AAIR Exam Prep

Free AAIR exam practice questions with answers and explanations, organized by domain and part.

Domain 3: AI Operations/Resilience / Part C - AI Controls Management

Q411 For control framework mapping for AI, sound practice requires that the enterprise PRIMARILY:

Answer: D

Mapping to a recognized framework, kept current, supports completeness; ad hoc or one-time-only mapping risks gaps.

Domain 2: AI Lifecycle / Part C - AI Implementation, Maintenance, and Decommissioning

Q412 Which practice reflects the soundest approach to phased AI rollout approach?

Answer: D

Phased rollout against the intended population allows real-world risk monitoring before full-scale deployment.

Domain 1: AI Governance / Part D - AI Policies, Procedures, and Organizational Training

Q413 What is the most effective way to manage procedure documentation for AI model changes within an AI risk program?

Answer: B

Documented change procedures should apply consistently, including to seemingly minor AI model updates.

Domain 1: AI Governance / Part E - AI Regulatory Compliance and Legal Considerations

Q414 To properly manage sector-specific AI regulatory requirements, an enterprise should PRIMARILY:

Answer: B

Sector-specific requirements layer on top of general AI regulation and must be separately identified and applied.

Domain 3: AI Operations/Resilience / Part A - AI Risk Scenario Identification and Assessment

Q415 What is the BEST way for an enterprise to manage risk assessment stakeholder involvement?

Answer: D

Joint stakeholder involvement produces more complete risk assessment than single-function or fully outsourced judgment.

Domain 3: AI Operations/Resilience / Part B - AI Risk Treatment Strategies

Q416 When addressing treatment plan monitoring and follow-up, what should the enterprise prioritize to manage AI risk effectively?

Answer: C

Treatment plans require tracked completion and verified effectiveness, not approval alone or unclear ownership.

Domain 2: AI Lifecycle / Part D - AI Data and Asset Management

Q417 For AI training data access controls, which practice best reflects sound AI risk management?

Answer: A

Access controls should follow data sensitivity classification across both training and production data, not informal trust.

Domain 3: AI Operations/Resilience / Part A - AI Risk Scenario Identification and Assessment

Q418 How should an enterprise best handle AI-specific risk scenario development as part of its AI risk program?

Answer: A

AI risk scenarios should be tailored beyond generic IT risk and security-only scenarios, developed proactively.

Domain 1: AI Governance / Part D - AI Policies, Procedures, and Organizational Training

Q419 When handling employee AI training program design, the enterprise's main priority should be to:

Answer: A

Role-tailored AI training addresses differing risk exposure better than one-size-fits-all or team-limited training.

Domain 3: AI Operations/Resilience / Part B - AI Risk Treatment Strategies

Q420 Which practice reflects the soundest approach to risk treatment option selection?

Answer: A

Treatment choice should be a cost-benefit decision aligned with risk appetite, not a default to one option.

‹ Prev
Next ›
Page 42 of 50 · 500 questions