Free AAIR exam practice questions with answers and explanations, organized by domain and part.
Domain 3: AI Operations/Resilience / Part F - AI Incident Response, BIA, Business Continuity, and Disaster Recovery
Q341 A disaster recovery (DR) plan for an AI system should address recovery of:
- A. Only the user interface
- B. Models, training/reference data, infrastructure, and dependent integrations
- C. Only the vendor's billing system
- D. Only marketing collateral
Answer: B
Full AI DR scope includes models, data, infrastructure, and integrations, not just the UI.
Domain 2: AI Lifecycle / Part C - AI Implementation, Maintenance, and Decommissioning
Q342 Defining clear retirement criteria for an AI model (e.g., sustained accuracy decline, superseded capability) BEFORE deployment is valuable PRIMARILY because it:
- A. Is only relevant for models used in regulated industries
- B. Guarantees the model will never need to be retired
- C. Removes the need for a decommissioning plan at retirement time
- D. Provides an objective basis for the decommissioning decision rather than relying on ad hoc judgment after the fact
Answer: D
Predefined, objective retirement criteria support a consistent decommissioning decision, rather than deciding reactively and inconsistently once problems have already emerged.
Domain 1: AI Governance / Part D - AI Policies, Procedures, and Organizational Training
Q343 Regarding new-hire AI onboarding training, the BEST practice is to:
- A. Introduce AI training only after a new hire's first year
- B. Make AI training optional for new hires
- C. Limit onboarding AI training to technical staff only
- D. Include AI risk and acceptable use training in new-hire onboarding
Answer: D
AI risk awareness should be built into onboarding for all relevant staff, not delayed or limited to technical roles.
Domain 2: AI Lifecycle / Part D - AI Data and Asset Management
Q344 Data quality controls for AI inputs should PRIMARILY address:
- A. Accuracy, completeness, and representativeness of the data used
- B. The visual formatting of data files
- C. The speed of data ingestion only
- D. The color-coding of data dashboards
Answer: A
Data quality controls target substantive attributes (accuracy, completeness, representativeness) that affect model outcomes.
Domain 3: AI Operations/Resilience / Part A - AI Risk Scenario Identification and Assessment
Q345 Risk assessment of autonomous AI decision-making should give particular attention to:
- A. The AI's visual interface design
- B. Scenarios where no human reviews the decision before it takes effect
- C. Only the system's processing speed
- D. The vendor's marketing claims
Answer: B
Full autonomy (no human review) raises the risk profile and warrants specific scrutiny.
Domain 2: AI Lifecycle / Part C - AI Implementation, Maintenance, and Decommissioning
Q346 Shadow deployment, where a new AI model runs alongside the production model without influencing live decisions, is MOST valuable because it:
- A. Allows direct comparison of the new model's outputs against the incumbent model under real production conditions without user-facing risk
- B. Eliminates the need for any further testing before full cutover
- C. Removes the need for a rollback plan
- D. Guarantees the new model will outperform the existing one
Answer: A
Shadow deployment lets teams observe real-world behavior and compare outputs safely, but it does not eliminate the need for further validation, guarantee performance, or remove rollback planning.
Domain 3: AI Operations/Resilience / Part F - AI Incident Response, BIA, Business Continuity, and Disaster Recovery
Q347 Communicating AI incident impact to regulators, where legally required, should be:
- A. Avoided unless the regulator specifically asks
- B. Timely and accurate, consistent with applicable breach/incident notification obligations
- C. Delayed until all internal investigation is fully complete, regardless of deadlines
- D. Limited to only favorable details
Answer: B
Regulatory notification must meet timeliness/accuracy obligations, not be delayed or selectively framed.
Domain 1: AI Governance / Part E - AI Regulatory Compliance and Legal Considerations
Q348 For a high-risk AI system subject to regulatory reporting, the enterprise's MOST important obligation is to:
- A. Avoid documentation to reduce audit exposure
- B. Maintain accurate records and report as required by the applicable regulatory regime
- C. Report only if a complaint is received
- D. Delegate all reporting to the AI vendor without oversight
Answer: B
Regulatory reporting obligations require proactive, accurate record-keeping, not reactive or delegated compliance.
Domain 1: AI Governance / Part D - AI Policies, Procedures, and Organizational Training
Q349 Regarding AI acceptable use policy scope, the BEST practice is to:
- A. Define an AI acceptable use policy covering permitted tools, data handling, and prohibited uses
- B. Leave AI acceptable use undefined and rely on informal norms
- C. Limit the policy to only prohibit a single named tool
- D. Apply the acceptable use policy only to the IT department
Answer: A
An AI acceptable use policy should be explicit and enterprise-wide, not informal or narrowly scoped.
Domain 2: AI Lifecycle / Part D - AI Data and Asset Management
Q350 When addressing asset inventory for AI systems, an AI risk practitioner should FIRST:
- A. Maintain inventory only for externally facing AI systems
- B. Update the AI asset inventory only during annual audits
- C. Maintain an inventory of AI models and their associated data assets across the enterprise
- D. Track AI assets informally through individual team spreadsheets
Answer: C
A centralized, current AI asset inventory supports risk oversight across the enterprise, not informal or partial tracking.