Courseiva
AI Governance and Ethics →hardMultiple Select

AI0-001 AI Governance and Ethics Practice Question

A retail company is deploying an AI system that generates personalized marketing copy and product recommendations. The legal team wants to align the deployment with the NIST AI Risk Management Framework's core functions. Which two activities are part of the MAP function? (Choose two.)

⚠ Common exam trap

The trap here is treating the NIST AI RMF functions as sequential project phases, when GOVERN is cross-cutting and MEASURE and MANAGE activities can occur alongside mapping.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Categorizing the likelihood and potential impact of risks such as manipulated recommendations or exposure of inferred preferences.

The MAP function establishes context and characterizes risks. Documenting business context and stakeholders, and categorizing likelihood and impact of identified risks, are core mapping activities. Applying controls belongs to MANAGE, continuous post-deployment tracking belongs to MEASURE, and assigning accountability across the organization belongs to GOVERN, which underpins all other functions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Establishing organizational policies that assign accountability for AI risk decisions across product, legal, and engineering teams.

    Why it's wrong here

    Assigning accountability and establishing governance policies align most closely with the GOVERN function, which sets the culture, roles, and processes that span the entire lifecycle. GOVERN is not a phase but a cross-cutting foundation. While mapping depends on clear ownership, the act of defining accountability structures is governance work rather than risk mapping, so this option does not fit the MAP function.

  • ✗

    Applying technical controls such as output filters and rate limits to reduce the chance of harmful generated copy reaching customers.

    Why it's wrong here

    Applying controls is a MANAGE activity. The MANAGE function allocates resources to treat prioritized risks through mitigation, transfer, avoidance, or acceptance. Output filters and rate limits are treatment mechanisms, not mapping steps. They depend on risks already being identified and prioritized, so placing them in MAP confuses the sequencing of the framework and would leave treatment disconnected from assessed risk.

  • ✗

    Continuously tracking key performance indicators and drift metrics after the recommendation engine enters production.

    Why it's wrong here

    Continuous tracking after deployment is characteristic of the MEASURE function, which monitors and evaluates performance and risk over time. MEASURE produces the evidence that feeds back into mapping and management. Tracking KPIs and drift is not part of initially establishing context or characterizing risks, so it does not belong in MAP even though it is essential to the overall risk management lifecycle.

  • ✓

    Categorizing the likelihood and potential impact of risks such as manipulated recommendations or exposure of inferred preferences.

    Why this is correct

    MAP includes identifying and characterizing risks, including estimating likelihood and impact, so that later functions can prioritize them. Categorizing risks for the recommendation engine, such as manipulated outputs or inference of sensitive preferences, is a mapping activity. It precedes measurement and management, and it determines which risks warrant deeper analysis or controls, making it a correct MAP responsibility.

  • ✓

    Documenting the specific business context, affected stakeholders, and intended purpose of the recommendation engine.

    Why this is correct

    Mapping requires establishing context: who is affected, what the system is meant to do, and what constraints apply. Documenting business context and stakeholders is a foundational MAP activity because it frames all subsequent risk identification and treatment. Without this context, teams cannot judge which risks are material for the recommendation engine or how to prioritize mitigation, so it belongs squarely in the MAP function.

About these practice questions

This AI0-001 question is part of Courseiva's 962-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.