Courseiva

ISACA Advanced in AI Risk (AAIR) (AAIR) (AAIR) — Questions 175

199 questions total · 3pages · All types, answers revealed

Page 1 of 3

Page 2
1
Multi-Selectmedium

Which TWO actions should be taken when a model exhibits significant drift?

Select 2 answers
A.Perform a root cause analysis to determine the nature of the drift.
B.Retrain the model on updated data if the drift is identified as environmental change.
C.Disable all logging to improve performance.
D.Change the model architecture to something simpler.
E.Immediately increase the compute resources.
AnswersA, B

Crucial to deciding whether to retrain or adjust inputs.

Why this answer

The model should be assessed for retraining and the production environment should be audited.

2
MCQhard

You are mapping AI risks to the NIST AI RMF. Which step is essential when documenting the 'Map' function for a high-risk autonomous system?

A.Identifying and documenting the context and intended use
B.Updating the SOC2 Type II report
C.Automating the model deployment pipeline
D.Conducting a quarterly penetration test
AnswerA

The 'Map' function focuses on understanding the context to prioritize risks.

Why this answer

Identifying and documenting the context and intended use is the foundation of mapping AI risks to an enterprise framework.

3
Multi-Selectmedium

Which THREE metrics should be tracked to assess the 'Risk' of an AI model in production?

Select 3 answers
A.Model accuracy/error rate
B.The brand of the coffee machine
C.The number of employees in the break room
D.Model latency (response time)
E.Data drift
AnswersA, D, E

Errors represent a direct risk to the business.

Why this answer

Risk is measured by performance stability (drift), accuracy, and operational health.

4
Multi-Selecthard

The AI Governance Committee is defining the roles for AI Risk oversight. Which TWO functions are essential for the 'Three Lines of Defense' model in AI Risk?

Select 2 answers
A.AI development teams performing self-assessments.
B.The AI Ethics Committee drafting external press releases.
C.The Chief Information Officer managing all AI infrastructure.
D.External vendors providing cloud infrastructure.
E.The AI Risk Management function providing independent oversight.
AnswersA, E

The first line of defense is the business unit/developer performing initial risk management.

Why this answer

The 1st line (Model Owners) and 2nd line (Risk/Compliance) are critical for effective AI risk management.

5
MCQhard

A firm is using the NIST AI Risk Management Framework to document its AI risk program. Which approach best ensures that AI risk metrics are dynamic?

A.Conducting annual risk assessments
B.Setting static thresholds for model accuracy
C.Limiting AI deployment to offline systems
D.Integrating model performance metrics into operational dashboards
AnswerD

Continuous monitoring and dashboarding provide the real-time visibility needed for dynamic risk management.

Why this answer

Mapping specific risk indicators to model performance monitoring allows metrics to evolve as the model's environment changes.

6
Multi-Selectmedium

Which TWO documents are essential to include in the AI Risk Project 'Review Pack'?

Select 2 answers
A.A summary of the team's lunch schedule.
B.A detailed risk mitigation and action plan.
C.A list of all software installed on company laptops.
D.A copy of the company's lease agreement.
E.A comprehensive AI Risk Assessment report.
AnswersB, E

Defines how risks will be handled.

Why this answer

The Risk Assessment report documents the analysis, and the Mitigation Plan shows how identified risks will be addressed.

7
MCQeasy

What is the first step in performing an AI Risk Assessment?

A.Hiring a security consultant.
B.Updating the company website.
C.Running a bias test.
D.Defining the scope, context, and purpose of the AI system.
AnswerD

Scoping is always the first step in any risk assessment process.

Why this answer

The first step is identifying the AI system and defining its intended purpose (Context).

8
Multi-Selecthard

You are integrating AI governance into the existing Corporate Governance framework. Which THREE of the following activities are essential to ensure the Board of Directors maintains adequate oversight?

Select 3 answers
A.Reviewing and approving the organization's AI Risk Appetite Statement.
B.Installing software patches on all GPU servers.
C.Designating executive-level accountability for AI risk management outcomes.
D.Conducting daily code reviews of all AI training algorithms.
E.Establishing a reporting cadence for significant AI-related risk incidents and model performance trends.
AnswersA, C, E

This is a fundamental governance responsibility for the board.

Why this answer

Board oversight of AI requires clear policies, defined accountability, and reporting mechanisms that link AI performance to the enterprise's risk and compliance goals.

9
Multi-Selectmedium

Which TWO factors should be included in an AI risk appetite statement?

Select 2 answers
A.The intended impact on company revenue
B.The specific programming language allowed
C.The preferred office software
D.Financial thresholds for model-related incidents
E.Maximum tolerable level of model bias
AnswersD, E

Financial impact limits are a classic component of risk appetite.

Why this answer

Risk appetite must be specific to the impact and the tolerance levels for failure.

10
MCQhard

A developer is using 'Shadow Deployments' for a new AI model. What is the main risk being addressed?

A.Operational risk of deploying a poorly performing model to production.
B.Model documentation compliance.
C.Training data leakage.
D.Hardware infrastructure costs.
AnswerA

Shadow mode validates the model against live data without impacting the end-user experience.

Why this answer

Shadow deployments allow real-world data validation without exposing end-users to potential model failures.

11
MCQmedium

A firm adopts the 'Three Lines of Defense' model for AI. What is the specific responsibility of the 'Third Line' (Internal Audit)?

A.Providing independent assurance on the design and effectiveness of the AI governance framework.
B.Approving AI model deployment.
C.Developing the AI models.
D.Defining the AI risk appetite.
AnswerA

Internal Audit's role is independent assurance, not operational management.

Why this answer

The Third Line provides independent, objective assurance on the effectiveness of the risk management and governance processes.

12
MCQhard

When reporting AI risk to the board, which approach best demonstrates 'Risk Culture' maturity?

A.Listing all AI projects currently in production with their budget spend.
B.Reporting solely on the number of successful cyber attacks against the AI infrastructure.
C.Presenting a heatmap showing residual risk levels against the defined enterprise risk appetite.
D.Providing a list of all AI models currently undergoing training.
AnswerC

This shows an understanding of risk management and governance maturity.

Why this answer

Risk culture maturity is demonstrated by transparently reporting not just incidents, but the effectiveness of the risk management process itself, including the 'Risk Appetite' vs. 'Actual Risk' gap.

13
MCQeasy

Which document is essential for defining the roles and responsibilities within an AI Risk Program?

A.AI Governance RACI Matrix.
B.Data Privacy Impact Assessment (DPIA).
C.Model Training Log.
D.AI Incident Response Plan.
AnswerA

A RACI matrix is the standard tool to formalize organizational roles in a governance program.

Why this answer

The RACI matrix clearly defines who is Responsible, Accountable, Consulted, and Informed for AI risk activities.

14
MCQeasy

What is the primary objective of a 'post-implementation review' in the AI Risk Governance lifecycle?

A.To decommission the model permanently.
B.To verify that the model continues to operate within established risk thresholds.
C.To ensure the developers received their bonuses.
D.To increase the model's complexity for better performance.
E.To ensure the developers received their bonuses.
.To decommission the model permanently.
AnswerB

Ongoing monitoring ensures that models do not drift into unsafe states.

Why this answer

Post-implementation reviews assess whether the AI model's performance and risk levels remain consistent with the original design and risk appetite.

15
MCQhard

When integrating AI risk into the broader ERM (Enterprise Risk Management) framework, which approach is most effective?

A.Only report AI risks if they result in a financial loss
B.Keep AI risks in a separate, isolated tracking system
C.Map AI risks to existing risk categories (e.g., operational, compliance)
D.Automate the removal of AI risks from the main risk register
AnswerC

Integration ensures AI risk is treated with the same rigor as traditional enterprise risks.

Why this answer

AI risks should not be siloed; they should be categorized alongside existing operational and reputational risks to ensure they are visible to the Board.

16
Multi-Selecthard

Which THREE items should be included in an AI 'Risk Assessment' report for a new project?

Select 3 answers
A.Identification of potential failure modes and their impact.
B.The favorite color of the lead developer.
C.The residual risk level after applying controls.
D.A list of all competitors currently using the same software.
E.Documentation of mitigating controls for identified risks.
AnswersA, C, E

Failure mode analysis is a standard risk assessment technique.

Why this answer

A complete report covers the risk identification, the impact analysis, and the control strategy.

17
MCQeasy

Why is 'Explainability' considered a key risk management control in the AI lifecycle?

A.It guarantees the model will never fail.
B.It increases the inference speed of the model.
C.It enables identification of potential bias, errors, or unexpected behavior in model decision-making.
D.It allows the model to train on less data.
AnswerC

Understanding *why* a model made a decision is essential for debugging and legal compliance.

Why this answer

Explainability allows stakeholders to audit decisions and ensure they comply with regulatory requirements (like GDPR).

18
MCQmedium

What is the primary benefit of documenting 'AI Model Lineage'?

A.It ensures the model is smaller in file size.
B.It provides transparency, auditability, and the ability to reproduce models.
C.It helps the marketing team write better ads.
D.It makes the model run faster.
AnswerB

Reproducibility and auditability are core requirements for AI safety and risk management.

Why this answer

Lineage allows for traceability, enabling auditability and root cause analysis in case of a model failure.

19
MCQmedium

When documenting an AI Risk Program, what should be included in the 'AI Asset Register'?

A.The raw hardware serial numbers of the servers.
B.The model purpose, data lineage, stakeholders, and risk classification.
C.The exact lines of code in the model.
D.The home addresses of all developers.
AnswerB

These are essential for understanding the risk and accountability for each AI model.

Why this answer

An asset register must track the model's purpose, data sources, and business owner to ensure oversight.

20
MCQeasy

In the context of AI risk management, what does the 'Human-in-the-Loop' (HITL) concept primarily aim to achieve?

A.To reduce the cost of model development.
B.To maintain accountability and oversight for AI-driven decisions.
C.To increase the speed of model inference.
D.To automate the labeling of training data.
AnswerB

HITL is designed to provide oversight and accountability for critical decisions.

Why this answer

HITL ensures that human judgment and ethics remain integrated into high-risk AI decision processes to prevent unmonitored failures.

21
MCQmedium

A practitioner is reviewing the 'Model Card' for an AI system. What is the primary purpose of this artifact in the AI lifecycle risk management process?

A.To automate the retraining pipeline for the model.
B.To serve as the primary authentication token for API access.
C.To provide transparency regarding the model's limitations, intended use cases, and performance metrics.
D.To define the deployment strategy in Kubernetes.
AnswerC

Model cards serve as the foundational documentation for risk assessment and compliance.

Why this answer

Model cards provide transparency and documentation about the intended use, limitations, and performance characteristics.

22
Multi-Selectmedium

Which TWO stakeholders are most important to engage when establishing an AI risk appetite?

Select 2 answers
A.The building security personnel.
B.The Board of Directors or Executive Committee.
C.The office cleaning staff.
D.Legal and Compliance officers.
E.The company's social media followers.
AnswersB, D

Leadership defines the organization's appetite for risk.

Why this answer

The Board/Executive Leadership defines the appetite, while Legal/Compliance ensures that the definition meets legal requirements.

23
Multi-Selecthard

Which THREE risks are associated with 'Automated Deployment' of AI models without a human-in-the-loop?

Select 3 answers
A.Rapid propagation of faulty or biased models to production.
B.The deployment takes too long to run.
C.Increased risk of security vulnerabilities being overlooked in the deployment config.
D.Lack of human intuition to catch edge-case failures.
E.Increased use of disk space.
AnswersA, C, D

A major risk when automation isn't constrained.

Why this answer

Without human checks, bad models can propagate quickly, causing cascading failures and security gaps.

24
MCQmedium

Which role is primarily responsible for ensuring that AI-generated content adheres to intellectual property risk policies?

A.Chief Legal Officer
B.System Administrator
C.Product Manager
D.Data Engineer
AnswerA

Legal counsel manages the risk associated with IP infringement and copyright.

Why this answer

The Chief Legal Officer or Legal counsel is accountable for IP rights and contractual obligations related to AI output.

25
MCQmedium

An enterprise is establishing an AI Governance Committee. Which organizational structure best ensures that risk management is integrated into the AI development lifecycle?

A.Centralized control under the Chief Data Officer
B.External advisory board oversight
C.Cross-functional membership including Legal, Security, and Engineering
D.Automated AI risk assessment tools alone
AnswerC

Cross-functional teams provide the holistic view required for AI risk management.

Why this answer

A cross-functional approach involving data science, legal, compliance, and IT security ensures risk is addressed at every SDLC phase.

26
MCQhard

An organization discovers that their AI model exhibits bias toward a specific demographic. What is the most important step in the Incident Response process?

A.Suspend the model's production use until the issue is investigated and remediated.
B.Retrain the model immediately.
C.Delete all training data related to the demographic.
D.Issue a public press release.
AnswerA

Suspending the model is the primary containment strategy to prevent continued harm.

Why this answer

Immediate containment is necessary to prevent further harm while the root cause is investigated.

27
Multi-Selecthard

The organization is updating its 'AI Risk Management Policy'. Which THREE components are essential to ensure it aligns with the 'Manage' function of the NIST AI RMF?

Select 3 answers
A.The marketing budget for upcoming AI product launches.
B.A defined mechanism for reporting and remediating non-compliant AI systems.
C.A list of all employees who have access to the source code repository.
D.Criteria for prioritizing AI risks based on impact and likelihood (Risk-based prioritization).
E.Procedures for documenting model performance monitoring and recalibration cycles.
AnswersB, D, E

This ensures that policy violations are identified and fixed.

Why this answer

The 'Manage' function involves implementing controls. Essential components include clear policies on prioritization, documented operational procedures, and a process for ongoing monitoring and improvement.

28
MCQeasy

During the AI lifecycle, when should a 'Data Quality' assessment be performed to minimize long-term risk?

A.After model deployment in production.
B.During the final model sign-off.
C.During the decommission phase.
D.During the data ingestion and preprocessing stage.
AnswerD

Performing quality checks before the model sees the data prevents propagation of errors into model weights.

Why this answer

Data quality must be validated prior to training to ensure model reliability.

29
Multi-Selecthard

Which THREE factors should be monitored to detect 'Model Drift' in the deployment phase?

Select 3 answers
A.The distribution of prediction outputs.
B.The temperature of the server room.
C.The current market price of GPU hardware.
D.The confidence score of the model predictions.
E.The distribution of incoming input features.
AnswersA, D, E

Detects if the model's behavior is changing significantly.

Why this answer

Feature distribution, target distribution, and model confidence scores all provide signals of drift.

30
Multi-Selectmedium

Which TWO of the following are key components of a robust AI lifecycle risk management program?

Select 2 answers
A.Continuous model performance and data quality monitoring.
B.Using only open-source libraries.
C.Strict adherence to a single coding language.
D.Comprehensive versioning of data, code, and model artifacts.
E.Increasing the number of developers on the team.
AnswersA, D

This is essential for identifying drift and errors.

Why this answer

Continuous monitoring and version control are fundamental for governing the model's entire lifespan.

31
Multi-Selectmedium

Which TWO of the following governance actions should a Chief Risk Officer (CRO) implement to align AI risk with the COSO Enterprise Risk Management (ERM) framework?

Select 2 answers
A.Establish a cross-functional AI Risk Committee
B.Assign AI risk ownership to individual data scientists
C.Disable all open-source AI libraries
D.Mandate daily model training cycles
E.Define AI-specific risk appetite statements within the ERM policy
AnswersA, E

This ensures governance oversight across the enterprise.

Why this answer

COSO ERM requires integrating risk into strategy and performance. Governance structures and risk appetite alignment are key.

32
MCQeasy

During the 'Monitoring' phase, which activity is most critical for identifying model 'feedback loops'?

A.Tracking the distribution of prediction outputs over time for systemic shifts.
B.Validating the hardware security keys.
C.Checking for system uptime.
D.Analyzing the training pipeline latency.
AnswerA

If outputs drift significantly, it may indicate the model is creating a feedback loop in the input data.

Why this answer

Feedback loops occur when model outputs influence the future training data, which must be detected by comparing output distributions over time.

33
Multi-Selecteasy

Which TWO of the following are considered 'High-Risk' AI use cases that require enhanced oversight by the Governance Committee?

Select 2 answers
A.Basic spell-checking software.
B.AI-powered biometric identification for facility access.
C.Automated recruitment and hiring filtering tools.
D.Email auto-complete features.
E.AI systems used for internal cafeteria menu suggestions.
AnswersB, C

Biometric systems carry significant privacy and security risks.

Why this answer

AI systems impacting physical safety or fundamental rights require the highest level of governance oversight.

34
Multi-Selectmedium

Which THREE items are necessary for a comprehensive 'AI Governance Policy'?

Select 3 answers
A.Standard Operating Procedures (SOPs) for model lifecycle management.
B.A list of every single line of code in the production models.
C.The personal home addresses of all developers.
D.AI risk classification framework (e.g., Low, Medium, High).
E.Definition of roles and responsibilities for AI risk oversight.
AnswersA, D, E

SOPs operationalize the policy.

Why this answer

A policy needs to define roles, risk classification, and the lifecycle process.

35
MCQeasy

What is 'Shadow AI'?

A.A marketing term for new AI tools
B.A feature in a programming language
C.AI used without formal approval or oversight
D.An AI model that only works in the dark
AnswerC

This represents an unmanaged risk.

Why this answer

Shadow AI refers to AI tools or models used within an organization without the knowledge or approval of the IT/Risk governance teams.

36
Multi-Selecthard

Which TWO aspects of 'Data Governance' are critical for AI risk management?

Select 2 answers
A.Data access control and security
B.The number of pens in the supply closet
C.The speed of the local internet
D.The interior design of the office
E.Data quality and consistency
AnswersA, E

Controlling who can touch the data is a primary risk control.

Why this answer

Data quality and security (access control) are the pillars of data governance for AI.

37
Multi-Selecthard

Which THREE artifacts should be reviewed during a post-incident AI risk analysis?

Select 3 answers
A.The employee training certificates.
B.The building access logs for the data center.
C.The original Model Card and documentation.
D.The raw input and prediction output logs.
E.The model versioning and lineage logs.
AnswersC, D, E

Identifies the intended purpose vs. actual misuse.

Why this answer

Model lineage, inference logs, and the original model card are critical for understanding *what* happened.

38
MCQhard

In a cross-functional AI governance meeting, the Data Science team wants to deploy a new model, but the Legal team is concerned about data privacy. How should the AI Risk Manager resolve this?

A.Order the Data Science team to stop work immediately
B.Ask the CEO to decide
C.Conduct a joint risk assessment to identify potential mitigations
D.Ignore the Legal team's concerns
AnswerC

This is a proactive, collaborative approach that allows for risk-based decision making.

Why this answer

The manager should facilitate a risk assessment to quantify the concern and identify potential technical controls to mitigate the privacy risk.

39
MCQhard

When defining KPIs for an AI Governance program, which metric is most predictive of long-term model robustness?

A.Number of users accessing the AI interface.
B.The frequency of model retraining triggered by performance drift alerts.
C.Total number of AI models currently in production.
D.The budget spent on GPU cloud computing resources.
AnswerB

Retraining frequency related to drift is a direct indicator of whether a model remains robust in a changing environment.

Why this answer

Model drift and retraining frequency serve as leading indicators for the degradation of AI reliability over time.

40
MCQhard

In the context of the Google Cloud Vertex AI Model Registry, what is the best approach to mitigate the risk associated with a model update that performs poorly on edge cases?

A.Implement traffic splitting with a shadow deployment.
B.Increase the training epoch count for the new version.
C.Directly replace the active production model version.
D.Update the training data to remove edge case records.
AnswerA

Shadow deployments allow testing with live data without impacting actual users.

Why this answer

A/B testing (or canary deployments) allows for traffic splitting to validate performance before full rollout.

41
MCQmedium

In the context of the Three Lines of Defense, which function constitutes the 'Second Line'?

A.The Internal Audit department.
B.The Board of Directors.
C.The AI Development team.
D.The AI Risk Management and Compliance teams.
AnswerD

The second line provides oversight, sets policies, and monitors risk.

Why this answer

The second line acts as the risk management and compliance oversight function, separate from the business owners.

42
Multi-Selecthard

When integrating AI risk into existing ERM, which THREE aspects of an AI model lifecycle must be audited to ensure compliance?

Select 3 answers
A.Personnel physical security badges
B.Office climate control settings
C.Model validation results
D.Incident response logs
E.Data lineage and provenance
AnswersC, D, E

Confirms the model meets risk thresholds before deployment.

Why this answer

Data lineage, model validation results, and incident response logs are critical audit points for enterprise risk accountability.

43
Multi-Selectmedium

A firm is establishing an AI Governance Committee. Which TWO groups should be represented to ensure comprehensive oversight?

Select 2 answers
A.Data Privacy Office
B.Public relations
C.Legal and Compliance
D.Hardware vendors
E.External marketing agencies
AnswersA, C

Crucial for handling PII within AI datasets.

Why this answer

Legal/Compliance and Data Privacy are essential for addressing the regulatory and ethical risks inherent in AI deployments.

44
Multi-Selecthard

When considering the 'Risk of Bias' in an AI system, which THREE components should be audited?

Select 3 answers
A.The physical location of the cloud data center.
B.The post-processing decisions made on the model outputs.
C.The composition and representativeness of the training dataset.
D.The number of coffee breaks the data science team takes.
E.The objective function or loss function used for model training.
AnswersB, C, E

Decisions made after the model generates an output can introduce bias.

Why this answer

Bias can enter the model through the training data, the algorithm's objective function, or through post-processing of results.

45
MCQeasy

An organization is establishing an AI Risk Committee. Which stakeholder is most critical to include to ensure alignment between enterprise risk appetite and technical AI capabilities?

A.Chief Risk Officer (CRO).
B.Chief Information Security Officer (CISO).
C.Lead Cloud Architect.
D.Head of Human Resources.
AnswerA

The CRO bridges the gap between enterprise-level risk appetite and specific domain risks like AI.

Why this answer

The Chief Risk Officer (CRO) is responsible for the enterprise risk framework. Their involvement is essential to ensure AI risks are measured consistently with other business risks.

46
MCQhard

You are managing a model that utilizes 'Online Learning'. What is the most critical risk requiring constant lifecycle vigilance?

A.Hardware failure in the training cluster.
B.Adversarial data poisoning and instability.
C.Data drift from batch updates.
D.Memory exhaustion due to high throughput.
AnswerB

Because the model learns from every input, a malicious actor can influence the model's logic through carefully crafted inputs.

Why this answer

Online learning models are constantly updating, making them highly susceptible to 'poisoning' attacks.

47
MCQmedium

When addressing 'Explainability' as an AI risk, which approach is most effective for a non-technical stakeholder?

A.Presenting the feature weights of a neural network.
B.Explaining the gradient descent optimization process.
C.Showing the mathematical formula used for loss reduction.
D.Providing counterfactual explanations like 'If your income had been $5k higher, the loan would have been approved'.
AnswerD

Counterfactuals provide intuitive, actionable insight into the model's logic.

Why this answer

Counterfactual explanations (e.g., 'What would have to change for this decision to be different?') are highly intuitive and effective for non-technical stakeholders.

48
Multi-Selectmedium

Which THREE factors are essential to consider when determining the 'AI Risk Appetite' for an enterprise?

Select 3 answers
A.The current market share of the company.
B.The organization's tolerance for legal and reputational damage.
C.The complexity and autonomy level of the AI models being deployed.
D.The existing regulatory landscape and sector-specific compliance requirements.
E.Historical data volume.
AnswersB, C, D

Reputational and legal tolerance are core components of risk appetite.

Why this answer

Risk appetite must consider the organization's business strategy, regulatory environment, and technical capability.

49
MCQhard

You are utilizing Azure Machine Learning to manage a deployment. You detect a sudden drop in model performance due to 'concept drift'. Which specific configuration in the Azure ML Model Monitoring dashboard should be adjusted to better detect this?

A.Increase the retraining frequency of the pipeline.
B.Disable the data lineage capture to improve latency.
C.Adjust the feature drift sensitivity threshold for categorical variables.
D.Switch the model to a higher-capacity compute instance.
AnswerC

Concept drift often manifests as changes in the distribution of target variables relative to inputs, requiring sensitive drift monitoring.

Why this answer

Concept drift occurs when the relationship between input variables and target variables changes, requiring adjustments to data drift detection parameters.

50
MCQhard

When drafting a vendor management policy for AI, what is the most important clause to include?

A.Requirement for vendor to provide coffee
B.Requirement to use a specific font
C.Vendor must provide free hardware
D.Right-to-audit the vendor's AI training practices
AnswerD

Audit rights are critical for evaluating third-party risks.

Why this answer

Right-to-audit clauses ensure that the organization can verify the vendor's AI risk controls, which is essential for third-party risk management.

51
MCQmedium

A practitioner is setting up a model monitoring service in AWS SageMaker Model Monitor. They observe that the ground truth data is significantly delayed. What action ensures risk identification remains effective?

A.Configure Data Quality Monitoring on input features only.
B.Disable monitoring until ground truth is available.
C.Manually force a model redeployment.
D.Reduce the sampling rate of the inference logs.
AnswerA

Input feature monitoring serves as a proxy for performance when ground truth labels are missing.

Why this answer

When ground truth is delayed, practitioners must rely on feature drift detection rather than accuracy metrics.

52
MCQhard

When assessing the risk of AI-generated content, which factor is the most important for calculating 'Impact'?

A.The potential for reputational and legal consequences
B.The speed at which the content is generated
C.The color of the font used for the output
D.The number of GPUs used to create the content
AnswerA

Impact is measured by the potential harm to the organization.

Why this answer

The potential for reputational or legal harm (consequence) is the most critical component when assessing the impact of AI-generated content.

53
MCQeasy

Which of the following is an example of an 'AI Risk Metric'?

A.Budget spent on office supplies
B.Rate of false negatives in model output
C.Employee headcount in AI department
D.Number of coffee machines in the breakroom
AnswerB

This measures the potential harm or financial risk caused by the model's inaccuracy.

Why this answer

The rate of false negatives in a credit approval model is a direct measure of AI-specific operational risk.

54
MCQmedium

What is the primary responsibility of a 'Model Owner' in an AI risk framework?

A.Writing all the Python code for the model
B.Approving company-wide bonuses
C.Fixing broken office furniture
D.Maintaining the risk profile and performance of the model
AnswerD

The owner is responsible for the model's performance and associated risks.

Why this answer

The model owner is accountable for the entire lifecycle and risk profile of a specific AI model.

55
Multi-Selectmedium

When designing an AI Risk Reporting dashboard for senior management, which TWO of the following should be visualized?

Select 2 answers
A.Server uptime percentages.
B.Raw model prediction scores for every transaction.
C.Status of compliance certifications for high-risk models.
D.Aggregate risk score per business unit.
E.Employee training attendance logs.
AnswersC, D

Compliance status is a key regulatory and board-level indicator.

Why this answer

Management needs to see the current risk levels and compliance status in a summarized format.

56
MCQeasy

What is the goal of an AI 'Model Inventory'?

A.To maintain visibility over all AI models and their associated risk profiles.
B.To automatically delete old models.
C.To provide marketing data to competitors.
D.To increase the speed of model deployment.
AnswerA

You cannot manage the risks of what you do not know exists.

Why this answer

The inventory provides a central repository for tracking all AI assets, which is the baseline for risk management.

57
MCQeasy

Which of the following is an example of an 'AI Risk' in a customer-facing service?

A.A chatbot providing inaccurate information to a customer.
B.The CEO deciding to change the corporate strategy.
C.The office printer running out of ink.
D.A scheduled maintenance window for the website.
AnswerA

This is a model-specific failure that directly impacts the user.

Why this answer

An AI chatbot producing hallucinated information is a clear AI risk involving inaccuracy and potential harm.

58
Multi-Selectmedium

Which TWO factors are essential when documenting a model for risk management?

Select 2 answers
A.The model's intended use cases and operational boundaries.
B.The specific brand of coffee used by the developers.
C.The specific team member's personal hobbies.
D.The performance metrics and limitations observed during testing.
E.The names of all users who access the model.
AnswersA, D

Defines the scope of risk.

Why this answer

Intended use and performance boundaries are essential for governance.

59
MCQhard

A company is scaling its AI initiatives across five business units. What is the most effective way to ensure consistent risk measurement?

A.Using different platforms for each business unit
B.Implementing a centralized AI risk taxonomy
C.Allowing each business unit to define its own risk metrics
D.Focusing only on the highest-risk model
AnswerB

A common language/taxonomy is essential for aggregating AI risk across diverse business units.

Why this answer

Standardizing a taxonomy ensures that all business units report risks using the same language and impact levels.

60
MCQhard

You are analyzing the risk of a generative AI implementation. Which metric most effectively measures 'model transparency' for a risk dashboard?

A.The number of unique contributors to the codebase.
B.The average latency of model inference.
C.Percentage of models deployed with a completed Model Card covering data provenance, limitations, and intended use.
D.The number of parameters in the neural network.
AnswerC

Model Cards are the industry standard for documenting AI transparency for risk assessment.

Why this answer

Documentation completeness (Model Cards) provides a standardized measure of transparency, enabling auditors to assess accountability.

61
Multi-Selecthard

When implementing an AI Risk Management program, which THREE components are necessary for effective monitoring?

Select 3 answers
A.A requirement that all staff undergo coding training.
B.A mechanism for logging and auditing model outputs.
C.A daily newsletter for employees about AI advancements.
D.A process for human intervention or override.
E.Automated real-time monitoring of model performance and drift.
AnswersB, D, E

Audit logs are necessary for accountability and incident investigation.

Why this answer

Real-time performance metrics, a process for human oversight, and a log of model decisions are foundational for continuous monitoring.

62
Multi-Selecthard

The AI Risk Governance Committee is defining the risk appetite for a new generative AI chatbot. Which THREE factors must be considered to align with organizational risk tolerance?

Select 3 answers
A.The speed of the development team's sprint cycles
B.Data privacy and residency requirements for training sets
C.The likelihood of model drift impacting output accuracy
D.The impact of potential hallucination on brand reputation
E.The total cost of GPU infrastructure
AnswersB, C, D

Compliance with data regulations is critical to risk appetite.

Why this answer

Risk appetite for AI depends on the domain, data sensitivity, and potential for harm.

63
MCQeasy

Which document should a practitioner review to determine the organization's threshold for acceptable AI model bias?

A.The vendor's Service Level Agreement (SLA).
B.The Enterprise Risk Appetite Statement.
C.The software's End User License Agreement (EULA).
D.The AI development team's sprint backlog.
AnswerB

This defines the organizational boundaries for risk-taking, including AI bias tolerance.

Why this answer

The Risk Appetite Statement is the formal document approved by the board or senior management that defines the level of risk the organization is willing to accept in pursuit of objectives, including AI-specific tolerances.

64
Multi-Selecthard

Which THREE factors should be considered when assessing the 'Risk Level' of an AI application?

Select 3 answers
A.The sensitivity of the input data.
B.The criticality of the decision-making process being automated.
C.The complexity of the neural network architecture.
D.The potential impact on human rights and individual safety.
E.The color scheme of the user interface.
AnswersA, B, D

Data sensitivity directly correlates to privacy and regulatory risk.

Why this answer

Criticality of the decision, the nature of the data involved, and the potential impact on individuals are the standard pillars of AI risk assessment.

65
Multi-Selectmedium

Which THREE roles should have oversight authority in the AI Risk Program?

Select 3 answers
A.The company's social media influencer
B.Chief Technology Officer
C.Chief Risk Officer
D.The office receptionist
E.Head of Business Unit (where AI is used)
AnswersB, C, E

CTO oversees technical feasibility and risk.

Why this answer

Oversight requires representatives from business, technology, and risk management.

66
MCQmedium

Your organization is implementing an AI Risk Register. Which approach provides the most effective cross-functional coordination for identifying bias in a new HR recruitment AI?

A.Perform a technical audit on the training dataset distribution.
B.Automate all bias detection using internal library scripts without human review.
C.Update the AI policy to forbid the use of demographic attributes in training data.
D.Conduct a mandatory tabletop exercise involving HR, legal, and data science teams to simulate potential discriminatory outcomes.
AnswerD

Tabletop exercises facilitate cross-functional alignment and identification of subjective risk scenarios.

Why this answer

Cross-functional engagement ensures that legal, ethics, and technical teams validate the model against disparate impact standards.

67
Multi-Selecthard

Which THREE components are necessary for effective cross-functional AI risk coordination?

Select 3 answers
A.Clearly defined RACI matrix for AI initiatives
B.Weekly team lunches
C.Standardized AI risk taxonomy
D.A centralized AI risk register
E.Unrestricted access to all production servers for all staff
AnswersA, C, D

A RACI (Responsible, Accountable, Consulted, Informed) matrix defines cross-functional roles.

Why this answer

Coordination requires clear communication, defined roles, and a shared vocabulary.

68
MCQhard

A company is utilizing a third-party LLM service. Which risk is specifically heightened by this arrangement?

A.Data leakage and privacy violations
B.Server downtime
C.Model training cost inflation
D.Lack of software updates
AnswerA

Third-party services introduce risks related to data handling and unauthorized use of inputs.

Why this answer

Data leakage is a significant risk when sending proprietary or sensitive data to external AI service providers.

69
MCQeasy

Why is 'Data Lineage' important in an AI risk management program?

A.It helps ensure data quality and integrity
B.It makes user interfaces more attractive
C.It improves server load times
D.It reduces the amount of storage needed
AnswerA

Knowing the provenance of data is key to managing the risk of poor-quality or biased inputs.

Why this answer

Data lineage allows you to trace data back to its source, which is critical for identifying and mitigating bias or training data contamination.

70
MCQmedium

A manufacturing firm is adopting a 'Privacy by Design' approach for AI. How does this integrate with the AI Risk Governance framework?

A.Privacy becomes the responsibility of the vendor, not the company.
B.Privacy controls are integrated into the MLOps pipeline as automated gates.
C.Privacy is only reviewed after the model is deployed.
D.Privacy impact assessments are excluded to speed up model deployment.
AnswerB

Automated privacy validation ensures compliance is embedded rather than bolted on.

Why this answer

Integrating privacy controls into the development lifecycle (DevOps/MLOps) is a key requirement of modern AI governance frameworks.

71
MCQmedium

A team notices that an AI model's performance decreases when the input data contains abbreviations that were not present in the training set. This is a risk associated with which lifecycle stage?

A.Infrastructure provisioning.
B.Data preprocessing and training design.
C.Monitoring phase.
D.Deployment phase.
AnswerB

The risk is that the training data did not represent the expected operational environment (data variety).

Why this answer

This is a Data Quality/Data Representation risk, where the model's understanding of data is limited by the training corpus.

72
MCQmedium

A company is implementing 'Human-in-the-Loop' (HITL) for its AI decision system. What is the primary risk of relying on HITL?

A.The 'automation bias' or 'rubber stamping' of decisions by human reviewers.
B.It requires expensive API calls.
C.It causes the model to become slower.
D.It forces the model to use a specific programming language.
AnswerA

Humans tend to accept automated suggestions without critical evaluation, defeating the purpose of the control.

Why this answer

Human fatigue and cognitive bias can lead to poor oversight, potentially creating a false sense of security.

73
MCQmedium

You are defining KPIs for an AI project in a regulated industry. Which metric best captures model reliability over time?

A.Model drift (data drift/concept drift)
B.Frequency of model retraining
C.Number of training iterations
D.Total cost of compute resources
AnswerA

Tracking drift is a direct indicator of model performance stability and reliability.

Why this answer

Drift metrics indicate whether the model's accuracy is degrading, which is a proxy for reliability.

74
MCQhard

In the context of the AI RMF, what is the significance of the 'Measure' function for risk management?

A.To identify which employees have access to the AI system.
B.To set the budget for future AI projects.
C.To provide a score for the developers' performance.
D.To evaluate the model's performance and risk outcomes against established benchmarks.
AnswerD

Measuring against benchmarks is how you prove a model is safe and effective.

Why this answer

The 'Measure' function uses quantitative and qualitative assessments to test whether the model is meeting its goals and risk requirements.

75
MCQmedium

What is the primary reason for maintaining an 'AI Model Inventory'?

A.To share model code with competitors
B.To make the database easier to back up
C.To identify and mitigate shadow AI risks
D.To increase the size of the IT department
AnswerC

Visibility is the first requirement for managing risks effectively.

Why this answer

An inventory ensures that no 'shadow AI' exists, allowing for comprehensive risk assessment and oversight.

Page 1 of 3

Page 2

All pages