

Cross-border transfers require assessing applicable legal requirements before proceeding.

Domain 1: AI Governance / Part B - AI Organizational Processes and Alignment

Q318 Embedding AI risk checkpoints into the existing project/SDLC gates is valuable PRIMARILY because it:

Answer: B

Early-gate checks catch risk cheaply, consistent with shift-left risk management principles.

Domain 1: AI Governance / Part A - AI Models, Frameworks, Strategies, and Use Cases

Q319 An AI strategy that is not linked to measurable business objectives is PRIMARILY at risk of:

Answer: B

Without measurable objectives, value and accountability become impossible to track.

Domain 2: AI Lifecycle / Part B - AI Model Training, Testing, and Validation

Q320 Detecting model drift during the testing/monitoring phase is MOST important because:

Answer: B

Drift reflects divergence between training and live data, which can degrade performance if unaddressed.

‹ Prev
Next ›
Page 32 of 50 · 500 questions