Practice AAISM AI Risk Management questions with full explanations on every answer.
Start practicing
AI Risk Management — choose a session length
Free · No account required
Click any question to see the full explanation and answer options, or start a focused practice session above.
An organization is using an LLM-based agent. What is the primary risk associated with 'indirect prompt injection' in this environment?
2Which TWO of the following are primary risks associated with 'membership inference attacks' against an AI model?
3When utilizing a third-party AI vendor, which contractual requirement is most critical for addressing 'shadow AI' risks within an enterprise?
4When establishing a risk management framework for GenAI, which THREE factors should be prioritized to satisfy the NIST AI Risk Management Framework requirements?
5A machine learning model is showing signs of 'data drift'. What is the most effective initial step in the risk assessment process?
6An organization is performing threat modeling for a RAG (Retrieval-Augmented Generation) pipeline. Which specific vulnerability is unique to the retrieval component?
7During an adversarial threat modeling exercise for a facial recognition system, you identify a risk of pixel perturbation attacks. Which countermeasure is the most appropriate technical control to implement?
8You are assessing a supply chain risk where an AI model uses a pre-trained base model from a third-party hub. Which action most effectively mitigates the risk of model poisoning during the integration phase?
9A developer is implementing 'Differential Privacy' on a training dataset. What is the primary trade-off they are managing?
10What is the primary objective of a 'Bias Audit' in an AI risk management program?
11Which of the following best describes 'Model Inversion' as a security risk?
12Which THREE technical controls are recommended to secure an AI model's API endpoint?
13When conducting a risk assessment for an AI system, which TWO of the following are considered 'AI System' components that require individual threat assessment?
14You are implementing 'AI Red Teaming'. What is the most effective way to test against prompt injection?
15You are managing risks for a federated learning deployment. What is the primary security concern regarding the 'model updates' sent from the edge clients to the aggregator?
16Which THREE criteria are essential for evaluating the risk of an AI vendor's 'Model Card'?
17Which TWO of the following are considered 'AI Supply Chain' risks?
18A model is vulnerable to 'Evasion Attacks' using FGSM (Fast Gradient Sign Method). Which architectural change most effectively increases robustness?
19What is the most effective control to prevent 'Model Scraping' from an exposed AI prediction API?
20When assessing AI third-party vendor risk, which document is most useful for understanding the vendor's data handling practices?
21You are managing an AI project and notice the model is performing poorly on a subset of data representing a protected class. What is the correct next step in the risk assessment process?
22Which THREE practices are necessary for managing 'AI Model Version Control' as part of an overall risk management strategy?
23An attacker is performing a 'Model Extraction' attack. What is the most likely goal of the attacker?
24Which TWO measures are most effective in reducing the risk of 'Hallucinations' in LLM systems?
25Which THREE factors must be included in a 'Model Risk Management' (MRM) policy?
26Which TWO techniques help mitigate 'Model Poisoning'?
27What is 'AI Shadowing' or 'Shadow AI' in an enterprise setting?
28When evaluating an AI model for production, what does the 'F1 Score' tell you from a risk management perspective?
29What is the primary risk associated with 'Overfitting' in an AI model?
30You are assessing the risk of 'Data Poisoning'. Which stage of the machine learning lifecycle is most vulnerable to this attack?
31What is the purpose of 'AI Model Transparency' in a risk management framework?
32A researcher is using 'Adversarial Training' to defend against evasion. How exactly does this work?
33Which THREE components are critical for an 'AI Incident Response' plan?
34Which TWO factors contribute to 'Model Obsolescence' risk?
35When assessing the risk of 'Prompt Leaking', what is the most important control to implement?
36What is the key risk difference between 'Data Privacy' and 'Model Security' in AI?
37An organization is evaluating 'Third-Party AI Models'. Which risk is most effectively addressed by a 'Model Evaluation Report'?
38Which THREE technical configurations help mitigate the risk of 'Model Exfiltration'?
39You are auditing an AI system for 'Model Explainability' (XAI). Why is XAI critical from a risk management perspective?
40What is the primary role of a 'Human-in-the-loop' (HITL) in AI risk management?
41Which TWO security controls are recommended for protecting 'Training Data'?
42What is the purpose of 'AI Model Inventory'?
43Which THREE items should be included in an 'AI Vendor Assessment'?
44Which of the following describes 'Model Integrity' risk?
45When dealing with 'Adversarial Evasion', why is the 'black-box' nature of an API a risk?
46Which TWO factors help maintain 'AI Accountability'?
47In an AI supply chain, what is 'Dependency Confusion' risk?
48What is the primary goal of 'Model Monitoring' in the context of risk management?
49What is the best way to manage 'Bias' in an AI system?
50What is 'Model Stealing' as a risk?
51Which THREE steps are needed for 'AI Risk Assessment'?
52Which of these is a 'Proactive' risk management strategy?
53Which THREE elements are essential for 'AI Governance'?
54What is the primary risk of using 'Pre-trained models' from public hubs without verification?
55What is 'Model Drift'?
56Which THREE technical controls effectively manage 'Third-Party AI Vendor' risks?
57What is 'AI Red Teaming'?
58Which TWO items must be documented in an 'AI Model Card'?
59What is the primary risk of 'Over-reliance' on AI outputs?
60Which risk management activity happens during the 'Design' phase of an AI project?
61What is a 'Side-Channel Attack' against an AI model?
62Which control is most effective against 'Data Poisoning' in a collaborative learning environment?
The AI Risk Management domain covers the key concepts tested in this area of the AAISM exam blueprint published by ISACA. Courseiva provides free domain-focused practice, mock exams, missed-question review, and readiness tracking across all AAISM domains — no account required.
The Courseiva AAISM question bank contains 62 questions in the AI Risk Management domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the AI Risk Management domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included