ISACA · Free Practice Questions · Last reviewed May 2026
18real exam-style questions organised by domain, each with the correct answer highlighted and a plain-English explanation of why it's right — and why the others are wrong.
An auditor is evaluating bias in a model deployed on AWS SageMaker. Which tool should be used to generate a report on pre-training and post-training bias metrics?
SageMaker Model Monitor
SageMaker Clarify
SageMaker Clarify is the standard tool for detecting bias in AWS-hosted models.
AWS Glue DataBrew
Amazon Inspector
When auditing an Azure Machine Learning pipeline, which functionality within 'Responsible AI dashboard' is required to perform counterfactual analysis on model predictions?
Causal Inference component
Model Overview component
Counterfactuals component
The Counterfactuals component provides 'what-if' analysis.
Error Analysis component
You are auditing a model using IBM Watson OpenScale. Which feature should be configured to detect 'Disparate Impact' to ensure regulatory compliance?
Fairness monitor
The Fairness monitor calculates Disparate Impact and other bias metrics.
Quality monitor
Drift detection monitor
Explainability monitor
Payload logging
To verify the provenance of a model in Google Cloud Vertex AI, which service should the auditor inspect to review the lineage graph of the artifacts?
Vertex AI ML Metadata
ML Metadata is specifically designed to track lineage and lineage graphs.
Vertex AI Feature Store
Cloud Logging
Vertex AI Model Registry
An auditor is evaluating an AI system's robustness against adversarial attacks. Which technique involves perturbing input data to see if the model output changes significantly?
Model pruning
Bias assessment
Data augmentation
Adversarial testing
Adversarial testing specifically probes models for sensitivity to noise.
Which technique is best for verifying that a model has not been subject to 'training data poisoning'?
Review of data provenance
Data provenance confirms the source and integrity of training inputs.
Latency testing
Model Accuracy testing
Hyperparameter tuning
Want more AI Auditing Tools And Techniques practice?
Practice this domainWhen auditing an AI system for regulatory compliance, you find that data lineage is broken between the feature store and the training pipeline. Which control is most likely deficient?
Access control lists for the model production environment
Encryption of data at rest in the data warehouse
Load balancing configuration for the inference API
Metadata logging and transformation documentation
Metadata is the key to maintaining lineage; without it, the link between features and training data is obscured.
A firm uses a third-party AI service. Which control is most critical to ensure compliance with the firm's own AI governance policy?
Including AI-specific compliance requirements in the vendor service-level agreement (SLA)
Contractual obligations are the primary mechanism for enforcing internal standards on external partners.
Conducting weekly penetration tests on the vendor's office premises
Requesting the vendor's employee turnover rates for the last fiscal year
Requiring the vendor to submit copies of all their marketing brochures
You are auditing a 'Model Monitoring' dashboard. Which metric is most indicative of a potential degradation in the model's reliability over time?
Statistical drift between the production input data and training baseline
If production data drifts significantly from training data, the model's assumptions are no longer valid.
The physical location of the cloud server hosting the model
The number of lines of code in the model deployment script
The number of users accessing the model API
You are auditing a firm's AI policy and find that the 'Model Inventory' in the enterprise risk management platform lacks versioning metadata. Which specific control gap should be prioritized to align with NIST AI RMF?
Absence of automated model deployment pipelines
Failure to define the RPO for the primary database
Lack of immutable audit logs for model architecture changes
Without versioning metadata, the lineage of model iterations is lost, violating traceability requirements.
Insufficient budget for cloud storage of historical data
You are assessing a company's 'AI Governance Committee'. Which action best demonstrates effective board-level oversight?
Managing the day-to-day procurement of data labeling services
Reviewing individual code commits for AI model training
Selecting the machine learning framework used by data scientists
Approving the annual AI strategy and corresponding risk mitigation plans
The board's role is to ensure that AI risk is integrated into the overall enterprise risk strategy.
Which component of an AI policy is most important for establishing organizational accountability?
Describing the history of artificial intelligence research
Listing the hardware specifications of the training clusters
Providing the contact information for the company's PR department
Defining the roles and responsibilities of the AI Governance Committee and model owners
Clear ownership ensures that someone is responsible for the performance and risk management of the AI system.
Want more AI Governance And Risk practice?
Practice this domainWhat is the primary purpose of a 'Champion-Challenger' deployment pattern in MLOps?
To manage database indexes
To compress model weights
To safely test a new model vs production
Ensures risk mitigation before full cutover.
To increase training speed
When auditing Kubeflow pipelines, which configuration file is used to define the resource requests for individual pipeline steps?
resource_spec in the SDK
Defines compute requirements for k8s pods.
Namespace policy
Kubeconfig file
Service mesh config
For a production LLM deployment, which operational metric is most critical to monitor to identify 'hallucination' or grounding failure in real-time?
Throughput (TPS)
Context faithfulness score
Measures how much the answer is supported by the context.
Token generation latency
Error code distribution
Memory footprint
An organization uses MLflow for model tracking. To ensure auditability of model lineage, what must be captured in the 'mlflow.log_artifact' call?
Environment variable list
User IP address
Compute cluster name
Git commit hash and data URI
This links code state to the model artifact.
In Google Vertex AI Pipelines, which mechanism prevents 'training-serving skew' when deploying a custom container model?
Custom prediction routines
Artifact metadata locks
Model Monitoring skew detection
Automates comparison of feature distributions.
Pipeline concurrency limits
When implementing drift detection in AWS SageMaker Model Monitor, which metric should be monitored to detect feature attribution shift for structured data?
Cosine Similarity
Mean Square Error
Feature Attribution Drift (SHAP)
This directly measures shift in SHAP values.
Precision-Recall AUC
Want more AI Operations practice?
Practice this domainThe AAIA exam has 200 questions and must be completed in 120 minutes. The passing score is 700/1000.
Scenario-based questions covering exam objectives with detailed answer explanations.
The exam covers 3 domains: AI Auditing Tools And Techniques, AI Governance And Risk, AI Operations. Questions are weighted by domain — higher-weight domains appear more on your actual exam.
No. These are original exam-style practice questions written against the official ISACA AAIA exam objectives. They are not copied from the real exam. Courseiva focuses on genuine understanding, not memorisation of braindumps.
Courseiva tracks your accuracy per domain and routes you toward weak areas automatically. Free, no account required.