Sample questions
ISACA Advanced in AI Audit (AAIA) (AAIA) practice questions
To verify the provenance of a model in Google Cloud Vertex AI, which service should the auditor inspect to review the lineage graph of the artifacts?
When conducting an audit, which THREE of the following represent potential 'Model Risk' areas that require documentation?
An auditor is evaluating the 'Model Monitoring' dashboard. Which TWO items should the dashboard display to alert the team of potential issues?
When reviewing an AI system log, what is the 'inference request' ID used for?
Which metric is commonly used to audit classification models?
Which TWO of the following are essential when performing an 'AI Risk Assessment'?
Which TWO of the following are typical 'Model Risk Management' (MRM) pillars?
Which 'AI Risk Mitigation' strategy is most effective for reducing 'Data Leakage' in training sets?
Which TWO of the following are legitimate 'AI Governance' concerns regarding third-party AI service providers (SaaS)?
When selecting testing techniques for an AI model, which THREE are considered 'Model-Agnostic'?
What is the key difference between 'AI Ethics' and 'AI Compliance'?
You are auditing a model's 'Robustness' against adversarial attacks. Which test is most appropriate?
You are assessing the risk of 'Data Poisoning' in a retail AI model. Which control should you implement during the data ingestion pipeline to mitigate this risk?
Which THREE criteria are essential when selecting an AI deployment strategy?
An auditor finds that a model's 'input feature importance' has changed significantly after a retrain. What is the most appropriate action?
Which operational process is required to ensure 'Data Privacy' when using user-generated data for model retraining?
When auditing a model deployment pipeline, which TWO aspects are critical to verify to ensure compliance with AI governance frameworks?
When auditing model deployment, what is the primary purpose of 'Shadow Mode' testing?
Which of the following is a common 'drift' symptom an auditor should look for in production models?
What is a 'Model Repository' in an AI audit context?
When documenting audit findings for an AI system, which TWO of the following are critical to include to ensure the audit can be replicated?
You are auditing a deployment on Kubernetes using Kubeflow. Which component should the auditor examine to ensure that the pipeline steps are reproducible?
An auditor is evaluating an AI system for 'Model Inversion' risk. What is this?
What is the primary role of a 'Human-in-the-Loop' (HITL) audit requirement?