Summer Sale- Special Discount Limited Time 65% Offer - Ends in 0d 00h 00m 00s - Coupon code: netdisc

Isaca AAISM ISACA Advanced in AI Security Management (AAISM) Exam Exam Practice Test

Page: 1 / 9
Total 90 questions

ISACA Advanced in AI Security Management (AAISM) Exam Questions and Answers

Question 1

An organization recently introduced a generative AI chatbot that can interact with users and answer their queries. Which of the following would BEST mitigate hallucination risk identified by the risk team?

Options:

A.

Performing model testing and validation

B.

Training the foundational model on large data sets

C.

Ensuring model developers have been trained in AI risk

D.

Fine-tuning the foundational model

Question 2

An AI research team is developing a natural language processing model that relies on several open-source libraries. Which of the following is the team’s BEST course of action to ensure the integrity of the software packages used?

Options:

A.

Maintain a list of frequently used libraries to ensure consistent application in projects

B.

Scan the packages and libraries for malware prior to installation

C.

Use the latest version of all libraries from public repositories

D.

Retrain the model regularly to handle package and library updates

Question 3

The PRIMARY benefit of implementing moderation controls in generative AI applications is that it can:

Options:

A.

Increase the model’s ability to generate diverse and creative content

B.

Optimize the model’s response time

C.

Ensure the generated content adheres to privacy regulations

D.

Filter out harmful or inappropriate content

Question 4

From a risk perspective, which of the following is the MOST important step when implementing an adoption strategy for AI systems?

Options:

A.

Benchmarking against peer organizations’ AI risk strategies

B.

Implementing a robust risk analysis methodology tailored to AI-specific tasks

C.

Conducting an AI risk assessment and updating the enterprise risk register

D.

Establishing a comprehensive AI risk assessment framework

Question 5

After implementing a third-party generative AI tool, an organization learns about new regulations related to how organizations use AI. Which of the following would be the BEST justification for the organization to decide not to comply?

Options:

A.

The AI tool is widely used within the industry

B.

The AI tool is regularly audited

C.

The risk is within the organization’s risk appetite

D.

The cost of noncompliance was not determined

Question 6

Which of the following is the MOST important course of action when implementing continuous monitoring and reporting for AI-based systems?

Options:

A.

Establish an automated alert system for threshold breaches in risk metrics

B.

Develop standardized risk reporting templates for different stakeholder groups

C.

Implement real-time monitoring of key risk indicators (KRIs) for AI systems

D.

Implement a risk dashboard for visualizing and tracking AI-related risk over time

Question 7

In the context of generative AI, which of the following would be the MOST likely goal of penetration testing during a red-teaming exercise?

Options:

A.

Generate outputs that are unexpected using adversarial inputs

B.

Stress test the model’s decision-making process

C.

Degrade the model’s performance for existing use cases

D.

Replace the model’s outputs with entirely random content

Question 8

Which of the following key risk indicators (KRIs) is MOST relevant when evaluating the effectiveness of an organization’s AI risk management program?

Options:

A.

Number of AI models deployed into production

B.

Percentage of critical business systems with AI components

C.

Percentage of AI projects in compliance

D.

Number of AI-related training requests submitted

Question 9

An organization has requested a developer to apply AI algorithms to existing modules in order to improve customer service quality. At this stage, which of the following should be considered FIRST?

Options:

A.

The developer may need to be held accountable for business inquiries raised by customers

B.

IT management may need to revise the service agreement if AI behavior cannot be predefined

C.

Project sponsors may need to agree on a phased approach in order to ensure safe release

D.

The organization may need to explain the performance of the applied AI algorithm

Question 10

An automotive manufacturer uses AI-enabled sensors on machinery to monitor variables such as vibration, temperature, and pressure. Which of the following BEST demonstrates how this approach contributes to operational resilience?

Options:

A.

Scheduling repairs for critical equipment based on real-time condition monitoring

B.

Performing regular maintenance based on manufacturer recommendations

C.

Conducting monthly manual reviews of maintenance schedules

D.

Automating equipment repairs without any human intervention

Question 11

Which area of intellectual property law presents the GREATEST challenge in determining copyright protection for AI-generated content?

Options:

A.

Enforcing trademark rights associated with AI systems

B.

Determining the rightful ownership of AI-generated creations

C.

Protecting trade secrets in AI technologies

D.

Establishing licensing frameworks for AI-generated works

Question 12

Which of the following BEST represents a combination of quantitative and qualitative metrics that can be used to comprehensively evaluate AI transparency?

Options:

A.

AI system availability and downtime metrics

B.

AI model complexity and accuracy metrics

C.

AI explainability reports and bias metrics

D.

AI ethical impact and user feedback metrics

Question 13

An organization is updating its vendor arrangements to facilitate the safe adoption of AI technologies. Which of the following would be the PRIMARY challenge in delivering this initiative?

Options:

A.

Failure to adequately assess AI risk

B.

Inability to sufficiently identify shadow AI within the organization

C.

Unwillingness of large AI companies to accept updated terms

D.

Insufficient legal team experience with AI

Question 14

Which of the following is the GREATEST benefit of implementing an AI tool to safeguard sensitive data and prevent unauthorized access?

Options:

A.

Timely analysis of endpoint activities

B.

Timely initiation of incident response

C.

Reduced number of false positives

D.

Reduced need for data classification

Question 15

A large pharmaceutical company using a new AI solution to develop treatment regimens is concerned about potential hallucinations with the introduction of real-world data. Which of the following is MOST likely to reduce this risk?

Options:

A.

Penetration testing

B.

Human-in-the-loop

C.

AI impact analysis

D.

Data asset validation

Question 16

Which of the following is the MOST critical key risk indicator (KRI) for an AI system?

Options:

A.

The accuracy rate of the model

B.

The amount of data in the model

C.

The response time of the model

D.

The rate of drift in the model

Question 17

When integrating AI for innovation, which of the following can BEST help an organization manage security risk?

Options:

A.

Re-evaluating the risk appetite

B.

Seeking third-party advice

C.

Evaluating compliance requirements

D.

Adopting a phased approach

Question 18

Which of the following technologies can be used to manage deepfake risk?

Options:

A.

Systematic data tagging

B.

Multi-factor authentication (MFA)

C.

Blockchain

D.

Adaptive authentication

Question 19

Which of the following is the BEST reason to immediately disable an AI system?

Options:

A.

Excessive model drift

B.

Slow model performance

C.

Overly detailed model outputs

D.

Insufficient model training

Question 20

Which of the following is MOST important to monitor in order to ensure the effectiveness of an organization’s AI vendor management program?

Options:

A.

Vendor compliance with AI-related requirements

B.

Vendor reviews of external AI threat reports

C.

Vendor results in compliance training programs

D.

Vendor participation in industry AI research

Question 21

Which of the following security framework elements BEST helps to safeguard the integrity of outputs generated by AI algorithms?

Options:

A.

Risk exposure due to bias in AI outputs is kept within an acceptable range

B.

Ethical standards are incorporated into security awareness programs

C.

Management is prepared to disclose AI system architecture to stakeholders

D.

Responsibility is defined for legal actions related to AI regulatory requirements

Question 22

An organization plans to apply an AI system to its business, but developers find it difficult to predict system results due to lack of visibility to the inner workings of the AI model. Which of the following is the GREATEST challenge associated with this situation?

Options:

A.

Gaining the trust of end users through explainability and transparency

B.

Assigning a risk owner who is responsible for system uptime and performance

C.

Determining average turnaround time for AI transaction completion

D.

Continuing operations to meet expected AI security requirements

Question 23

In a new supply chain management system, AI models used by participating parties are interactively connected to generate advice in support of management decision making. Which of the following is the GREATEST challenge related to this architecture?

Options:

A.

Establishing clear lines of responsibility for AI model outputs

B.

Identifying hallucinations returned by AI models

C.

Determining the aggregate risk of the system

D.

Explaining the overall benefit of the system to stakeholders

Question 24

Which of the following controls BEST mitigates the inherent limitations of generative AI models?

Options:

A.

Ensuring human oversight

B.

Adopting AI-specific regulations

C.

Classifying and labeling AI systems

D.

Reverse engineering the models

Question 25

Which of the following is the BEST mitigation control for membership inference attacks on AI systems?

Options:

A.

Model ensemble techniques

B.

AI threat modeling

C.

Differential privacy

D.

Cybersecurity-oriented red teaming

Question 26

Which of the following recommendations would BEST help a service provider mitigate the risk of lawsuits arising from generative AI’s access to and use of internet data?

Options:

A.

Activate filtering logic to exclude intellectual property flags

B.

Disclose service provider policies to declare compliance with regulations

C.

Appoint a data steward specialized in AI to strengthen security governance

D.

Review log information that records how data was collected

Question 27

As organizations increasingly rely on vendors to develop AI systems, which of the following is the MOST effective way to monitor vendors and ensure compliance with ethical and security standards?

Options:

A.

Conducting regular audits of vendor processes and adherence to AI development guidelines

B.

Requiring vendors to monitor their adherence to ethics and security standards

C.

Mandating that vendors share source code and AI documentation with the contracting party

D.

Allowing vendors to self-attest ethical AI compliance and implement benchmark monitoring

Page: 1 / 9
Total 90 questions