Free AAIR exam practice questions with answers and explanations, organized by domain and part.
Domain 3: AI Operations/Resilience / Part F - AI Incident Response, BIA, Business Continuity, and Disaster Recovery
Q381 A disaster recovery (DR) plan for an AI model failure should PRIMARILY ensure:
- A. The model is never allowed to fail
- B. The enterprise can restore service (including fallback to manual/alternative processes) within acceptable timeframes
- C. The vendor assumes all recovery responsibility by default
- D. Recovery is attempted only after regulatory notification
Answer: B
DR planning focuses on restoring service within acceptable timeframes, including fallback options.
Domain 3: AI Operations/Resilience / Part C - AI Controls Management
Q382 Validating AI-generated outputs against defined business rules before use is an example of:
- A. A control with no practical value
- B. A detective/preventive control catching erroneous outputs before they cause harm
- C. A risk acceptance mechanism
- D. A data retention control
Answer: B
Output validation detects (and can prevent) erroneous output before downstream use.
Domain 3: AI Operations/Resilience / Part A - AI Risk Scenario Identification and Assessment
Q383 A risk scenario describing a generative AI model producing false but plausible outputs is BEST categorized as:
- A. A hallucination risk requiring output validation controls
- B. A cybersecurity vulnerability only
- C. A pure data storage issue
- D. An issue with no relevant control response
Answer: A
This is the defining characteristic of hallucination risk in generative AI, addressed via validation controls.
Domain 1: AI Governance / Part D - AI Policies, Procedures, and Organizational Training
Q384 How should AI training content be tailored across an enterprise's employees?
- A. Provide AI training only to the data science team
- B. Rely on self-directed learning with no formal program
- C. Tailor AI training content to role-specific risk exposure (e.g., developers vs. general staff)
- D. Provide identical generic AI training to every employee regardless of role
Answer: C
Role-tailored AI training addresses differing risk exposure better than one-size-fits-all or team-limited training.
Domain 1: AI Governance / Part B - AI Organizational Processes and Alignment
Q385 Regarding organizational alignment of AI initiatives, the BEST practice is to:
- A. Ensure AI initiatives are aligned to defined business objectives and governance structures
- B. Allow business units to pursue AI initiatives independently of governance
- C. Align AI initiatives only to IT's technical roadmap
- D. Align AI initiatives only after audit findings require it
Answer: A
AI initiatives should align to business objectives within governance structures, not run independently of oversight.
Domain 1: AI Governance / Part E - AI Regulatory Compliance and Legal Considerations
Q386 What must be established before personal data is used in AI processing?
- A. Use the most convenient legal basis regardless of actual applicability
- B. Establish and document a valid legal basis before using personal data in AI processing
- C. Assume consent is implied by data being already collected
- D. Proceed with processing and determine legal basis if challenged
Answer: B
A valid, documented legal basis must be established before processing, not assumed or determined after the fact.
Domain 3: AI Operations/Resilience / Part D - AI Risk Metrics, Monitoring, and Reporting
Q387 If actual AI incident frequency consistently exceeds the modeled/expected rate, the enterprise should PRIMARILY:
- A. Ignore the deviation as statistical noise indefinitely
- B. Reassess the underlying risk assumptions and controls driving the model
- C. Increase the reporting threshold so fewer incidents are counted
- D. Stop reporting the metric
Answer: B
Persistent deviation from expected rates signals a need to reassess assumptions/controls, not suppress reporting.
Domain 3: AI Operations/Resilience / Part B - AI Risk Treatment Strategies
Q388 Risk transfer for AI risk (e.g., insurance, vendor indemnification) is MOST appropriate when:
- A. The risk can be fully eliminated by transfer alone
- B. The enterprise chooses to shift financial impact while still managing operational exposure
- C. No other treatment option exists
- D. The risk is negligible
Answer: B
Transfer shifts financial impact but does not eliminate the need to manage operational risk.
Domain 1: AI Governance / Part D - AI Policies, Procedures, and Organizational Training
Q389 Refresher AI training is important PRIMARILY because:
- A. AI capabilities, risks, and regulations evolve, making static one-time training insufficient
- B. Employees forget everything after a year regardless of content
- C. It is a regulatory checkbox with no substantive value
- D. It replaces the need for policy updates
Answer: A
The fast pace of AI change makes periodic refreshers necessary to keep training current.
Domain 1: AI Governance / Part A - AI Models, Frameworks, Strategies, and Use Cases
Q390 To properly manage AI use-case prioritization, an enterprise should PRIMARILY:
- A. Prioritize use cases strictly by projected return on investment, independent of risk exposure
- B. Prioritize by lowest cost regardless of value
- C. Prioritize use cases by combined business value and risk exposure
- D. Prioritize by whichever team requests first
Answer: C
Prioritization must weigh value against risk exposure together; ROI alone ignores risk, and cost- or request-order-driven prioritization ignores both value and risk.