AAIR Exam Prep

Free AAIR exam practice questions with answers and explanations, organized by domain and part.

Domain 3: AI Operations/Resilience / Part F - AI Incident Response, BIA, Business Continuity, and Disaster Recovery

Q371 Testing an AI-specific DR plan is important PRIMARILY because it:

Answer: A

Testing validates that the DR plan is actually workable, not just theoretically documented.

Domain 3: AI Operations/Resilience / Part C - AI Controls Management

Q372 Detective controls, such as automated model output monitoring, are valuable PRIMARILY because they:

Answer: B

Detective controls identify issues post-occurrence, enabling timely response.

Domain 1: AI Governance / Part B - AI Organizational Processes and Alignment

Q373 Misalignment between an AI initiative's timeline and the enterprise risk assessment cycle MOST often results in:

Answer: B

Timeline misalignment can let deployment outpace risk assessment, a control gap.

Domain 3: AI Operations/Resilience / Part F - AI Incident Response, BIA, Business Continuity, and Disaster Recovery

Q374 Classifying the severity of an AI incident should PRIMARILY consider:

Answer: B

Severity classification should be based on actual scope/impact/sensitivity, not optics alone.

Domain 1: AI Governance / Part F - AI Trustworthiness, Ethical, and Societal Implications

Q375 When an AI system's output could plausibly cause reputational or societal harm even if technically accurate, the organization's ethical governance process should PRIMARILY:

Answer: C

Ethical governance requires evaluating broader societal and reputational consequences in addition to technical accuracy, rather than treating accuracy as sufficient on its own.

Domain 3: AI Operations/Resilience / Part F - AI Incident Response, BIA, Business Continuity, and Disaster Recovery

Q376 A business impact analysis (BIA) for a process dependent on AI should assess:

Answer: B

BIA focuses on process criticality and disruption impact, not technical model attributes.

Domain 1: AI Governance / Part D - AI Policies, Procedures, and Organizational Training

Q377 An AI acceptable use policy should PRIMARILY define:

Answer: B

Acceptable use policy scope is about permitted/prohibited use, not technical implementation details.

Domain 3: AI Operations/Resilience / Part B - AI Risk Treatment Strategies

Q378 Risk treatment priorities for AI risk scenarios should be driven MOST by:

Answer: B

Prioritization should reflect risk appetite and the actual severity/likelihood of scenarios.

Domain 2: AI Lifecycle / Part B - AI Model Training, Testing, and Validation

Q379 Before deploying an AI model, what type of testing should be performed in addition to standard accuracy evaluation?

Answer: D

Adversarial robustness testing is a distinct check beyond standard accuracy evaluation and should be done proactively.

Domain 2: AI Lifecycle / Part A - AI Design, Development/Procurement, and Documentation

Q380 Risk assessment at the AI design stage is valuable MAINLY because it:

Answer: B

Early-stage risk assessment is the most cost-effective point to address design flaws.

‹ Prev
Next ›
Page 38 of 50 · 500 questions