AAIR Exam Prep

Free AAIR exam practice questions with answers and explanations, organized by domain and part.

Domain 3: AI Operations/Resilience / Part F - AI Incident Response, BIA, Business Continuity, and Disaster Recovery

Q461 When addressing disaster recovery testing for AI systems, what is the BEST first step for an AI risk practitioner?

Answer: A

AI systems, including model/data restoration, should be included in regular DR testing, not excluded by default or location assumption. Per the AAIR Review Manual: "Governance and accountability Effective data disposition requires governance structures that oversee the decommissioning process, including policies addressing ancillary data such as model predictions, explanations, intermediate feature representations, and credentials."

Domain 1: AI Governance / Part E - AI Regulatory Compliance and Legal Considerations

Q462 For a high-risk AI system subject to regulatory reporting, the enterprise's MOST important obligation is to:

Answer: C

Regulatory reporting obligations require proactive, accurate record-keeping, not reactive or delegated compliance. Per the AAIR Review Manual: "By proactively managing the retirement of AI solutions, organizations can optimize their technology investments, reduce exposure to obsolete or unsupported systems, and maintain compliance with applicable legal and regulatory obligations."

Domain 2: AI Lifecycle / Part D - AI Data and Asset Management

Q463 Regarding asset inventory for AI systems, the BEST practice is to:

Answer: D

A centralized, current AI asset inventory supports risk oversight across the enterprise, not informal or partial tracking. Per the AAIR Review Manual: "Maintaining a full Al model inventory ensures completeness and accuracy in Al asset management.52 Unlike traditional IT assets, Al solutions are complex systems composed of multiple models, datasets, algorithms, and workflows, often with decentralized ownership and varying development life cycles."

Domain 3: AI Operations/Resilience / Part E - AI Supply Chain Risk Management

Q464 Reliance on a single AI vendor for multiple critical functions MOST increases:

Answer: D

Single-vendor reliance across critical functions creates concentration risk. Per the AAIR Review Manual: "• C oncentr ation risk-Organizations should also assess concentration risk, where heavy reliance on a limited number of AI vendors creates systemic exposure if a provider fails."

Domain 3: AI Operations/Resilience / Part A - AI Risk Scenario Identification and Assessment

Q465 A risk scenario involving third-party AI API outages should be evaluated for impact on:

Answer: A

Third-party dependency risk should be assessed for its effect on business continuity. Per the AAIR Review Manual: "Risk management is responsible for integrating Al solution dependencies, associated threats, and model risk into the enterprise's business impact analysis (BIA) and continuity planning."

Domain 3: AI Operations/Resilience / Part F - AI Incident Response, BIA, Business Continuity, and Disaster Recovery

Q466 Recovery Time Objective (RTO) for a critical AI system should be set based on:

Answer: D

RTO should reflect actual tolerable downtime derived from business impact, not arbitrary choice. Per the AAIR Review Manual: "Part F: Al Incident Response, BIA, Business Continuity, and Disaster Recovery As AI systems become increasingly integrated into critical infrastructures, business operations, and everyday applications, the need for a structured approach to incident response bas become more crucial."

Domain 3: AI Operations/Resilience / Part F - AI Incident Response, BIA, Business Continuity, and Disaster Recovery

Q467 A business impact analysis (BIA) for a process dependent on AI should assess:

Answer: A

BIA focuses on process criticality and disruption impact, not technical model attributes. Per the AAIR Review Manual: "Its goals are to mitigate risk, enhance transparency, and build trust in AI systems. 3.5.4 Privacy Impact Assessment A privacy impact assessment (PIA) is an analysis of how personal information is collected, used, shared, and maintained for a specified scope of consideration."

Domain 2: AI Lifecycle / Part B - AI Model Training, Testing, and Validation

Q468 Implementing a quality assurance process for human-labeled training data is valuable PRIMARILY because it:

Answer: C

QA catches labeling errors before they propagate into the model; it isn't limited to contractor-produced labels, doesn't grow dataset size, or remove the need for reliability measurement. Per the AAIR Review Manual: "An improvement in this score since implementing the AI agents indicates that customers are pleased with the quality of the response they receive from not only human agents but also the AI triage and response process."

Domain 1: AI Governance / Part F - AI Trustworthiness, Ethical, and Societal Implications

Q469 When addressing societal impact assessment for high-risk AI, what is the BEST first step for an AI risk practitioner?

Answer: D

A dedicated societal impact assessment is needed for high-impact systems; a privacy impact assessment covers narrower ground and isn't equivalent, and post-deployment-only or internal-use exemptions both miss pre-deployment review. Per the AAIR Review Manual: "Its goals are to mitigate risk, enhance transparency, and build trust in AI systems. 3.5.4 Privacy Impact Assessment A privacy impact assessment (PIA) is an analysis of how personal information is collected, used, shared, and maintained for a specified scope of consideration."

Domain 1: AI Governance / Part D - AI Policies, Procedures, and Organizational Training

Q470 Which is the BEST indicator that AI policy adoption is effective?

Answer: A

Effectiveness is measured by actual behavior/compliance, not document volume or reissue frequency. Per the AAIR Review Manual: "This enables effective communication about risk to senior leadership and other relevant stakeholders. 153 Compliance-driven enterprises can map FAIR-AIR outputs to jurisdictional regulatory frameworks like the EU AI Act."

‹ Prev
Next ›
Page 47 of 50 · 500 questions