Sample questions
ISACA Advanced in AI Security Management (AAISM) (AAISM) practice questions
An organization is using Google Cloud Vertex AI and suspects an adversarial poisoning attack on a custom training dataset. Which tool should be used to verify the integrity and pro…
Which of these is a 'Proactive' risk management strategy?
What is the primary function of an 'AI Steering Committee'?
Which THREE practices are necessary for managing 'AI Model Version Control' as part of an overall risk management strategy?
What is 'AI Risk Appetite'?
A board of directors requests a summary of AI risk exposure. Which metric provides the most relevant insight into AI security program maturity?
How does 'Continuous Monitoring' differ from 'Point-in-Time Auditing'?
What is the primary role of an 'AI Ethics Board' in an organization's governance structure?
Which THREE factors increase 'AI Model Risk'?
A security manager is integrating AI governance into the existing NIST AI RMF framework. Which action best ensures alignment between AI security controls and business risk appetite…
A machine learning model is showing signs of 'data drift'. What is the most effective initial step in the risk assessment process?
A developer is implementing 'Differential Privacy' on a training dataset. What is the primary trade-off they are managing?
Which TWO of the following are considered 'AI Supply Chain' risks?
What is 'AI Shadowing' or 'Shadow AI' in an enterprise setting?
Which THREE actions should be included in an AI incident response plan?
Which document should define the organization's stance on AI transparency and explainability?
When a model fails in production, what is the first step in the 'Incident Response' process?
Which THREE security controls are effective against 'Data Leakage' in AI?
Which mechanism best ensures 'Auditability' of AI decision-making?
Which THREE criteria are essential for evaluating the risk of an AI vendor's 'Model Card'?
An attacker is performing a 'Model Extraction' attack. What is the most likely goal of the attacker?
A researcher is using 'Adversarial Training' to defend against evasion. How exactly does this work?
Which TWO security controls are recommended for protecting 'Training Data'?
Which THREE steps are needed for 'AI Risk Assessment'?