Free AAIR exam practice questions with answers and explanations, organized by domain and part.
Domain 2: AI Lifecycle / Part B - AI Model Training, Testing, and Validation
Q441 Relying on an outdated benchmark dataset to validate a model's ongoing performance is risky PRIMARILY because:
- A. Outdated benchmarks are more expensive to license, a factor that many practitioners tend to overlook even though it can meaningfully influence the final outcome
- B. The benchmark may no longer reflect current real-world data patterns the model will encounter, which is a minor but relevant consideration in most situations
- C. Older benchmarks are always smaller in size, an aspect that is often underestimated in real-world settings but can have a significant and lasting impact on both the process and its eventual results
- D. Benchmark datasets cannot legally be reused
Answer: B
Stale benchmarks risk misrepresenting current real-world conditions; size, licensing, or cost aren't the core concern.
Domain 3: AI Operations/Resilience / Part D - AI Risk Metrics, Monitoring, and Reporting
Q442 Benchmarking a new AI model against the legacy system it is intended to replace is valuable PRIMARILY because it:
- A. Removes the need for ongoing post-launch monitoring, a factor that many practitioners tend to overlook even though it can meaningfully influence the final outcome
- B. Is only required when the legacy system is more than five years old, which is a minor but relevant consideration in most situations
- C. Provides objective evidence of whether the new model actually performs better before full rollout, an aspect that is often underestimated in real-world settings but can have a significant and lasting impact on both the process and its eventual results
- D. Guarantees the new model will have lower operating costs
Answer: C
Baseline benchmarking gives objective pre-rollout evidence of improvement; it isn't age-gated, doesn't guarantee lower cost, or remove post-launch monitoring.
Domain 3: AI Operations/Resilience / Part E - AI Supply Chain Risk Management
Q443 Use of open-source AI components introduces risk PRIMARILY related to:
- A. Unclear provenance, maintenance, and security vulnerabilities in the component, a factor that many practitioners tend to overlook even though it can meaningfully influence the final outcome
- B. Guaranteed vendor support, which is a minor but relevant consideration in most situations
- C. Automatic compliance with enterprise policy
- D. Elimination of all licensing considerations, an aspect that is often underestimated in real-world settings but can have a significant and lasting impact on both the process and its eventual results
Answer: A
Open-source components can carry provenance, maintenance, and vulnerability risks requiring assessment.
Domain 1: AI Governance / Part E - AI Regulatory Compliance and Legal Considerations
Q444 When contracting with an AI vendor, which clause is MOST important for ongoing risk management?
- A. Audit rights, data handling, and liability allocation provisions, an aspect that is often underestimated in real-world settings but can have a significant and lasting impact on both the process and its eventual results
- B. Service-level commitments specifying uptime and response times, a factor that many practitioners tend to overlook even though it can meaningfully influence the final outcome
- C. Logo usage rights, which is a minor but relevant consideration in most situations
- D. Marketing exclusivity clauses
Answer: A
Audit, data-handling, and liability clauses are the substantive risk-management levers; SLAs matter operationally but are less central to AI-specific risk management than these provisions, and marketing/logo clauses are irrelevant.
Domain 3: AI Operations/Resilience / Part D - AI Risk Metrics, Monitoring, and Reporting
Q445 A well-designed key risk indicator (KRI) for an AI system should be:
- A. Measurable, relevant to a specific risk, and tied to a defined threshold, a factor that many practitioners tend to overlook even though it can meaningfully influence the final outcome
- B. Reported only during audits
- C. Changed frequently with no consistent definition, an aspect that is often underestimated in real-world settings but can have a significant and lasting impact on both the process and its eventual results
- D. Vague and qualitative only, which is a minor but relevant consideration in most situations
Answer: A
Effective KRIs are measurable, risk-relevant, and threshold-based.
Domain 1: AI Governance / Part F - AI Trustworthiness, Ethical, and Societal Implications
Q446 Providing users with a clear opt-out from AI-driven personalization is valuable PRIMARILY because it:
- A. Removes the need to disclose that personalization is being used, an aspect that is often underestimated in real-world settings but can have a significant and lasting impact on both the process and its eventual results
- B. Automatically reduces the enterprise's AI infrastructure costs
- C. Respects user autonomy and supports compliance with applicable privacy expectations, a factor that many practitioners tend to overlook even though it can meaningfully influence the final outcome
- D. Is only relevant for personalization involving biometric data, which is a minor but relevant consideration in most situations
Answer: C
Opt-out mechanisms respect autonomy and support privacy compliance; they aren't biometric-specific, don't inherently reduce infrastructure cost, or remove the need for disclosure.
Domain 1: AI Governance / Part E - AI Regulatory Compliance and Legal Considerations
Q447 When using web-scraped data to train an AI model, the enterprise should PRIMARILY assess:
- A. Whether competitors have scraped similar data, an aspect that is often underestimated in real-world settings but can have a significant and lasting impact on both the process and its eventual results
- B. Whether the data was easy to collect, which is a minor but relevant consideration in most situations
- C. Copyright, licensing, and intellectual property risk associated with that data's use, a factor that many practitioners tend to overlook even though it can meaningfully influence the final outcome
- D. Only the storage cost of the scraped data
Answer: C
Scraped training data carries copyright/IP risk that must be assessed; ease of collection, storage cost, or peer practice don't address that.
Domain 3: AI Operations/Resilience / Part D - AI Risk Metrics, Monitoring, and Reporting
Q448 A leading indicator for AI model risk (e.g., rising input data anomalies) is valuable PRIMARILY because it:
- A. Is only useful for historical reporting, a factor that many practitioners tend to overlook even though it can meaningfully influence the final outcome
- B. Replaces the need for lagging indicators, an aspect that is often underestimated in real-world settings but can have a significant and lasting impact on both the process and its eventual results
- C. Confirms an incident has already occurred
- D. Provides early warning before a risk materializes into an incident, which is a minor but relevant consideration in most situations
Answer: D
Leading indicators provide early warning signals before issues fully materialize.
Domain 1: AI Governance / Part C - AI Ownership, Oversight, and Accountability
Q449 Within an enterprise's AI governance structure, the governance committee is PRIMARILY responsible for:
- A. Approving individual end-user access requests to AI tools, a factor that many practitioners tend to overlook even though it can meaningfully influence the final outcome
- B. Writing the organization's AI model source code
- C. Negotiating AI vendor contract pricing, which is a minor but relevant consideration in most situations
- D. Overseeing the AI governance program and policies and reporting on program metrics, an aspect that is often underestimated in real-world settings but can have a significant and lasting impact on both the process and its eventual results
Answer: D
The governance committee's core role is oversight of the AI governance program and policies, including reporting on related metrics, not day-to-day technical or contractual tasks.
Domain 3: AI Operations/Resilience / Part D - AI Risk Metrics, Monitoring, and Reporting
Q450 How should AI risk metrics relate to the enterprise's existing risk reporting?
- A. Combine AI risk metrics into one unexplained composite score for executives, a factor that many practitioners tend to overlook even though it can meaningfully influence the final outcome
- B. Integrate AI risk metrics into existing enterprise risk reporting rather than maintaining a fully separate report, which is a minor but relevant consideration in most situations
- C. Maintain AI risk metrics completely isolated from enterprise risk reporting, an aspect that is often underestimated in real-world settings but can have a significant and lasting impact on both the process and its eventual results
- D. Report AI risk metrics only within the AI development team
Answer: B
AI risk metrics should feed into integrated enterprise reporting, not remain isolated, team-limited, or overly compressed.