You must be able to read a deployment scenario and select the specific governance actions required: measure and mitigate bias, satisfy privacy and data-protection rules, and provide transparency. The single most important thing is matching each obligation to the correct control rather than a generic best practice.
Start practicing
AI Governance and Ethics — choose a session length
Free · No account required
Domain overview
This domain covers the ethical and legal guardrails for AI systems: bias detection and mitigation, privacy-preserving techniques, transparency duties, and regulatory compliance. Questions are scenario-based, asking you to select multiple correct actions or requirements a company must take when deploying models that make or inform decisions about people.
Exam objectives
Identifying disparate impact and applying bias mitigation across the AI lifecycle
Applying GDPR principles: lawful basis, data minimization, purpose limitation, and data subject rights
Implementing transparency measures such as disclosure, labeling, and model documentation for generative AI
Using privacy-enhancing techniques like differential privacy to prevent inference of individual records
Treating fairness as a one-time check instead of an ongoing process of measurement, mitigation, and monitoring after deployment.
Confusing GDPR obligations with general security controls, missing requirements like lawful basis, purpose limitation, and data subject rights.
Assuming transparency means only publishing a policy, while omitting disclosure to users, content labeling, and documentation of model limitations.
Click any question to see the full explanation and answer options, or start a focused practice session above.
An AI team is developing a model that approves loan applications. The dataset contains historical loan decisions where a protected group was disproportionately denied loans. The team wants to ensure the model does not perpetuate this bias. Which fairness metric should be used during validation to directly measure whether the model's positive prediction rate is equal across groups?
2A company is deploying an AI system that screens job applications. According to the EU AI Act, this system is likely classified as high-risk because it affects employment opportunities. Which requirement must the company implement for high-risk AI systems?
3A data scientist is using SHAP to explain a complex ensemble model's predictions. A business stakeholder asks why a particular prediction was made. The data scientist wants to show the most influential features for that single prediction. Which SHAP visualisation is most appropriate?
4A financial institution needs to deploy a credit scoring model that is interpretable to regulators. The model must provide clear reasons for each decision. Which model type should the institution choose?
5An organisation is developing an AI policy. According to the NIST AI RMF, which function involves establishing policies and procedures to ensure the organisation governs AI responsibly?
6A company uses AI to generate marketing images. They want to ensure that the images are clearly identified as AI-generated to comply with transparency obligations. Which approach is most effective?
7A hospital wants to train a diagnostic model using data from multiple hospitals without sharing raw patient data. Which technique allows model training across decentralised data while preserving privacy?
8Under the GDPR, individuals have the right to not be subject to a decision based solely on automated processing if it produces legal effects. Which of the following is a typical safeguard that organisations must provide to comply with this right?
9A company is evaluating a vendor's AI system for hiring. The vendor claims the system is fair because it achieves demographic parity. However, the company discovers that the system has significantly different false positive rates across groups. Which fairness issue does this indicate?
10An AI system trained on historical medical records shows that certain racial groups have higher predicted risk for a disease. The data reflects real-world differences in diagnosis rates due to unequal access to healthcare. Which type of bias is this?
11A company is implementing an AI ethics board. Which TWO responsibilities should the board typically have?
12A company is deploying an AI system that falls under the EU AI Act's high-risk category. Which THREE requirements must the company fulfill?
13A data scientist is using LIME to explain a black-box model. Which TWO characteristics of LIME are true?
14A healthcare AI system diagnosing diabetic retinopathy from retinal images shows high accuracy overall but significantly lower recall for patients with darker skin tones. Which fairness metric would BEST capture this disparity by comparing true positive rates across groups?
15A data scientist needs to explain a single prediction from a complex ensemble model to a business stakeholder. Which technique generates local, interpretable explanations by perturbing input features and fitting a simple surrogate model?
16A company deploys an AI resume screening tool. It learns from historical hiring data where most successful hires were male, leading the model to favour male candidates. Which type of bias is this primarily?
17Under the EU AI Act, an AI system that uses subliminal techniques to materially distort a person's behaviour, causing psychological or physical harm, would be classified under which risk tier?
18A hospital wants to train a diagnostic model using patient data from multiple hospitals without sharing raw patient records. Which technique enables collaborative model training while keeping data decentralised?
19A company using an AI-based hiring tool receives a candidate request for explanation of an automated rejection. Which GDPR principle is most directly relevant?
20Which NIST AI RMF function involves identifying the context, risks, and potential impacts of an AI system, including mapping the AI lifecycle and stakeholders?
21A company is required to disclose that content has been generated or significantly modified by AI. Which practice directly addresses this transparency obligation?
22An organisation is deploying an AI system for credit scoring, which is considered high-risk under the EU AI Act. Which requirement is NOT typically mandated for high-risk systems?
23Which technique adds controlled noise to query results or training data to prevent an attacker from inferring whether a specific individual's data was included in the dataset?
24A company is forming an AI ethics board to oversee the development of a high-stakes AI system for bail decision recommendations. Which THREE responsibilities should the board primarily undertake?
25A financial institution wants to use AI for loan approvals and must comply with fair lending laws. Which TWO practices should the institution adopt to mitigate bias and ensure compliance?
26A healthcare AI startup is developing a model to predict patient readmission risk. The model will be used to allocate post-discharge resources. Which regulatory framework primarily governs the use of patient data in this scenario?
27A data scientist is training a resume screening model to rank job applicants. The training data includes historical hiring decisions from the past 10 years. The company wants to avoid unfair bias against underrepresented groups. Which type of bias is most likely present in the training data?
28A financial institution is deploying an AI system to approve personal loans. To comply with the EU AI Act's high-risk AI requirements, the bank must ensure meaningful human oversight. Which implementation BEST satisfies this requirement?
29A data scientist needs to explain why a specific loan application was rejected by a tree-based model. The model is complex and not inherently interpretable. Which method should the data scientist use to provide a local explanation for this single prediction?
30A company wants to train a language model on sensitive customer data without transferring the raw data to a central server. Which privacy-preserving technique should they use?
31An AI governance team is implementing the NIST AI Risk Management Framework. They have identified a high-risk AI system and are in the 'Measure' function. Which activity is most appropriate for this function?
32A company uses an AI system to generate marketing images. They are concerned about copyright ownership of the generated content. According to current US copyright law, who typically owns the copyright for AI-generated work?
33A company is evaluating fairness metrics for a hiring model. They want to ensure that the model has similar true positive rates (TPR) across demographic groups. Which fairness metric should they use?
34A company is developing an AI policy. Which of the following should be included to ensure accountability for AI-driven decisions?
35An AI system is being deployed to detect deepfakes in video content. To comply with transparency obligations, what should the company implement?
36A company is conducting a vendor AI assessment for a third-party natural language processing service. They need to ensure the vendor's AI governance practices align with their own. Which THREE areas should they evaluate?
37A data scientist is using differential privacy to protect individual privacy in a training dataset. Which TWO actions are correct implementations of differential privacy?
38A data scientist discovers that a model trained to predict loan defaults is denying loans at a higher rate for a particular demographic group. Which type of bias is MOST likely present?
39A healthcare AI startup is developing a model to predict patient readmission risk. The company wants to ensure the model's decisions can be understood by clinicians. Which explainability technique provides local, model-agnostic explanations by fitting a simple surrogate model around a prediction?
40A company is training a large language model and wants to reduce its carbon footprint. Which practice is MOST effective for reducing training energy consumption while maintaining model quality?
41A hospital is implementing an AI system to analyze patient X-rays for potential fractures. The hospital must comply with HIPAA regulations. Which privacy-preserving technique allows the model to be trained on data from multiple hospitals without sharing raw patient data?
42An AI ethics board is reviewing a model that recommends criminal sentencing lengths. They want to ensure that the model's false positive rates for different demographic groups are equal. Which fairness metric should they use?
43A company uses an AI system to screen job applicants. Under the GDPR, if the system makes automated decisions that have a legal or similarly significant effect on individuals, the data subject has the right to obtain an explanation of the decision. What is this right commonly called?
44A researcher is developing a generative AI model that creates realistic images. To comply with emerging transparency obligations, the researcher must ensure that AI-generated content can be identified as such. Which technique embeds a digital identifier directly into the content that survives compression and cropping?
45An AI risk manager is applying the NIST AI Risk Management Framework (AI RMF). In which function would the organization establish a risk management process and assign roles and responsibilities for AI oversight?
46A company is considering using an open-source large language model for a commercial application. Which intellectual property consideration is MOST important when deciding between open-source and proprietary models?
47A city government uses an AI system to allocate limited social services resources. To ensure fairness, they want to implement human oversight for high-stakes decisions. Which mechanism allows a human to review and potentially override the AI's decision before it is executed?
48A data scientist is evaluating a binary classifier for a hiring tool. They compute demographic parity and find that the selection rate for Group A is 0.2 and for Group B is 0.4. Which action would MOST directly address this disparity?
49A research lab is training a large language model and wants to minimize its environmental impact. Which THREE practices are most effective for reducing the carbon footprint of model training?
50A bank wants to ensure its credit scoring model is fair across demographic groups. The model currently uses features like zip code, income, and credit history. To mitigate potential bias, which TWO actions should the data science team prioritize?
51An AI team notices that their hiring model consistently selects male candidates over equally qualified female candidates. Analysis shows the training data contains past hiring decisions where men were predominantly hired. Which type of bias is the root cause?
52A data scientist needs to explain why a black-box model denied a loan application. Which explainability technique generates local feature importance values using a simpler interpretable model around the prediction?
53A bank uses an AI system for credit scoring. To meet fairness requirements, they want to ensure the model predicts similar outcomes for individuals who are similar with respect to the target variable, regardless of protected attributes. Which fairness metric addresses this?
54A company trains a large language model on a dataset that includes copyrighted books. Under current legal interpretations, which statement about copyright infringement is MOST accurate?
55A hospital wants to train a diagnostic AI model using data from multiple hospitals without sharing raw patient data. Which privacy-preserving technique allows collaborative training while keeping data local?
56An AI model for skin cancer detection achieves high accuracy but performs poorly on dark skin tones. The team wants to evaluate whether the model is calibrated across skin tones. Which fairness metric should they use?
57A company deploys an AI chatbot that generates product descriptions. The company wants to be transparent about AI-generated content. Which practice should they follow?
58During an audit of an AI system, the auditor requests documentation on the model's intended use, performance metrics, and limitations. Which tool is designed to provide this information in a standardized format?
59A social media platform uses an AI system to moderate content. The system incorrectly flags legitimate posts as hate speech, disproportionately affecting minority groups. Which type of bias is likely present?
60A healthcare AI system is subject to GDPR because it processes patient data. Which THREE requirements must the system satisfy?
61A company wants to adopt green AI practices to reduce the environmental impact of training large models. Which TWO actions are most effective?
62A data scientist notices that a hiring model systematically scores female candidates lower than male candidates with similar qualifications. The training data was collected from past hiring decisions where the company historically hired more men. Which type of AI bias is most directly demonstrated?
63A healthcare AI startup is developing a diagnostic tool that uses patient data to predict disease risk. To comply with HIPAA and minimize privacy risks while still training accurate models, which privacy-preserving technique should they prioritize?
64A financial institution deploys an AI model for loan approval. To meet regulatory requirements under the EU AI Act for high-risk AI systems, they must ensure human oversight. Which implementation best satisfies the requirement for meaningful human intervention?
65A data governance team is developing an AI policy for a large corporation. Which TWO elements are essential for a responsible AI governance framework?
66A company is deploying a generative AI system that produces text content. To comply with emerging transparency obligations, which THREE measures should they implement?
67A startup is training a large language model and wants to reduce its environmental impact. Which TWO practices are considered green AI?
68A company uses an AI model to screen job applicants. A disparate impact analysis reveals that the model's rejection rate for a protected group is significantly higher than for others. Which THREE actions should the company take to address this?
69Under the EU AI Act, an AI system used for credit scoring is classified as high-risk. Which THREE obligations apply to the deployer of such a system?
70A healthcare technology company is preparing to deploy an AI system that analyzes patient X-rays to detect early-stage lung cancer. The system is intended to be marketed as a medical device in the European Union. Under the EU AI Act, which classification and corresponding obligation apply to this system?
71A health-tech firm is preparing a model card for a clinical decision support tool that flags patients at risk of sepsis. The compliance team asks which element of the model card is MOST directly relevant to documenting the system's intended use and out-of-scope applications. Which section should the team prioritize?
72A health system wants to deploy an AI triage tool that analyzes patient symptoms and vital signs to prioritize emergency department patients. Before deployment, the governance committee must determine whether the tool qualifies as a high-risk AI system under the EU AI Act. Which factor is MOST determinative of that classification?
73A retail company uses an AI system to dynamically adjust prices based on individual browsing behavior. The system occasionally offers different prices to different customers for the same product. A customer advocacy group raises concerns under the EU AI Act. Which statement BEST describes the compliance obligation?
74A retail company is deploying an AI system that generates personalized marketing copy and product recommendations. The legal team wants to align the deployment with the NIST AI Risk Management Framework's core functions. Which two activities are part of the MAP function? (Choose two.)
75A municipality uses an AI system to triage requests for public housing assistance. Community advocates ask how they can challenge a denial that they believe resulted from an erroneous data match. Which governance mechanism is MOST appropriate to provide affected individuals with a route to contest automated outcomes?
76A software company is developing an AI-powered code generation tool that suggests code snippets to developers. The company wants to align with the EU AI Act's transparency requirements. Which two actions should the company take? (Choose two.)
77A media company wants to use an AI system to generate synthetic voiceovers for news summaries. Before launch, the ethics board asks the team to address the risk that listeners may mistake synthetic audio for authentic recordings. Which control BEST mitigates this specific risk?
78A marketing team wants to use an AI system to generate personalized advertisements that include realistic images of celebrities endorsing products. The legal team raises concerns about compliance with the EU AI Act. Which action should the team take to comply with the Act's transparency requirements?
79A data scientist is building a machine learning model to predict employee attrition for an HR department. The model will be used to identify employees at risk of leaving and to suggest personalized retention offers. The company operates in the EU. Under the EU AI Act, which classification applies to this AI system?
80A software vendor is developing an AI system that generates realistic images of people for use in marketing campaigns. The system will be sold to clients in the EU. Under the EU AI Act, which obligation applies to the vendor regarding the generated content?
81A hospital plans to deploy an AI system that analyzes patient data to predict the likelihood of hospital readmission. The system will be used to allocate post-discharge care resources. The hospital's ethics committee wants to ensure compliance with the EU AI Act's requirements for high-risk AI systems. Which practice is MOST critical for meeting the Act's human oversight requirements?
You must be able to read a deployment scenario and select the specific governance actions required: measure and mitigate bias, satisfy privacy and data-protection rules, and provide transparency. The single most important thing is matching each obligation to the correct control rather than a generic best practice.
The Courseiva AI0-001 question bank contains 81 questions in the AI Governance and Ethics domain, covering the 5% of the exam attributed to this domain in the official CompTIA blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the AI Governance and Ethics domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included