Free AAIR exam practice questions with answers and explanations, organized by domain and part.
Domain 3: AI Operations/Resilience / Part F - AI Incident Response, BIA, Business Continuity, and Disaster Recovery
Q351 A tabletop exercise simulating an AI incident is valuable PRIMARILY because it:
- A. Guarantees the real incident will never happen
- B. Tests and improves the organization's actual readiness and coordination before a real event
- C. Replaces the need for a written incident response plan
- D. Is only useful for compliance checkbox purposes
Answer: B
Tabletop exercises validate and improve real readiness/coordination ahead of an actual incident.
Domain 3: AI Operations/Resilience / Part F - AI Incident Response, BIA, Business Continuity, and Disaster Recovery
Q352 A post-incident root cause analysis for an AI failure is valuable PRIMARILY because it:
- A. Assigns blame to a specific individual
- B. Identifies underlying causes so controls can be strengthened to prevent recurrence
- C. Satisfies only a reporting formality
- D. Replaces the need for an incident report
Answer: B
Root cause analysis drives control improvement, not blame assignment.
Domain 1: AI Governance / Part E - AI Regulatory Compliance and Legal Considerations
Q353 When addressing regulatory horizon scanning for AI, an AI risk practitioner should FIRST:
- A. Rely on vendors to notify the enterprise of regulatory changes
- B. Monitor regulation only in the enterprise's headquarters jurisdiction
- C. Maintain an ongoing process to monitor emerging AI regulation relevant to the enterprise
- D. Review AI regulatory developments only once a year
Answer: C
Ongoing horizon scanning across relevant jurisdictions is needed, not infrequent, vendor-dependent, or single-jurisdiction monitoring.
Domain 2: AI Lifecycle / Part B - AI Model Training, Testing, and Validation
Q354 Regarding model performance benchmarking, the BEST practice is to:
- A. Release models based on developer confidence alone
- B. Skip benchmarking for minor model updates
- C. Benchmark AI model performance against defined acceptance criteria before production release
- D. Release models once they outperform a prior inferior baseline only slightly
Answer: C
Formal benchmarking against acceptance criteria should precede release, not rely on marginal improvement or developer confidence alone.
Domain 1: AI Governance / Part F - AI Trustworthiness, Ethical, and Societal Implications
Q355 An AI ethics review board adds value PRIMARILY by:
- A. Approving all AI projects automatically
- B. Independently evaluating ethical implications before high-risk AI deployment
- C. Replacing technical testing entirely
- D. Reporting only to the vendor
Answer: B
Independent ethical evaluation before deployment is the board's core value-add.
Domain 3: AI Operations/Resilience / Part D - AI Risk Metrics, Monitoring, and Reporting
Q356 When addressing integration of AI risk metrics into enterprise reporting, an AI risk practitioner should FIRST:
- A. Combine AI risk metrics into one unexplained composite score for executives
- B. Integrate AI risk metrics into existing enterprise risk reporting rather than maintaining a fully separate report
- C. Maintain AI risk metrics completely isolated from enterprise risk reporting
- D. Report AI risk metrics only within the AI development team
Answer: B
AI risk metrics should feed into integrated enterprise reporting, not remain isolated, team-limited, or overly compressed.
Domain 1: AI Governance / Part E - AI Regulatory Compliance and Legal Considerations
Q357 Intellectual property risk in generative AI output is MOST associated with:
- A. Hardware failure
- B. Potential infringement from training data or output resembling copyrighted material
- C. Network latency
- D. Office lease terms
Answer: B
IP risk arises from training data provenance and output similarity to protected works.
Domain 3: AI Operations/Resilience / Part D - AI Risk Metrics, Monitoring, and Reporting
Q358 Regarding AI risk reporting to stakeholders, the BEST practice is to:
- A. Report AI risk only when specifically requested
- B. Limit AI risk reporting to technical teams only
- C. Tailor AI risk reporting content and frequency to the needs of each stakeholder audience (board, management, operational teams)
- D. Provide identical AI risk reports to all stakeholder groups
Answer: C
Reporting should be tailored to audience needs, not uniform, on-demand only, or restricted to technical teams.
Domain 1: AI Governance / Part C - AI Ownership, Oversight, and Accountability
Q359 Responsibility for assessing AI-related risk as part of the organization's audit plan BEST belongs to:
- A. The AI vendor's customer support function
- B. End users of the AI solution
- C. Internal audit
- D. The AI development team
Answer: C
Internal audit is responsible for incorporating AI-related risk into its audit plan, providing independent assurance over AI governance and controls.
Domain 1: AI Governance / Part D - AI Policies, Procedures, and Organizational Training
Q360 An AI acceptable-use policy that lists prohibited use cases is valuable PRIMARILY because it:
- A. Replaces the need for technical controls entirely
- B. Gives employees clear boundaries, reducing inadvertent misuse
- C. Is a one-time document requiring no updates
- D. Only applies to external vendors
Answer: B
Clear boundaries reduce inadvertent misuse; policy complements, not replaces, technical controls.