Free AAIR exam practice questions with answers and explanations, organized by domain and part.
Domain 3: AI Operations/Resilience / Part E - AI Supply Chain Risk Management
Q311 When a critical AI vendor experiences a security breach, the enterprise's FIRST priority should be:
- A. Terminating the contract immediately without assessment
- B. Assessing the breach's impact on the enterprise's own data/systems and activating incident response as needed
- C. Issuing a public statement before internal assessment
- D. Waiting for the vendor's public disclosure before taking any action
Answer: B
Immediate priority is assessing actual impact and responding, not premature termination or public statements.
Domain 3: AI Operations/Resilience / Part A - AI Risk Scenario Identification and Assessment
Q312 Developing AI risk scenarios (e.g., biased lending decisions) is MOST useful for:
- A. Making the risk register appear larger
- B. Translating abstract AI risk into concrete, assessable situations for the enterprise
- C. Replacing the need for controls
- D. Satisfying only external auditors
Answer: B
Concrete scenarios make abstract AI risk assessable and actionable.
Domain 1: AI Governance / Part C - AI Ownership, Oversight, and Accountability
Q313 Information security and privacy's responsibility within AI oversight is BEST described as:
- A. Providing independent assurance as part of the annual audit plan
- B. Managing end-user job classification
- C. Addressing data and information systems security- and privacy-related concerns throughout the AI solution's life cycle
- D. Approving the enterprise's overall business strategy
Answer: C
Information security and privacy focuses on security and privacy concerns across the AI life cycle; audit assurance and HR job classification are separate, distinct functions.
Domain 1: AI Governance / Part A - AI Models, Frameworks, Strategies, and Use Cases
Q314 An AI use case inventory lacking a "data sensitivity" field would MOST hinder:
- A. Marketing analytics only
- B. Prioritizing risk assessments where sensitive data exposure is highest
- C. Vendor contract renewal dates
- D. Office hardware procurement
Answer: B
Data sensitivity drives risk-based prioritization of which use cases need assessment first.
Domain 3: AI Operations/Resilience / Part A - AI Risk Scenario Identification and Assessment
Q315 In the context of risk assessment stakeholder involvement, which of the following represents sound AI risk management?
- A. Outsource all risk assessment judgment entirely to external consultants
- B. Involve business, technical, and risk stakeholders jointly in AI risk assessment
- C. Conduct AI risk assessment using only the technical team's input
- D. Conduct AI risk assessment using only business stakeholder input
Answer: B
Joint stakeholder involvement produces more complete risk assessment than single-function or fully outsourced judgment.
Domain 3: AI Operations/Resilience / Part B - AI Risk Treatment Strategies
Q316 Choosing to deploy additional human review ("human-in-the-loop") for high-stakes AI decisions is an example of:
- A. Risk avoidance
- B. Risk mitigation through an added control layer
- C. Risk transfer
- D. Risk acceptance
Answer: B
Adding human review reduces risk through an additional control, i.e., mitigation.
Domain 1: AI Governance / Part E - AI Regulatory Compliance and Legal Considerations
Q317 Before transferring AI training data across borders, the enterprise should FIRST:
- A. Assess applicable data protection and cross-border transfer requirements
- B. Notify the media
- C. Delete all personal data regardless of necessity
- D. Proceed, since AI data is exempt from privacy law
Answer: A
Cross-border transfers require assessing applicable legal requirements before proceeding.
Domain 1: AI Governance / Part B - AI Organizational Processes and Alignment
Q318 Embedding AI risk checkpoints into the existing project/SDLC gates is valuable PRIMARILY because it:
- A. Adds unnecessary delay with no benefit
- B. Catches AI-specific risks early, when they are cheaper and easier to remediate
- C. Replaces the need for a risk committee
- D. Is only relevant for externally purchased AI
Answer: B
Early-gate checks catch risk cheaply, consistent with shift-left risk management principles.
Domain 1: AI Governance / Part A - AI Models, Frameworks, Strategies, and Use Cases
Q319 An AI strategy that is not linked to measurable business objectives is PRIMARILY at risk of:
- A. Being perfectly executed regardless
- B. Producing unmeasurable value and diffuse accountability
- C. Automatically aligning with risk appetite
- D. Reducing audit scope
Answer: B
Without measurable objectives, value and accountability become impossible to track.
Domain 2: AI Lifecycle / Part B - AI Model Training, Testing, and Validation
Q320 Detecting model drift during the testing/monitoring phase is MOST important because:
- A. Drift always improves model performance
- B. Model performance can degrade as real-world data diverges from training data
- C. Drift only matters for regulated industries
- D. It eliminates the need for retraining
Answer: B
Drift reflects divergence between training and live data, which can degrade performance if unaddressed.