AAIR Exam Prep

Free AAIR exam practice questions with answers and explanations, organized by domain and part.

Domain 3: AI Operations/Resilience / Part D - AI Risk Metrics, Monitoring, and Reporting

Q31 With respect to trend analysis of AI risk indicators, which approach is MOST appropriate for an enterprise managing AI risk?

Answer: C

Trend analysis over time catches gradual degradation; a fixed, never-updated baseline, a single data point, or incident-triggered-only analysis all miss ongoing drift.

Domain 1: AI Governance / Part A - AI Models, Frameworks, Strategies, and Use Cases

Q32 Choosing between a principles-based framework (e.g., broad AI RMF) and a certifiable management-system standard (e.g., ISO/IEC 42001) should be driven MOST by:

Answer: D

The choice should hinge on the enterprise's own need for flexibility versus certifiable assurance; regulator adoption trends are relevant context but not the primary driver, and cost or recency are secondary.

Domain 3: AI Operations/Resilience / Part C - AI Controls Management

Q33 When addressing control effectiveness evaluation, an AI risk practitioner should FIRST:

Answer: A

Effectiveness requires actual evidence-based testing; absence of reported exceptions, absence of incidents, and mere policy documentation are not equivalent to tested evidence.

Domain 3: AI Operations/Resilience / Part E - AI Supply Chain Risk Management

Q34 When addressing AI vendor exit and transition planning, an AI risk practitioner should FIRST:

Answer: B

Exit/transition planning should be proactive for critical vendors; a reactive contract-extension right, assuming it's unnecessary for cloud services, and waiting for a discontinuation signal are all reactive or incomplete.

Domain 2: AI Lifecycle / Part B - AI Model Training, Testing, and Validation

Q35 Adversarial testing of an AI model is used to evaluate:

Answer: C

Adversarial testing specifically probes robustness against deliberately crafted problematic inputs, which is distinct from standard held-out validation accuracy testing.

Domain 3: AI Operations/Resilience / Part D - AI Risk Metrics, Monitoring, and Reporting

Q36 Aggregating AI risk metrics across business units is valuable PRIMARILY to:

Answer: D

Aggregation's value is enterprise-wide visibility while unit-level detail is retained; using it mainly to rank units on one score, hiding issues in averages, or replacing unit monitoring all misuse or lose that detail.

Domain 3: AI Operations/Resilience / Part A - AI Risk Scenario Identification and Assessment

Q37 An enterprise evaluating likelihood and impact estimation for AI risk should PRIMARILY ensure that:

Answer: A

Estimation should combine available data with expert judgment, especially where data is sparse; excluding judgment, relying on intuition alone, or assuming uniform risk all weaken the estimate.

Domain 1: AI Governance / Part F - AI Trustworthiness, Ethical, and Societal Implications

Q38 When addressing societal impact assessment for high-risk AI, an AI risk practitioner should FIRST:

Answer: B

A dedicated societal impact assessment is needed for high-impact systems; a privacy impact assessment covers narrower ground and isn't equivalent, and post-deployment-only or internal-use exemptions both miss pre-deployment review.

Domain 1: AI Governance / Part A - AI Models, Frameworks, Strategies, and Use Cases

Q39 Regarding AI maturity model selection, the BEST practice is to:

Answer: C

Framework choice should fit the enterprise's own maturity and risk appetite; copying a competitor, following marketing, or choosing complexity for its own sake all ignore organizational fit.

Domain 2: AI Lifecycle / Part D - AI Data and Asset Management

Q40 A data retention and disposal policy for AI training data should balance:

Answer: D

Retention policy should balance legal obligations against privacy/minimization principles; storage-capacity planning is an operational concern, not the governance balance at issue, and cost- or team-preference-only framing ignores both sides.

‹ Prev
Next ›
Page 4 of 50 · 500 questions