Courseiva
Back to ISACA Advanced in AI Audit (AAIA) (AAIA) questions

Scenario-based practice

Hard Difficulty Questions

Practise ISACA Advanced in AI Audit (AAIA) (AAIA) practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

20
scenario questions
AAIA
exam code
ISACA
vendor

Scenario guide

How to approach hard difficulty questions

These are the questions most candidates get wrong. They require connecting multiple concepts, reading tricky output, or knowing edge-case behaviour that isn't on most study cards. Practising them trains you to operate under uncertainty — a necessary skill on the real exam.

Quick answer

Hard Difficulty Questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Related practice questions

Related AAIA topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1hardmulti select
Full question →

When conducting an audit, which THREE of the following represent potential 'Model Risk' areas that require documentation?

Question 2hardmulti select
Full question →

Which TWO of the following are legitimate 'AI Governance' concerns regarding third-party AI service providers (SaaS)?

Question 3hardmulti select
Full question →

When selecting testing techniques for an AI model, which THREE are considered 'Model-Agnostic'?

Question 4hardmultiple choice
Full question →

You are auditing a model's 'Robustness' against adversarial attacks. Which test is most appropriate?

Question 5hardmulti select
Full question →

Which THREE criteria are essential when selecting an AI deployment strategy?

Question 6hardmultiple choice
Full question →

An auditor finds that a model's 'input feature importance' has changed significantly after a retrain. What is the most appropriate action?

Question 7hardmultiple choice
Full question →

Which operational process is required to ensure 'Data Privacy' when using user-generated data for model retraining?

Question 8hardmulti select
Full question →

When auditing a model deployment pipeline, which TWO aspects are critical to verify to ensure compliance with AI governance frameworks?

Question 9hardmultiple choice
Full question →

When auditing model deployment, what is the primary purpose of 'Shadow Mode' testing?

Question 10hardmulti select
Full question →

When documenting audit findings for an AI system, which TWO of the following are critical to include to ensure the audit can be replicated?

Question 11hardmultiple choice
Full question →

An auditor is evaluating an AI system for 'Model Inversion' risk. What is this?

Question 12hardmultiple choice
Full question →

An auditor is evaluating the 'Safety Filter' of an LLM. Which approach is most suitable for detecting 'jailbreak' vulnerabilities?

Question 13hardmulti select
Full question →

When documenting findings, which THREE elements should be included for each finding?

Question 14hardmultiple choice
Full question →

An organization is using 'Federated Learning' to maintain data privacy while training models. What is the primary audit risk associated with this architecture?

Question 15hardmultiple choice
Full question →

In an audit of differential privacy implementations, what is the 'epsilon' parameter used for?

Question 16hardmultiple choice
Full question →

You are auditing a 'Model Monitoring' dashboard. Which metric is most indicative of a potential degradation in the model's reliability over time?

Question 17hardmultiple choice
Full question →

You find that the 'Inference API' for a model allows 'Prompt Injection' attacks. Which governance failure is most likely?

Question 18hardmultiple choice
Full question →

When using 'LIME' (Local Interpretable Model-agnostic Explanations) for auditing, what is the auditor looking for?

Question 19hardmulti select
Full question →

An auditor is evaluating the data pipeline security. Which THREE controls should be verified?

Question 20hardmultiple choice
Full question →

Which technique is most appropriate for mitigating 'Concept Drift' in a production model?

These AAIA practice questions are part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style AAIA questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.