AAIR Exam Prep

Free AAIR exam practice questions with answers and explanations, organized by domain and part.

Domain 3: AI Operations/Resilience / Part A - AI Risk Scenario Identification and Assessment

Q71 An enterprise evaluating prioritizing AI risk scenarios for treatment should PRIMARILY ensure that:

Answer: D

Prioritization should reflect likelihood, impact, and risk appetite, not equal treatment, ease alone, or past incidents only.

Domain 2: AI Lifecycle / Part D - AI Data and Asset Management

Q72 An enterprise evaluating AI training data access controls should PRIMARILY ensure that:

Answer: A

Access controls should follow data sensitivity classification across both training and production data, not informal trust.

Domain 1: AI Governance / Part D - AI Policies, Procedures, and Organizational Training

Q73 Regarding employee AI training program design, the BEST practice is to:

Answer: C

Role-tailored AI training addresses differing risk exposure better than one-size-fits-all or team-limited training.

Domain 3: AI Operations/Resilience / Part C - AI Controls Management

Q74 Segregation of duties in AI model deployment (e.g., developer cannot self-approve production release) is intended to:

Answer: B

Segregation of duties prevents unilateral, unreviewed changes from reaching production.

Domain 2: AI Lifecycle / Part D - AI Data and Asset Management

Q75 In the context of AI training data access controls, which of the following represents sound AI risk management?

Answer: A

Access controls should follow data sensitivity classification across both training and production data, not informal trust.

Domain 3: AI Operations/Resilience / Part C - AI Controls Management

Q76 An enterprise evaluating control framework mapping for AI should PRIMARILY ensure that:

Answer: D

Mapping to a recognized framework, kept current, supports completeness; ad hoc or one-time-only mapping risks gaps.

Domain 2: AI Lifecycle / Part A - AI Design, Development/Procurement, and Documentation

Q77 In the context of explainability requirements at design stage, which of the following represents sound AI risk management?

Answer: A

Explainability requirements should be risk-based and considered during design, not uniform or deferred.

Domain 2: AI Lifecycle / Part C - AI Implementation, Maintenance, and Decommissioning

Q78 Configuration drift in a production AI system (undocumented changes diverging from approved baseline) is a risk PRIMARILY because it:

Answer: B

Unreviewed configuration drift can silently alter behavior/controls outside the approved baseline.

Domain 2: AI Lifecycle / Part C - AI Implementation, Maintenance, and Decommissioning

Q79 With respect to phased AI rollout approach, which approach is MOST appropriate for an enterprise managing AI risk?

Answer: D

Phased rollout against the intended population allows real-world risk monitoring before full-scale deployment.

Domain 1: AI Governance / Part D - AI Policies, Procedures, and Organizational Training

Q80 With respect to procedure documentation for AI model changes, which approach is MOST appropriate for an enterprise managing AI risk?

Answer: B

Documented change procedures should apply consistently, including to seemingly minor AI model updates.

‹ Prev
Next ›
Page 8 of 50 · 500 questions