AAIR Exam Prep

Free AAIR exam practice questions with answers and explanations, organized by domain and part.

Domain 3: AI Operations/Resilience / Part F - AI Incident Response, BIA, Business Continuity, and Disaster Recovery

Q351 A tabletop exercise simulating an AI incident is valuable PRIMARILY because it:

Answer: B

Tabletop exercises validate and improve real readiness/coordination ahead of an actual incident.

Domain 3: AI Operations/Resilience / Part F - AI Incident Response, BIA, Business Continuity, and Disaster Recovery

Q352 A post-incident root cause analysis for an AI failure is valuable PRIMARILY because it:

Answer: B

Root cause analysis drives control improvement, not blame assignment.

Domain 1: AI Governance / Part E - AI Regulatory Compliance and Legal Considerations

Q353 When addressing regulatory horizon scanning for AI, an AI risk practitioner should FIRST:

Answer: C

Ongoing horizon scanning across relevant jurisdictions is needed, not infrequent, vendor-dependent, or single-jurisdiction monitoring.

Domain 2: AI Lifecycle / Part B - AI Model Training, Testing, and Validation

Q354 Regarding model performance benchmarking, the BEST practice is to:

Answer: C

Formal benchmarking against acceptance criteria should precede release, not rely on marginal improvement or developer confidence alone.

Domain 1: AI Governance / Part F - AI Trustworthiness, Ethical, and Societal Implications

Q355 An AI ethics review board adds value PRIMARILY by:

Answer: B

Independent ethical evaluation before deployment is the board's core value-add.

Domain 3: AI Operations/Resilience / Part D - AI Risk Metrics, Monitoring, and Reporting

Q356 When addressing integration of AI risk metrics into enterprise reporting, an AI risk practitioner should FIRST:

Answer: B

AI risk metrics should feed into integrated enterprise reporting, not remain isolated, team-limited, or overly compressed.

Domain 1: AI Governance / Part E - AI Regulatory Compliance and Legal Considerations

Q357 Intellectual property risk in generative AI output is MOST associated with:

Answer: B

IP risk arises from training data provenance and output similarity to protected works.

Domain 3: AI Operations/Resilience / Part D - AI Risk Metrics, Monitoring, and Reporting

Q358 Regarding AI risk reporting to stakeholders, the BEST practice is to:

Answer: C

Reporting should be tailored to audience needs, not uniform, on-demand only, or restricted to technical teams.

Domain 1: AI Governance / Part C - AI Ownership, Oversight, and Accountability

Q359 Responsibility for assessing AI-related risk as part of the organization's audit plan BEST belongs to:

Answer: C

Internal audit is responsible for incorporating AI-related risk into its audit plan, providing independent assurance over AI governance and controls.

Domain 1: AI Governance / Part D - AI Policies, Procedures, and Organizational Training

Q360 An AI acceptable-use policy that lists prohibited use cases is valuable PRIMARILY because it:

Answer: B

Clear boundaries reduce inadvertent misuse; policy complements, not replaces, technical controls.

‹ Prev
Next ›
Page 36 of 50 · 500 questions