Courseiva
AI Governance and Ethics →hardMultiple Choice

AI0-001 AI Governance and Ethics Practice Question

An AI governance team is implementing the NIST AI Risk Management Framework. They have identified a high-risk AI system and are in the 'Measure' function. Which activity is most appropriate for this function?

⚠ Common exam trap

The AI0-001 exam often tests the distinction between the NIST AI RMF functions (Map, Measure, Manage, Govern) by presenting risk mitigation actions (like implementing controls) as plausible activities for the 'Measure' function, when they actually belong to the 'Manage' function.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Conduct bias and fairness impact assessments on the model

In the NIST AI Risk Management Framework (AI RMF), the 'Measure' function focuses on assessing and analyzing risks associated with AI systems. For a high-risk AI system, conducting bias and fairness impact assessments is a core activity within this function, as it quantifies and evaluates potential harms related to fairness, accuracy, and transparency. This aligns with the framework's emphasis on quantitative and qualitative risk measurement before moving to risk treatment in the 'Manage' function.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Conduct bias and fairness impact assessments on the model

    Why this is correct

    Bias and fairness impact assessments generate quantitative and qualitative evidence about model behaviour, which is exactly what the Measure function covers: analysing, benchmarking and monitoring identified risks. Mapping and framing belong to earlier functions, while this activity quantifies the high-risk system's performance.

  • ✗

    Implement technical controls to mitigate identified risks

    Why it's wrong here

    Implementing technical controls is risk treatment, which sits in the Manage function, not Measure. It is tempting because mitigation follows naturally from identifying risk, and would be correct once measurement has produced evidence and the team is actively allocating resources to reduce the assessed risk.

  • ✗

    Document the system's intended purpose and data sources

    Why it's wrong here

    Documenting intended purpose and data sources is context establishment, part of the Map function, not Measure. It is tempting because documentation underpins later analysis, and would be correct when framing the system's context, categorising it and identifying relevant stakeholders and dependencies.

  • ✗

    Establish an AI ethics board to oversee risk decisions

    Why it's wrong here

    Establishing an ethics board is a governance-structure activity belonging to the Govern function, not Measure. It is tempting because boards do oversee risk decisions, and would be correct when standing up organisational accountability, roles and policies before or alongside assessing a specific system's risks.

About these practice questions

Courseiva writes every AI0-001 question from scratch — 962 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.