ISACA · Free Practice Questions · Last reviewed May 2026
18real exam-style questions organised by domain, each with the correct answer highlighted and a plain-English explanation of why it's right — and why the others are wrong.
Which TWO actions should be taken to enforce Least Privilege access for developers interacting with SageMaker Model Monitor?
Allow all 'iam:PassRole' actions
Restrict access to the 'sagemaker:CreateModelMonitor' action
Limiting this action prevents unauthorized creation of monitoring jobs.
Grant s3:PutObject on the bucket containing baseline data
Baseline data access is required for monitoring jobs.
Assign the 'SageMakerFullAccess' managed policy
Enable root access to the underlying EC2 instance
You are configuring AWS Bedrock Guardrails to prevent the model from returning PII. Which specific configuration setting should be enabled to ensure PII filtering is applied to both prompt and response?
Use the prompt engineering instruction 'Do not output PII' in the System Prompt field.
Set the content moderation filter level to 'High' in the model configuration.
Apply an IAM policy to the Bedrock execution role restricting access to PII-containing datasets.
Enable PII filtering in the Policy Settings for both 'input' and 'output' content flows.
Correct configuration for bidirectional PII filtering in Bedrock Guardrails.
You are configuring Microsoft Defender for Cloud to monitor your Azure OpenAI service. Which specific resource diagnostic setting must be enabled to ensure that prompt injection attempts are logged in the Log Analytics workspace?
Enable 'AccessControl' logging in Entra ID
Enable 'RequestResponse' diagnostic logs for the AI resource
The RequestResponse category includes the prompt and completion data required for security analysis.
Enable 'MetricAlerts' at the subscription level
Enable 'AuditLogs' in the Storage Account settings
During an adversarial training cycle, you notice the model's accuracy on the validation set drops significantly despite high training accuracy. Which technique should you apply to mitigate potential model poisoning?
Increase the learning rate
Enable Model Versioning in MLflow
Implement Differential Privacy (DP-SGD)
DP-SGD reduces the influence of individual training points, neutralizing poisoning attempts.
Switch to a pre-trained Transformer architecture
When implementing Google Cloud's 'Vertex AI' model guardrails, you need to prevent the leakage of PII in model outputs. Which configuration tool is used to enforce these constraints at the request/response level?
Vertex AI 'Feature Store' access control
Vertex AI 'Safety Settings' filters
These filters allow developers to set threshold levels for various categories of sensitive content.
Vertex AI 'Model Registry' IAM roles
Vertex AI 'Pipeline' execution logs
You are configuring Microsoft Defender for Cloud for an Azure OpenAI deployment. To detect prompt injection attempts effectively, which specific setting must be enabled in the 'Microsoft Defender for Cloud Apps' dashboard?
Set 'Log Analytics' retention to 365 days
Enable 'AI Security Posture Management' (AI-SPM)
AI-SPM is the designated feature set for identifying security configuration risks and anomalous activity in AI workloads.
Configure 'Conditional Access' policies for API keys
Enable 'Azure Policy' for resource tagging
Want more AI Technologies And Controls practice?
Practice this domainA company is adopting the ISO/IEC 42001 AI management system standard. What is the primary purpose of the 'Context of the Organization' clause?
To define the boundaries and strategic intent of the AI management system.
It establishes the framework within which AI risks are managed.
To specify hardware requirements for training.
To mandate the use of cloud-based AI services.
To identify all bugs in the production code.
When drafting an AI policy, how should the organization address 'Human-in-the-Loop' (HITL) requirements?
Require HITL for every single AI inference.
Mandate HITL for high-impact or sensitive decision-making processes.
Risk-based approach allows for automation of low-risk tasks while safeguarding high-stakes decisions.
Delegate HITL requirements to the software development team.
Exclude HITL to maximize system throughput.
A multinational bank is deploying a proprietary LLM. Which approach provides the most robust assurance for model supply chain security?
Scanning all model weights using antivirus.
Reviewing the vendor's marketing brochure.
Limiting model access via VPN.
Implementing an AI Software Bill of Materials (SBOM).
Provides visibility into training data, libraries, and base model lineage.
An AI security program manager is assessing AI risks. Which tool provides the most centralized oversight for AI model compliance?
An enterprise GRC platform with AI modules.
Provides audit trails, policy mapping, and risk tracking.
A local Python script for model testing.
A public open-source project management board.
A standard spreadsheet file.
When establishing an AI steering committee, which reporting cadence is most effective for ensuring board-level oversight of residual AI risk?
Weekly technical incident logs.
Quarterly strategic risk and compliance assessments.
Provides the appropriate balance of strategic oversight and risk management updates.
Annual compliance attestation only.
Real-time dashboard access for all directors.
An enterprise is defining its 'AI System Inventory'. Which metadata attribute is most critical for assessing legal and regulatory risk?
Hardware acceleration type.
Inference latency in milliseconds.
Model training compute cost.
Training data source and provenance.
Determines the legal basis for data processing and potential copyright infringement.
Want more AI Governance And Program Management practice?
Practice this domainAn organization is using an LLM-based agent. What is the primary risk associated with 'indirect prompt injection' in this environment?
The model produces hallucinatory facts.
The API key for the LLM is exposed in the code.
The training data includes PII of users.
External data retrieved by the agent contains instructions that override system prompts.
This is the definition of indirect prompt injection where the LLM executes malicious input.
Which TWO of the following are primary risks associated with 'membership inference attacks' against an AI model?
Exposure of sensitive information about training data subjects.
Privacy leakage is the core consequence of membership inference.
Violation of regulatory requirements like GDPR/HIPAA.
Determining if an individual's record was used in training violates privacy rights.
Unauthorized modification of model weights.
Unauthorized access to the model training algorithm.
Complete system shutdown via resource exhaustion.
When utilizing a third-party AI vendor, which contractual requirement is most critical for addressing 'shadow AI' risks within an enterprise?
A mandate to use the vendor's cloud region exclusively.
A request for a free trial period.
A requirement for 99.99% uptime SLA.
A clause requiring the vendor to disclose all sub-processors.
Understanding the supply chain is vital for managing third-party AI risk and shadow deployment.
When establishing a risk management framework for GenAI, which THREE factors should be prioritized to satisfy the NIST AI Risk Management Framework requirements?
Continuous monitoring of model performance metrics.
Continuous monitoring is a core requirement of the NIST framework.
Establishing a robust AI governance structure.
Governance is foundational to the NIST AI RMF.
Ensuring the system is inherently secure and resilient.
Safety and resiliency are key pillars of the AI RMF.
Requiring all models to be open-source.
Implementing a strict 'no external API' policy for all models.
A machine learning model is showing signs of 'data drift'. What is the most effective initial step in the risk assessment process?
Retrain the model immediately with all available data.
Analyze the statistical distribution of input production data versus training data.
Statistical analysis is the baseline step for confirming and scoping data drift.
Shut down the application to prevent incorrect predictions.
Change the model architecture to a more complex design.
An organization is performing threat modeling for a RAG (Retrieval-Augmented Generation) pipeline. Which specific vulnerability is unique to the retrieval component?
Database poisoning within the retrieved document index.
Retrieval poisoning is the specific risk where the context provider is compromised.
Overfitting of the LLM on the training set.
Gradient-based evasion attacks on the LLM.
Prompt injection targeting the LLM model weights.
Want more AI Risk Management practice?
Practice this domainThe AAISM exam has 200 questions and must be completed in 120 minutes. The passing score is 700/1000.
Scenario-based questions covering exam objectives with detailed answer explanations.
The exam covers 3 domains: AI Technologies And Controls, AI Governance And Program Management, AI Risk Management. Questions are weighted by domain — higher-weight domains appear more on your actual exam.
No. These are original exam-style practice questions written against the official ISACA AAISM exam objectives. They are not copied from the real exam. Courseiva focuses on genuine understanding, not memorisation of braindumps.
Courseiva tracks your accuracy per domain and routes you toward weak areas automatically. Free, no account required.