Winter Sale- Special Discount Limited Time 65% Offer - Ends in 0d 00h 00m 00s - Coupon code: netdisc

Isaca AAIA ISACA Advanced in AI Audit (AAIA) Exam Practice Test

Page: 1 / 18
Total 180 questions

ISACA Advanced in AI Audit (AAIA) Questions and Answers

Question 1

Which of the following AI system characteristics would BEST help an IS auditor evaluate the system's algorithm?

Options:

A.

The AI system algorithm uses training data to inform decision output.

B.

The AI system provides multiple options for model training.

C.

The AI system provides transparent justification of decisions.

D.

The AI system uses archived transaction data to provide decisions.

Question 2

Which of the following controls MOST effectively helps to ensure an AI model is resilient against external threats?

Options:

A.

AI data set anonymization

B.

Monitoring of AI model developers

C.

Monitoring of AI access logs

D.

AI model configuration testing

Question 3

An AI healthcare diagnostic tool requires large volumes of patient data, raising concerns about privacy and data breaches. Which of the following is the MOST effective strategy to mitigate this risk?

Options:

A.

Encrypt the data and transmit it through a secure channel.

B.

Limit the tool's access to only publicly available datasets.

C.

Collect data from all patients to use for data analysis.

D.

Use synthetic data or anonymized data sets for model training.

Question 4

Which of the following strategies used by modelers to enhance data accuracy has the GREATEST risk of bias and information loss?

Options:

A.

Filling blank attributes in records with the mean, median, or mode within a grouping

B.

Identifying and deleting duplicate entries in the data set

C.

Separating multiple data attributes within one field into individual attribute columns

D.

Placing numerical data into bins or buckets for a manageable quantity of correlations and result analyses

Question 5

Which of the following is MOST important to consider when auditing an organization's AI procedures?

Options:

A.

Frequency of AI system updates to enhance security

B.

Employee training on recognized AI best practices

C.

Backup and recovery in the event of an AI data breach

D.

AI data validation and filtration to prevent data poisoning

Question 6

When auditing the transparency of an AI system, which of the following would be the MOST effective way to understand the model's decision-making process?

Options:

A.

Evaluating the diversity of the training data set

B.

Analyzing the complexity of the algorithms used

C.

Assessing the computational cost of the model

D.

Reviewing the explainability of AI outputs

Question 7

Which of the following is the GREATEST concern when an audit team relies on generative AI to create audit reports?

Options:

A.

The reports may be more likely to reflect outdated information.

B.

The reports may contain misstatements resulting from hallucinations.

C.

The reports may use inconsistent formatting from prior audit findings.

D.

The reports may tend to use generic language for audit issues.

Question 8

Which of the following is the PRIMARY purpose of an AI acceptable use policy?

Options:

A.

Establishing guidance on the ethical use of AI

B.

Outlining AI usage monitoring procedures

C.

Educating employees on where to find and how to use AI tools

D.

Explaining the distinction between different types of AI

Question 9

Which of the following is the MOST important risk for an IS auditor to consider when reviewing the adoption of an AI system?

Options:

A.

Costs associated with AI system maintenance

B.

Immaturity of AI systems in the industry

C.

Bias in AI system decision making

D.

Resistance to the use of AI technology

Question 10

An AI tool is being implemented for a regional healthcare organization. Which of the following training methods BEST ensures the AI output does not reveal whether someone's personal data was used?

Options:

A.

Supervised learning with labeled patient records

B.

Data augmentation during training to improve privacy

C.

Differential privacy applied during model training

D.

Transfer learning using public health data sets

Question 11

Which of the following BEST detects model drift or unexpected changes in AI model outputs?

Options:

A.

Standardization of AI configurations

B.

Anomaly monitoring

C.

AI model documentation reviews

D.

AI model retraining

Question 12

From a data appropriateness and bias perspective, which of the following should be of GREATEST concern when reviewing an AI model used in a credit scoring system?

Options:

A.

The model incorporates the applicant's loan history to assess spending habits.

B.

The model utilizes historical credit data to predict future credit behavior.

C.

The model considers the applicant's income level as a key factor in the credit decision.

D.

The model uses postal codes as a primary factor in determining creditworthiness.

Question 13

An organization plans to share customer data collected through an AI system with third-party vendors. Which of the following BEST demonstrates compliance with data privacy principles?

Options:

A.

Including a statement about AI data sharing practices in the company's privacy policy

B.

Obtaining expressed consent from customers before sharing their data

C.

Communicating to customers about AI data sharing practices

D.

Ensuring vendors implement adequate technical safeguards for data protection

Question 14

A healthcare organization uses an AI model to analyze patient data and provide diagnostic recommendations. Which of the following MOST effectively detects data drift related to the model's predictions?

Options:

A.

Comparing incoming patient data distributions with the training data set

B.

Applying overrides to allow healthcare professionals to correct the AI model’s recommendations

C.

Conducting periodic model retraining to ensure alignment with updated patient data

D.

Using adversarial testing to simulate scenarios that stress test the model’s predictions

Question 15

Which of the following presents the GREATEST risk when an organization deploys a machine learning model in a public cloud environment for real-time predictions?

Options:

A.

Cloud provider employees have limited AI skills

B.

AI model audit trails have not been comprehensively documented

C.

The service level agreement (SLA) does not include network latency and inference guarantees

D.

The cloud provider has not adopted an ethical AI governance framework

Question 16

Which of the following controls would MOST effectively mitigate worst-case service disruption scenarios affecting an AI-based application system?

Options:

A.

Performing periodic tabletop exercises

B.

Implementing a kill chain process in the event of disruption

C.

Updating key risk indicators (KRIs) regularly

D.

Including a range of AI disruption scenarios in the disaster recovery plan (DRP)

Question 17

An internal audit department notices that AI-generated audit reports are producing false conclusions. Which of the following is the BEST way to correct this issue?

Options:

A.

Increase the model context.

B.

Suspend utilization of the tool until resolved.

C.

Decrease the model's creativity score.

D.

Update service level agreements (SLAs).

Question 18

In the context of an AI implementation, which of the following actions is MOST critical for an organization's change management program?

Options:

A.

Ensuring the organization has a dedicated AI governance committee

B.

Reviewing documentation for AI system changes, updates, and patches

C.

Conducting a comprehensive risk assessment specific to AI-related changes

D.

Verifying that all employees have completed mandatory AI ethics training

Question 19

Which of the following will provide the BEST evidence to support the alignment of an AI model with an organization's business objectives?

Options:

A.

AI model vulnerability assessment

B.

AI change management requests

C.

AI model inventory

D.

AI acceptable use policy

Question 20

An organization deploys a complex AI model to support credit risk assessments. Stakeholders find the model’s output difficult to interpret. Which of the following BEST improves interpretability?

Options:

A.

Training stakeholders to interpret AI outputs

B.

Implementing a rule-based system to validate the AI model's decisions

C.

Developing documentation and visual tools explaining how the model generates outputs

D.

Reducing the model’s complexity

Question 21

An IS auditor reviews an AI tool using K-means to cluster customers. One cluster shows very high spending but low product diversity. What should the auditor recommend?

Options:

A.

Document the algorithm failed because high spending customers did not exhibit high product diversity.

B.

Treat the cluster as a potentially valid segment of loyal customers with limited product interest.

C.

Increase the number of clusters to better capture variations in spending behavior.

D.

Replace K-means clustering with a supervised learning model for more accurate analysis.

Question 22

During audit planning, an IS auditor reviews the correlation matrix. Which variable pair from an electrical generation facility has the MOST significant correlation?

Options:

A.

Electricity demand and machine torque is 0.0

B.

Daily precipitation and generator efficiency is 0.09

C.

Temperature and generator effectiveness is –0.85

D.

Rotational speed and tool wear is 0.56

Question 23

What should be done FIRST when an AI-powered chatbot starts giving incorrect financial advice after a backend API change?

Options:

A.

Push a patch to improve chatbot response speed.

B.

Add more rules to override the model's output.

C.

Retrain the model with historical and updated data.

D.

Suspend the chatbot and assess the impact.

Question 24

While evaluating a complex machine learning (ML) model used for regulatory compliance in a financial institution, which of the following should the IS auditor do to BEST ensure transparency?

Options:

A.

Document sources and data processes.

B.

Create dashboards to show outputs.

C.

Provide periodic model audit reports.

D.

Use tools that explain model decisions.

Question 25

Which of the following is the PRIMARY objective of AI governance?

Options:

A.

Implementing compliance and ethics controls for AI initiatives

B.

Defining clear roles and responsibilities for AI development, use, and oversight

C.

Ensuring controls over AI are designed well and operate effectively

D.

Promoting a positive return on investment (ROI) from AI projects

Question 26

Which of the following is the MOST important consideration for change management related to the organization-wide adoption of AI systems and tools?

Options:

A.

Direct involvement from organization senior leadership

B.

Implementation of AI-powered systems with shorter user training cycles

C.

Phased implementation and stringent project stage gates

D.

Establishment of organization data governance and infrastructure readiness

Question 27

A car manufacturer uses an AI model to predict maintenance needs for its vehicles. Which of the following techniques can an IS auditor apply to MOST effectively verify the AI model's decisions to stakeholders?

Options:

A.

Using neural network visualization to show how the AI model processes data through its layers

B.

Using K-means algorithms to group vehicles based on mileage or engine temperature for maintenance patterns

C.

Utilizing support vector machines (SVM) to classify vehicles based on maintenance urgency

D.

Using local interpretable model-agnostic explanation (LIME) to analyze how specific features contribute to predictions

Question 28

Which of the following is the MOST important course of action for an organization prior to allowing end users to utilize an AI tool?

Options:

A.

Develop an AI policy with guidelines on appropriate use.

B.

Determine the impact to the disaster recovery plan (DRP).

C.

Implement baseline performance metrics.

D.

Ensure a cybersecurity insurance clause is in place to include the use of AI.

Question 29

An IS auditor is interviewing management about implemented controls around machine learning (ML) models deployed in the production environment. Which of the following schedules for reviewing the performance of a deployed model would be of GREATEST concern to the auditor?

Options:

A.

After changes to hardware and software platforms

B.

After functionality changes

C.

One time prior to migrating to production

D.

On an annual recurring basis

Question 30

An IS auditor uses an internally developed generative AI tool to prepare a status update for audit stakeholders. Which of the following is the auditor’s MOST appropriate course of action?

Options:

A.

Compare results with a publicly available generative AI tool to ensure outputs are similar.

B.

Assess whether the information provided is complete and accurate.

C.

Regenerate the results to ensure similar outputs are provided.

D.

Share and review the results with management.

Question 31

A car rental company is developing an AI system to dynamically adjust rental pricing based on demand, location, and customer profiles. Which of the following is the MOST important reason to conduct specific testing during development?

Options:

A.

To ensure the model’s pricing logic aligns with business strategy

B.

To ensure the system integrates seamlessly with legacy booking platforms

C.

To confirm that the AI system can handle high volumes of customer queries

D.

To verify that pricing decisions do not result in discriminatory outcomes

Question 32

When auditing a machine learning (ML) solution, false positives can BEST be assessed by examining the level of:

Options:

A.

Precision

B.

Completeness

C.

Accuracy

D.

Recall

Question 33

An IS auditor is auditing an organization’s data governance framework. The primary objective is to provide assurance that data management practices are standardized to support a trustworthy AI system. Which of the following should be the auditor's MOST important consideration?

Options:

A.

Retention of stored data

B.

Portability of data

C.

Data practices for training models

D.

Accountability for data management

Question 34

A retail organization uses an AI model to analyze customers' purchase history in order to offer personalized discounts. Which of the following practices represents the MOST ethical use of customer data?

Options:

A.

Utilizing customer purchase data only after obtaining explicit consent and allowing customers to opt out

B.

Retaining and analyzing all available customer data to ensure unbiased recommendations

C.

Providing the public with access to review and audit the data set of collected customer information

D.

Sharing customer purchase data with third-party vendors to improve advertising and communication

Question 35

Which of the following is MOST important to have in place when initially populating data into a data frame for an AI model?

Options:

A.

The box charts, histograms, scatterplots, and Venn diagrams that identify correlations and outliers

B.

The code for separating data into training and testing data sets

C.

An analysis of exploratory data that checks for incorrect data types, null values, and duplicate entries

D.

An approved risk assessment for including, excluding, or subsequently dropping data attributes from the model

Question 36

Which of the following is MOST important to review in order to gain assurance that an AI model is performing without biases?

Options:

A.

AI training data

B.

AI development environment

C.

AI model adaptability

D.

AI model temperature

Question 37

An organization is using a large language model (LLM) to assist in evaluating loan applications, but the training data used is known to be incomplete. Which of the following is the GREATEST associated risk?

Options:

A.

Unfair loan decisions

B.

Delays in loan approval

C.

Reduced customer satisfaction

D.

Increased manual processing of applications

Question 38

Which of the following is the PRIMARY reason IS auditors must be aware that generative AI may return different investment recommendations from the same set of data?

Options:

A.

Limitations can arise in the quantification of risk profiles.

B.

Neural node access varies each time the process is executed.

C.

Computational logic is based on probabilities.

D.

Servers are reconfigured periodically.

Question 39

To confirm the fairness of AI model decisions, the BEST way to collect reliable evidence during an AI audit is by:

Options:

A.

Analyzing system metadata.

B.

Testing the model with a curated sample data set.

C.

Interviewing developers.

D.

Observing the system’s interactions with end users.

Question 40

Which of the following presents the MOST significant barrier to generative AI model explainability?

Options:

A.

Bias within data sets used for model training

B.

Rapid evolution of algorithm capabilities

C.

Lack of alignment between stakeholder groups

D.

Insufficient staff experience with generative AI tools

Question 41

Which of the following would pose the GREATEST risk when reviewing AI acceptable use training content?

Options:

A.

The content does not cover the use of effective prompting.

B.

The content does not cover the non-deterministic nature of AI.

C.

The content does not cover AI model architectures.

D.

The content does not cover required performance metrics.

Question 42

Which of the following is the MOST important reason to perform regular ethical reviews of AI systems?

Options:

A.

To improve the accuracy and performance of the systems

B.

To align AI system development with organizational values and principles

C.

To ensure the systems align with the preservation of individual rights

D.

To identify and mitigate potential data drift within models

Question 43

The GREATEST benefit of using AI auditing techniques over traditional methods is that AI auditing techniques can:

Options:

A.

eliminate the need for human intervention.

B.

ensure full compliance with regulations.

C.

identify complex data patterns.

D.

significantly reduce data bias.

Question 44

An AI social media platform uses an algorithm to increase user engagement that could unintentionally promote divisive content. Which of the following is the BEST course of action to mitigate this risk?

Options:

A.

Introduce controls allowing individuals to customize content preferences.

B.

Suspend the algorithm until concerns are addressed.

C.

Obtain users' consent for the content they wish to view.

D.

Regularly audit and adjust algorithms to reduce biases.

Question 45

A digital bank utilizes an AI system to generate credit scores. Which of the following would BEST mitigate the risk of sudden and unexplained changes in a borrower’s credit score?

Options:

A.

Ensuring the system is periodically reviewed and calibrated by human experts to maintain stability in predictions

B.

Using only data from the last six months to one year to avoid outdated information affecting the credit score

C.

Allowing the AI to operate fully autonomously to prevent processing delays

D.

Obtaining and validating the credit scores from third-party agencies to cross-check AI-generated results

Question 46

Which of the following is the BEST reason that recurrent neural networks enable language translation of documents?

Options:

A.

The process is sequential.

B.

The process uses association rules.

C.

The process is specialized for grid data.

D.

The process is unidirectional.

Question 47

Which of the following is the MOST important task when gathering data during the AI system development process?

Options:

A.

Stratifying the data

B.

Isolating the system

C.

Cleaning the data

D.

Training the system

Question 48

During a risk assessment for an AI system, data drift was identified as a key risk. Which of the following is the BEST course of action?

Options:

A.

Document the risk and implement continuous monitoring.

B.

Retrain the model immediately using the same data set.

C.

Archive the training data and proceed with deployment.

D.

Disable the AI system until risk is eliminated.

Question 49

A healthcare AI tool recommends treatments with high success rates but significant risk. The hospital prioritizes patient safety over innovation. What is the BEST course of action?

Options:

A.

Adjust the AI's parameters to align with the hospital’s risk tolerance.

B.

Discontinue using the AI tool and rely solely on doctor expertise.

C.

Obtain patients' consent for the use of their data by the AI tool.

D.

Use the AI tool only for low-risk situations.

Question 50

An IS auditor is considering the integration of AI techniques into the audit sampling process. Which of the following BEST enables the auditor to identify high-risk transactions within large data sets for targeted sampling?

Options:

A.

Natural language processing (NLP)

B.

Optical character recognition (OCR)

C.

Rule-based analytics

D.

Predictive analytics

Question 51

An IS auditor notes the combined number of records utilized within the training, validation, and testing data sets exceeds the total number of records in the original data set. Which of the following is MOST important for the auditor to determine?

Options:

A.

Whether the training, validation, and testing data sets were created in the correct order

B.

Whether data leakage occurred from utilizing overlapping records in the data sets

C.

Whether a sufficient number of records were utilized in the training data set

D.

Whether the validation data set utilized the same number of records as the training data sets

Question 52

Which of the following should be an IS auditor's GREATEST concern when using a predictive AI tool to analyze data abnormalities?

Options:

A.

The false positives or false negatives generated by the AI tool

B.

The ease of integrating the AI tool with existing data audit software

C.

The speed at which the AI tool processes large data sets

D.

The cost of implementing and maintaining the AI tool for data audit purposes

Question 53

A bank uses a video-based know your customer (KYC) verification process. Cybercriminals exploit this process by using deepfake technology to impersonate bank customers. Which of the following countermeasures is the BEST way for the bank to mitigate this risk?

Options:

A.

Requesting additional identity and address documents for verification

B.

Leveraging AI-based liveness detection during video verification

C.

Encrypting all customer data and communication

D.

Discontinuing the use of the video-based verification process

Question 54

Which of the following types of AI can use unlabeled data sets to imitate human learning behavior?

Options:

A.

Supervised learning

B.

Federated learning

C.

Reinforcement learning

D.

Unsupervised learning

Page: 1 / 18
Total 180 questions