Summer Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: Board70

AAIR Exam Dumps - Isaca AI Risk Questions and Answers

Question # 14

An organization depends on multiple external suppliers for AI models and training datasets. Which of the following is MOST important to have in place in order to reduce supply chain risk?

Options:

A.

Verifiable end-to-end provenance and audit trails for externally sourced artifacts

B.

Standard indemnity clauses in vendor contracts to assign liability responsibilities

C.

Requirement for vendors to provide documentation of model training methods used

D.

Appointment of a vendor risk manager with AI expertise to serve as a single point of contact

Buy Now
Question # 15

Which of the following BEST helps to ensure AI model outputs can be reproduced in other environments?

Options:

A.

Requiring manual review of outputs for stability and accuracy

B.

Capturing and archiving complete snapshots of training datasets

C.

Maintaining continuous post-deployment performance monitoring

D.

Implementing AI-specific change management processes

Buy Now
Question # 16

An organization plans to deploy a generative AI system that processes sensitive personal data across multiple countries with varying privacy laws. Which of the following is the BEST course of action to manage legal and regulatory exposure?

Options:

A.

Remediate regulatory gaps in each jurisdiction through iterative post-deployment updates and model retraining.

B.

Tailor organizational controls to relevant statutory requirements and preserve audit trails to prove adherence.

C.

Adopt uniform global policies and implement strong encryption of personal data for all cross-border transfers.

D.

Prioritize protection of intellectual property and restrict disclosure of model operations to safeguard assets.

Buy Now
Question # 17

Which of the following is the MOST important consideration when determining mitigation controls for an AI system?

Options:

A.

Providing comprehensive AI risk awareness training to security and technical personnel

B.

Determining control performance baselines and reporting requirements for regulatory compliance

C.

Evaluating control effectiveness and costs against potential business losses from unmitigated AI risk

D.

Prioritizing controls based on the complexity and computational requirements of the AI system

Buy Now
Question # 18

Which of the following would be of GREATEST concern to a risk practitioner reviewing the testing and validation of an AI-driven technical support system?

Options:

A.

Inaccurate outputs resulting from model drift

B.

Infrequent incorporation of updated training datasets

C.

Insufficient encryption of data at rest and in transit

D.

Excessive dependence on manual sampling

Buy Now
Question # 19

An organization uses multiple external data sources to train its AI models. Which of the following is the risk practitioner's BEST recommendation to protect the organization from data poisoning attacks?

Options:

A.

Data integrity reviews in response to indications that significant model drift has occurred

B.

Continuous monitoring and anomaly detection for data ingestion pipelines

C.

Stringent controls over model code and deployment artifacts

D.

Enhanced regularization and training techniques to limit the influence of anomalies

Buy Now
Question # 20

An organization integrates multiple AI services using APIs to enhance a customer support chatbot. Which of the following is the GREATEST risk?

Options:

A.

Greater likelihood of bias or inaccuracy in chatbot responses

B.

Unauthorized disclosure of sensitive records via insecure external connections

C.

Customer dissatisfaction from operational delays

D.

Insufficient training datasets due to outdated or limited sample coverage

Buy Now
Question # 21

An organization uses an AI model that learns from live data streams. Which of the following is the BEST course of action to manage the risk of an adaptive model?

Options:

A.

Utilize a defense-in-depth control approach for model access.

B.

Restrict data sources and perform periodic data quality inspections.

C.

Apply dynamic performance thresholds and conduct scheduled recalibrations.

D.

Implement automated monitoring to detect data drift and data poisoning.

Buy Now
Question # 22

Which of the following is the MOST important reason for a risk practitioner to classify AI risk using threat actor profiles?

Options:

A.

To align AI threat and vulnerability risk with the overall IT control taxonomy

B.

To tailor controls to adversary motivations and capabilities

C.

To develop response metrics for AI cybersecurity incidents

D.

To ensure external threats to corporate assets are given highest priority

Buy Now
Question # 23

Which of the following is the BEST governance approach for balancing risk management and operational flexibility across diverse AI applications?

Options:

A.

Control approaches for AI solutions that prioritize compliance on a single regulation

B.

Frameworks that can be adapted to business-relevant AI use cases

C.

External consultants who conduct independent AI governance reviews

D.

Risk ownership processes that focus on ensuring centralized decision-making

Buy Now
Exam Code: AAIR
Exam Name: ISACA Advanced in AI Risk
Last Update: Jun 21, 2026
Questions: 90
AAIR pdf

AAIR PDF

$25.5  $84.99
AAIR Engine

AAIR Testing Engine

$28.5  $94.99
AAIR PDF + Engine

AAIR PDF + Testing Engine

$40.5  $134.99