Free AAIR exam practice questions with answers and explanations, organized by domain and part.
Domain 3: AI Operations/Resilience / Part F - AI Incident Response, BIA, Business Continuity, and Disaster Recovery
Q371 Testing an AI-specific DR plan is important PRIMARILY because it:
- A. Confirms the plan will work in practice rather than only on paper
- B. Is required only once at initial plan creation
- C. Replaces the need for a BIA
- D. Eliminates all AI-related risk
Answer: A
Testing validates that the DR plan is actually workable, not just theoretically documented.
Domain 3: AI Operations/Resilience / Part C - AI Controls Management
Q372 Detective controls, such as automated model output monitoring, are valuable PRIMARILY because they:
- A. Prevent all errors from ever occurring
- B. Identify issues/anomalies after they occur so they can be addressed promptly
- C. Replace the need for preventive controls entirely
- D. Have no role in AI risk management
Answer: B
Detective controls identify issues post-occurrence, enabling timely response.
Domain 1: AI Governance / Part B - AI Organizational Processes and Alignment
Q373 Misalignment between an AI initiative's timeline and the enterprise risk assessment cycle MOST often results in:
- A. Faster project delivery with no downside
- B. AI systems being deployed before risks are adequately assessed
- C. Improved risk coverage
- D. No practical effect
Answer: B
Timeline misalignment can let deployment outpace risk assessment, a control gap.
Domain 3: AI Operations/Resilience / Part F - AI Incident Response, BIA, Business Continuity, and Disaster Recovery
Q374 Classifying the severity of an AI incident should PRIMARILY consider:
- A. How embarrassing the incident is to the development team
- B. Scope, impact, and sensitivity of affected data/decisions/stakeholders
- C. The time of day the incident occurred
- D. The incident's social media visibility only
Answer: B
Severity classification should be based on actual scope/impact/sensitivity, not optics alone.
Domain 1: AI Governance / Part F - AI Trustworthiness, Ethical, and Societal Implications
Q375 When an AI system's output could plausibly cause reputational or societal harm even if technically accurate, the organization's ethical governance process should PRIMARILY:
- A. Proceed with deployment since technical accuracy is the only relevant standard
- B. Only consider societal impact after the system has already caused harm
- C. Evaluate the broader societal and reputational impact alongside technical accuracy before deployment
- D. Defer the decision entirely to the legal department with no governance input
Answer: C
Ethical governance requires evaluating broader societal and reputational consequences in addition to technical accuracy, rather than treating accuracy as sufficient on its own.
Domain 3: AI Operations/Resilience / Part F - AI Incident Response, BIA, Business Continuity, and Disaster Recovery
Q376 A business impact analysis (BIA) for a process dependent on AI should assess:
- A. Only the AI vendor's revenue
- B. The criticality of the AI-dependent process and the impact of its disruption
- C. Only the AI model's training data size
- D. Only the number of lines of code in the model
Answer: B
BIA focuses on process criticality and disruption impact, not technical model attributes.
Domain 1: AI Governance / Part D - AI Policies, Procedures, and Organizational Training
Q377 An AI acceptable use policy should PRIMARILY define:
- A. The programming languages permitted for development
- B. Permitted and prohibited uses of AI tools and data within the enterprise
- C. The office hours during which AI may be used
- D. The vendor selection criteria only
Answer: B
Acceptable use policy scope is about permitted/prohibited use, not technical implementation details.
Domain 3: AI Operations/Resilience / Part B - AI Risk Treatment Strategies
Q378 Risk treatment priorities for AI risk scenarios should be driven MOST by:
- A. Which risk is easiest to treat, regardless of severity
- B. Alignment with the enterprise's risk appetite and the severity/likelihood of each scenario
- C. Alphabetical order of risk scenario names
- D. Vendor availability only
Answer: B
Prioritization should reflect risk appetite and the actual severity/likelihood of scenarios.
Domain 2: AI Lifecycle / Part B - AI Model Training, Testing, and Validation
Q379 Before deploying an AI model, what type of testing should be performed in addition to standard accuracy evaluation?
- A. Assume robustness because the model performs well on clean test data
- B. Test adversarial robustness only for external-facing models
- C. Defer robustness testing until after a security incident
- D. Test AI models for robustness against adversarial or unexpected inputs prior to deployment
Answer: D
Adversarial robustness testing is a distinct check beyond standard accuracy evaluation and should be done proactively.
Domain 2: AI Lifecycle / Part A - AI Design, Development/Procurement, and Documentation
Q380 Risk assessment at the AI design stage is valuable MAINLY because it:
- A. Delays the project with no benefit
- B. Identifies risks when they are cheapest and easiest to address
- C. Replaces the need for later testing
- D. Is only required for regulated industries
Answer: B
Early-stage risk assessment is the most cost-effective point to address design flaws.