AAIR Exam Prep

Free AAIR exam practice questions with answers and explanations, organized by domain and part.

Domain 3: AI Operations/Resilience / Part F - AI Incident Response, BIA, Business Continuity, and Disaster Recovery

Q341 A disaster recovery (DR) plan for an AI system should address recovery of:

Answer: B

Full AI DR scope includes models, data, infrastructure, and integrations, not just the UI.

Domain 2: AI Lifecycle / Part C - AI Implementation, Maintenance, and Decommissioning

Q342 Defining clear retirement criteria for an AI model (e.g., sustained accuracy decline, superseded capability) BEFORE deployment is valuable PRIMARILY because it:

Answer: D

Predefined, objective retirement criteria support a consistent decommissioning decision, rather than deciding reactively and inconsistently once problems have already emerged.

Domain 1: AI Governance / Part D - AI Policies, Procedures, and Organizational Training

Q343 Regarding new-hire AI onboarding training, the BEST practice is to:

Answer: D

AI risk awareness should be built into onboarding for all relevant staff, not delayed or limited to technical roles.

Domain 2: AI Lifecycle / Part D - AI Data and Asset Management

Q344 Data quality controls for AI inputs should PRIMARILY address:

Answer: A

Data quality controls target substantive attributes (accuracy, completeness, representativeness) that affect model outcomes.

Domain 3: AI Operations/Resilience / Part A - AI Risk Scenario Identification and Assessment

Q345 Risk assessment of autonomous AI decision-making should give particular attention to:

Answer: B

Full autonomy (no human review) raises the risk profile and warrants specific scrutiny.

Domain 2: AI Lifecycle / Part C - AI Implementation, Maintenance, and Decommissioning

Q346 Shadow deployment, where a new AI model runs alongside the production model without influencing live decisions, is MOST valuable because it:

Answer: A

Shadow deployment lets teams observe real-world behavior and compare outputs safely, but it does not eliminate the need for further validation, guarantee performance, or remove rollback planning.

Domain 3: AI Operations/Resilience / Part F - AI Incident Response, BIA, Business Continuity, and Disaster Recovery

Q347 Communicating AI incident impact to regulators, where legally required, should be:

Answer: B

Regulatory notification must meet timeliness/accuracy obligations, not be delayed or selectively framed.

Domain 1: AI Governance / Part E - AI Regulatory Compliance and Legal Considerations

Q348 For a high-risk AI system subject to regulatory reporting, the enterprise's MOST important obligation is to:

Answer: B

Regulatory reporting obligations require proactive, accurate record-keeping, not reactive or delegated compliance.

Domain 1: AI Governance / Part D - AI Policies, Procedures, and Organizational Training

Q349 Regarding AI acceptable use policy scope, the BEST practice is to:

Answer: A

An AI acceptable use policy should be explicit and enterprise-wide, not informal or narrowly scoped.

Domain 2: AI Lifecycle / Part D - AI Data and Asset Management

Q350 When addressing asset inventory for AI systems, an AI risk practitioner should FIRST:

Answer: C

A centralized, current AI asset inventory supports risk oversight across the enterprise, not informal or partial tracking.

‹ Prev
Next ›
Page 35 of 50 · 500 questions