Courseiva
Back to ISACA Advanced in AI Security Management (AAISM) (AAISM) questions

Scenario-based practice

Hard Difficulty Questions

Practise ISACA Advanced in AI Security Management (AAISM) (AAISM) practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

20
scenario questions
AAISM
exam code
ISACA
vendor

Scenario guide

How to approach hard difficulty questions

These are the questions most candidates get wrong. They require connecting multiple concepts, reading tricky output, or knowing edge-case behaviour that isn't on most study cards. Practising them trains you to operate under uncertainty — a necessary skill on the real exam.

Quick answer

Hard Difficulty Questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Related practice questions

Related AAISM topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1hardmultiple choice
Full question →

An organization is using Google Cloud Vertex AI and suspects an adversarial poisoning attack on a custom training dataset. Which tool should be used to verify the integrity and provenance of the training artifacts?

Question 2hardmulti select
Full question →

Which THREE practices are necessary for managing 'AI Model Version Control' as part of an overall risk management strategy?

Question 3hardmultiple choice
Full question →

How does 'Continuous Monitoring' differ from 'Point-in-Time Auditing'?

Question 4hardmulti select
Full question →

Which THREE factors increase 'AI Model Risk'?

Question 5hardmulti select
Full question →

Which THREE security controls are effective against 'Data Leakage' in AI?

Question 6hardmultiple choice
Full question →

An attacker is performing a 'Model Extraction' attack. What is the most likely goal of the attacker?

Question 7hardmultiple choice
Full question →

A researcher is using 'Adversarial Training' to defend against evasion. How exactly does this work?

Question 8hardmultiple choice
Full question →

You are assessing the risk of 'Data Poisoning'. Which stage of the machine learning lifecycle is most vulnerable to this attack?

Question 9hardmulti select
Full question →

Which THREE documents are vital for an AI audit trail?

Question 10hardmulti select
Full question →

Which THREE items should be included in an 'AI Inventory'?

Question 11hardmulti select
Full question →

Which THREE components are critical for an 'AI Incident Response' plan?

Question 12hardmultiple choice
Full question →

An organization is performing threat modeling for a RAG (Retrieval-Augmented Generation) pipeline. Which specific vulnerability is unique to the retrieval component?

Question 13hardmulti select
Full question →

Which THREE elements are essential for 'AI Governance'?

Question 14hardmultiple choice
Full question →

What is 'Model Stealing' and why is it considered a security incident?

Question 15hardmultiple choice
Full question →

What is the 'Membership Inference' attack in machine learning?

Question 16hardmulti select
Full question →

Which THREE factors must be included in a 'Model Risk Management' (MRM) policy?

Question 17hardmulti select
Full question →

Which THREE technical controls effectively manage 'Third-Party AI Vendor' risks?

Question 18hardmulti select
Full question →

When establishing a risk management framework for GenAI, which THREE factors should be prioritized to satisfy the NIST AI Risk Management Framework requirements?

Question 19hardmultiple choice
Full question →

You are auditing an AI system for 'Model Explainability' (XAI). Why is XAI critical from a risk management perspective?

Question 20hardmultiple choice
Full question →

Which of the following describes the purpose of 'Differential Privacy' in a machine learning system?

These AAISM practice questions are part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style AAISM questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.