Courseiva

AAISM · domain

AI Risk Management

Practise ISACA Advanced in AI Security Management (AAISM) (AAISM) AI Risk Management practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

62 questions12 easy30 medium20 hard

Focused practice

Practice AI Risk Management questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about AI Risk Management

AI Risk Management questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common AI Risk Management exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All AI Risk Management questions (62)

Click any question to see the full explanation, or start a practice session above.

1

Which of these is a 'Proactive' risk management strategy?

Easy
2

When conducting a risk assessment for an AI system, which TWO of the following are considered 'AI System' components that require individual threat assessment?

Hard
3

An attacker is performing a 'Model Extraction' attack. What is the most likely goal of the attacker?

Hard
4

When establishing a risk management framework for GenAI, which THREE factors should be prioritized to satisfy the NIST AI Risk Management Framework requirements?

Hard
5

You are assessing the risk of 'Data Poisoning'. Which stage of the machine learning lifecycle is most vulnerable to this attack?

Hard
6

Which THREE technical controls are recommended to secure an AI model's API endpoint?

Medium
7

What is 'Model Drift'?

Medium
8

Which risk management activity happens during the 'Design' phase of an AI project?

Medium
9

What is the primary risk associated with 'Overfitting' in an AI model?

Medium
10

Which TWO measures are most effective in reducing the risk of 'Hallucinations' in LLM systems?

Medium
11

Which TWO items must be documented in an 'AI Model Card'?

Medium
12

What is 'AI Red Teaming'?

Easy
13

You are auditing an AI system for 'Model Explainability' (XAI). Why is XAI critical from a risk management perspective?

Hard
14

Which TWO security controls are recommended for protecting 'Training Data'?

Medium
15

What is the primary risk of 'Over-reliance' on AI outputs?

Medium
16

A model is vulnerable to 'Evasion Attacks' using FGSM (Fast Gradient Sign Method). Which architectural change most effectively increases robustness?

Hard
17

What is the purpose of 'AI Model Inventory'?

Easy
18

What is a 'Side-Channel Attack' against an AI model?

Hard
19

When assessing AI third-party vendor risk, which document is most useful for understanding the vendor's data handling practices?

Easy
20

Which THREE technical controls effectively manage 'Third-Party AI Vendor' risks?

Hard
21

Which THREE criteria are essential for evaluating the risk of an AI vendor's 'Model Card'?

Medium
22

You are managing an AI project and notice the model is performing poorly on a subset of data representing a protected class. What is the correct next step in the risk assessment process?

Medium
23

Which TWO of the following are primary risks associated with 'membership inference attacks' against an AI model?

Medium
24

What is 'Model Stealing' as a risk?

Hard
25

Which control is most effective against 'Data Poisoning' in a collaborative learning environment?

Medium
26

What is the purpose of 'AI Model Transparency' in a risk management framework?

Easy
27

Which THREE elements are essential for 'AI Governance'?

Hard
28

You are managing risks for a federated learning deployment. What is the primary security concern regarding the 'model updates' sent from the edge clients to the aggregator?

Hard
29

What is the primary objective of a 'Bias Audit' in an AI risk management program?

Easy
30

You are assessing a supply chain risk where an AI model uses a pre-trained base model from a third-party hub. Which action most effectively mitigates the risk of model poisoning during the integration phase?

Medium
31

When utilizing a third-party AI vendor, which contractual requirement is most critical for addressing 'shadow AI' risks within an enterprise?

Medium
32

Which TWO factors help maintain 'AI Accountability'?

Medium
33

An organization is evaluating 'Third-Party AI Models'. Which risk is most effectively addressed by a 'Model Evaluation Report'?

Medium
34

An organization is using an LLM-based agent. What is the primary risk associated with 'indirect prompt injection' in this environment?

Medium
35

When evaluating an AI model for production, what does the 'F1 Score' tell you from a risk management perspective?

Medium
36

A machine learning model is showing signs of 'data drift'. What is the most effective initial step in the risk assessment process?

Easy
37

Which THREE factors must be included in a 'Model Risk Management' (MRM) policy?

Hard
38

What is the key risk difference between 'Data Privacy' and 'Model Security' in AI?

Easy
39

What is the best way to manage 'Bias' in an AI system?

Easy
40

What is the primary role of a 'Human-in-the-loop' (HITL) in AI risk management?

Easy
41

During an adversarial threat modeling exercise for a facial recognition system, you identify a risk of pixel perturbation attacks. Which countermeasure is the most appropriate technical control to implement?

Hard
42

An organization is performing threat modeling for a RAG (Retrieval-Augmented Generation) pipeline. Which specific vulnerability is unique to the retrieval component?

Hard
43

When assessing the risk of 'Prompt Leaking', what is the most important control to implement?

Medium
44

In an AI supply chain, what is 'Dependency Confusion' risk?

Hard
45

Which TWO techniques help mitigate 'Model Poisoning'?

Medium
46

Which THREE components are critical for an 'AI Incident Response' plan?

Hard
47

What is the primary goal of 'Model Monitoring' in the context of risk management?

Medium
48

Which THREE practices are necessary for managing 'AI Model Version Control' as part of an overall risk management strategy?

Hard
49

A researcher is using 'Adversarial Training' to defend against evasion. How exactly does this work?

Hard
50

What is the primary risk of using 'Pre-trained models' from public hubs without verification?

Medium
51

A developer is implementing 'Differential Privacy' on a training dataset. What is the primary trade-off they are managing?

Medium
52

Which THREE items should be included in an 'AI Vendor Assessment'?

Medium
53

Which THREE technical configurations help mitigate the risk of 'Model Exfiltration'?

Hard
54

Which TWO of the following are considered 'AI Supply Chain' risks?

Medium
55

Which TWO factors contribute to 'Model Obsolescence' risk?

Medium
56

Which THREE steps are needed for 'AI Risk Assessment'?

Medium
57

When dealing with 'Adversarial Evasion', why is the 'black-box' nature of an API a risk?

Hard
58

What is the most effective control to prevent 'Model Scraping' from an exposed AI prediction API?

Medium
59

Which of the following describes 'Model Integrity' risk?

Medium
60

You are implementing 'AI Red Teaming'. What is the most effective way to test against prompt injection?

Medium
61

What is 'AI Shadowing' or 'Shadow AI' in an enterprise setting?

Easy
62

Which of the following best describes 'Model Inversion' as a security risk?

Easy

Frequently asked questions

What does the AI Risk Management domain cover on the AAISM exam?
AI Risk Management questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 62 AI Risk Management questions in the AAISM question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only AI Risk Management questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
ISACA Advanced in AI Security Management (AAISM) (AAISM) AI Risk Management Practice Questions