Isaca AAIR Practice Test Questions and Exam Dumps Part14 Q261-280

View Full Isaca AAIR Exam Dumps and Practice Test Dumps.


Q261. An organization has defined several AI risk policies, but employees are uncertain which policy applies when a system combines predictive analytics with generative AI. What should the AI risk function do FIRST?

  1. Clarify policy scope, applicability, and decision criteria for overlapping AI capabilities
    2. Require employees to choose whichever policy seems most relevant
    3. Remove all AI-specific policies
    4. Apply only the oldest approved policy

Correct Answer: 1. Clarify policy scope, applicability, and decision criteria for overlapping AI capabilities

Explanation: Policies should provide enough clarity for stakeholders to determine which requirements apply to hybrid or complex AI systems. When several technologies are combined, overlapping governance requirements may apply simultaneously. The risk function should define scope, precedence, and escalation criteria so teams do not interpret obligations inconsistently. Removing AI-specific policies would create a governance gap, while leaving employees to make ad hoc decisions can result in inconsistent treatment of similar risks. Clear applicability guidance supports consistent compliance, accountability, control selection, and lifecycle governance as AI systems increasingly combine multiple models and capabilities.

Q262. An executive sponsor wants to approve a high-risk AI application even though the designated risk owner has not reviewed the residual risk. What is the BEST response?

  1. Deploy because executive sponsorship overrides risk ownership
    2. Remove the residual-risk assessment
    3. Ask the development team to accept the risk
    4. Require the designated risk acceptance process to be completed by the appropriate authorized owner**

Correct Answer: 4. Require the designated risk acceptance process to be completed by the appropriate authorized owner

Explanation: Executive sponsorship does not automatically replace the organization’s established risk-accountability structure. Material residual risk should be reviewed and accepted by the individual or governance body authorized to assume that exposure. This preserves clear accountability and ensures the decision is based on documented risk information rather than project urgency or sponsorship alone. If the exposure exceeds the risk owner’s authority, escalation may be required. Allowing development teams or sponsors to bypass formal acceptance weakens governance and can result in significant AI risks being deployed without informed business ownership.

Q263. An AI system is used in several business units, but each unit has assigned a different business owner. What governance issue should be addressed?

  1. Whether the model has sufficient computing capacity
    2. Establishing clear enterprise accountability for shared AI assets and local use-case responsibilities
    3. Whether all users have identical job titles
    4. Whether the model is hosted internally

Correct Answer: 2. Establishing clear enterprise accountability for shared AI assets and local use-case responsibilities

Explanation: Shared AI assets can create ambiguous accountability when different business units use the same system for different purposes. Governance should distinguish enterprise-level ownership of the model or platform from accountability for each local use case. The organization should define who owns core model risk, who approves changes, who monitors shared controls, and who accepts risks associated with individual implementations. Without this structure, important activities can be duplicated or overlooked. Clear ownership is especially important when one model change can affect several processes or business units simultaneously.

Q264. An organization plans to use AI-generated content in communications to customers. Which governance control is MOST appropriate when inaccurate statements could create legal exposure?

  1. Increase model temperature to create more varied responses
    2. Allow the model to publish directly to improve speed
    3. Establish content-validation and approval requirements proportionate to the legal impact
    4. Remove customer communication records after publication

Correct Answer: 3. Establish content-validation and approval requirements proportionate to the legal impact

Explanation: Generative AI can produce plausible but inaccurate statements, so customer-facing content with legal or regulatory implications should be subject to controls that reflect the potential consequence of error. Depending on the use case, this may include approved templates, source grounding, deterministic checks, human review, or restricted topics. The organization should also retain appropriate evidence of what was published. Increasing creativity may raise rather than reduce variability. AI can improve communication efficiency, but accountability for legally significant statements should remain within approved business processes.

Q265. An organization wants to use public web data for AI model training. What should be evaluated BEFORE concluding that publicly accessible data is safe to use?

  1. Only whether the website requires a password
    2. Whether the dataset is technically easy to collect
    3. Whether the model requires more examples
    4. Legal rights, privacy expectations, terms of use, provenance, and intended processing**

Correct Answer: 4. Legal rights, privacy expectations, terms of use, provenance, and intended processing

Explanation: Public availability does not automatically mean unrestricted permission for AI training. Information may still be subject to copyright, contractual terms, privacy obligations, database rights, or reasonable expectations about how it will be used. The organization should understand the source, collection method, permitted uses, affected individuals, and applicable legal requirements before incorporating the data into a training pipeline. Provenance should also be retained so data can later be reviewed or removed when necessary. Technical accessibility is not equivalent to legal or ethical authorization.

Q266. A predictive model is trained using historical data from a period when business practices were substantially different from today. What should the risk professional be MOST concerned about?

  1. Whether the data file is compressed
    2. Whether the historical data remains representative of the current operating environment
    3. Whether the model uses enough servers
    4. Whether the model is open source

Correct Answer: 2. Whether the historical data remains representative of the current operating environment

Explanation: Historical data can become inappropriate when customer behavior, regulations, products, economic conditions, or business processes change. A model trained on an outdated environment may reproduce patterns that no longer apply and may perform poorly or unfairly in current conditions. The organization should assess representativeness, temporal drift, data quality, and relevance before relying on older records. If significant differences exist, additional recent data, weighting, model redesign, or use restrictions may be needed. Dataset size alone does not establish fitness for purpose.

Q267. A model is intended to recommend maintenance actions for industrial equipment. Which validation evidence provides the STRONGEST assurance before deployment?

  1. Testing against representative real-world failure modes and operating conditions
    2. A statement from developers that the model is ready
    3. High performance on unrelated public benchmarks
    4. The model’s large parameter count

Correct Answer: 1. Testing against representative real-world failure modes and operating conditions

Explanation: Validation should reflect the actual business environment and the consequences of incorrect recommendations. For industrial maintenance, representative tests should include realistic equipment states, known failure modes, edge cases, and relevant operational conditions. Public benchmarks may provide supplemental evidence but do not necessarily prove suitability for the specific equipment and process. High-impact applications require validation that connects model performance directly to intended use. The evidence should also identify limitations and conditions under which human review or alternative procedures are required.

Q268. An AI system performs consistently during normal usage but begins producing incorrect results when upstream data arrives late. Which lifecycle control is MOST appropriate?

  1. Ignore data-delivery timing because model accuracy was previously validated
    2. Retrain the model every time a feed is delayed
    3. Define input freshness requirements and fail-safe behavior for stale or delayed data
    4. Increase user access privileges

Correct Answer: 3. Define input freshness requirements and fail-safe behavior for stale or delayed data

Explanation: AI systems depend not only on data values but also on data timeliness. If stale inputs can create incorrect decisions, the system should validate freshness and define what happens when required data is delayed. Appropriate responses might include rejecting the prediction, using a fallback process, notifying an operator, or clearly flagging uncertainty. Retraining does not address a data-delivery problem. Monitoring input quality and operational dependencies throughout the lifecycle helps ensure the model continues to operate under the assumptions validated during development.

Q269. A risk assessment team wants to identify AI scenarios that could produce severe impact despite having very low historical frequency. Which approach is MOST appropriate?

  1. Exclude scenarios without internal loss history
    2. Use scenario analysis that includes low-frequency, high-impact events
    3. Assign zero likelihood whenever data is unavailable
    4. Evaluate only routine operating failures

Correct Answer: 2. Use scenario analysis that includes low-frequency, high-impact events

Explanation: Emerging AI risks may have limited historical data but still warrant attention because their consequences could be severe. Scenario analysis allows experts to examine plausible low-frequency events, document assumptions, assess potential consequences, and determine whether controls or contingency plans are justified. Treating the absence of historical incidents as proof of negligible risk can produce significant blind spots. Risk assessment should combine available evidence with expert judgment, external events, threat intelligence, and uncertainty analysis when reliable internal statistics do not yet exist.

Q270. An AI system has numerous safeguards, but management cannot determine which control reduces which risk. What should be done?

  1. Add more controls until coverage is obvious
    2. Remove all controls and redesign from the beginning
    3. Assume every control reduces every AI risk
    4. Map controls to specific risk scenarios, objectives, and expected risk-reduction effects**

Correct Answer: 4. Map controls to specific risk scenarios, objectives, and expected risk-reduction effects

Explanation: Controls should be traceable to the risks they are intended to address. Mapping helps management understand whether safeguards reduce likelihood, reduce impact, improve detection, or support recovery. It also identifies gaps, duplication, and dependencies among controls. Without this relationship, residual-risk assessments can become arbitrary because management cannot explain why exposure should be lower after controls are applied. Control mapping supports testing, rationalization, reporting, and risk-treatment decisions and makes it easier to determine whether the control environment remains adequate as AI systems evolve.

Q271. An organization considers eliminating a manual review control because automated validation now catches most errors. What should it do FIRST?

  1. Evaluate whether automated controls provide equivalent or better coverage for the relevant risk
    2. Remove the manual control immediately to reduce cost
    3. Assume automation is always more reliable
    4. Ignore the residual-risk impact

Correct Answer: 1. Evaluate whether automated controls provide equivalent or better coverage for the relevant risk

Explanation: Control changes should be assessed according to their effect on residual risk. Automated validation may improve consistency and efficiency, but the organization should determine whether it covers all important failure modes addressed by the manual review. Human reviewers may consider contextual or qualitative factors that deterministic automation does not capture. Conversely, automation may provide stronger coverage for repetitive checks. Evidence-based comparison helps management rationalize controls without unintentionally creating gaps. Any resulting change should be documented and monitored to confirm expected effectiveness.

Q272. A risk treatment plan reduces a model’s error rate but significantly increases decision latency beyond business tolerance. What should management do?

  1. Ignore latency because risk was reduced
    2. Evaluate the treatment’s overall business impact and determine whether an alternative control is required
    3. Automatically accept slower performance
    4. Remove the original risk from the register

Correct Answer: 3. Evaluate the treatment’s overall business impact and determine whether an alternative control is required

Explanation: Risk treatments can introduce new risks or operational costs. A control that improves accuracy but makes a critical service unusably slow may not represent an acceptable overall solution. Management should assess tradeoffs across risk, performance, customer impact, cost, and strategic objectives and determine whether another treatment can achieve adequate risk reduction without violating business requirements. Controls should be evaluated holistically rather than assuming that any reduction in one risk dimension is automatically beneficial overall.

Q273. A KRI shows that model overrides by human reviewers are increasing steadily. What should the organization investigate?

  1. Whether the trend indicates model quality deterioration, changing conditions, or inappropriate decision thresholds
    2. Whether reviewers can be prevented from overriding the model
    3. Whether the KRI should be removed
    4. Whether risk tolerance should automatically be increased

Correct Answer: 1. Whether the trend indicates model quality deterioration, changing conditions, or inappropriate decision thresholds

Explanation: Increasing override rates can be an important signal that the model’s recommendations no longer align with real-world conditions or reviewer expectations. The cause might include model drift, data changes, policy changes, poor calibration, or a threshold that routes inappropriate cases to automation. Overrides should be monitored and analyzed rather than discouraged automatically. If reviewers consistently correct the model, the organization may need to retrain, recalibrate, restrict, or redesign the system. The KRI provides value when it prompts investigation and improvement.

Q274. An executive dashboard reports residual AI risk as a single score but does not show whether the score is within approved tolerance. What should be added?

  1. More technical model parameters
    2. Clear comparison to risk appetite or tolerance thresholds and required actions
    3. Vendor marketing rankings
    4. Raw source code

Correct Answer: 2. Clear comparison to risk appetite or tolerance thresholds and required actions

Explanation: A risk score is difficult to interpret without context. Management needs to know whether current exposure is acceptable, approaching a limit, or outside authorized tolerance. Dashboards should therefore show threshold status, material trends, drivers, ownership, and actions where appropriate. This enables risk information to support decisions rather than merely describe conditions. Technical details can remain available to operational teams, while executives need concise information that connects risk metrics to enterprise governance and required management response.

Q275. A third-party AI provider relies heavily on one proprietary dataset owned by another company. What risk should the customer assess?

  1. Employee scheduling risk
    2. Only model latency
    3. Upstream data dependency, licensing, continuity, and supply-chain risk
    4. Office security risk only

Correct Answer: 4. Upstream data dependency, licensing, continuity, and supply-chain risk

Explanation: AI providers may depend on datasets they do not own. If access to that dataset is revoked, licensing terms change, quality deteriorates, or legal disputes arise, the provider’s model may be affected. Customers should understand material upstream dependencies and determine whether those dependencies could affect continuity, legality, quality, or model behavior. The direct vendor may have good controls while still relying on fragile upstream resources. Supply-chain assessment should therefore extend beyond immediate suppliers when dependencies are material to the service.

Q276. A critical AI vendor uses an externally hosted foundation model that can change without the vendor’s direct control. What should the customer require?

  1. Visibility into material dependency changes and appropriate impact assessment
    2. A guarantee that no external provider will ever change
    3. Removal of all vendor monitoring
    4. Unlimited use of customer data for model training

Correct Answer: 3. Visibility into material dependency changes and appropriate impact assessment

Explanation: When a vendor depends on external foundation models, changes by the upstream provider can affect the service’s behavior, security, compliance, or performance. Customers should seek appropriate visibility into material changes and understand how the vendor validates updates before they affect downstream users. Contracts and supplier governance may address notification, testing, rollback, and subcontractor management. It may not be feasible to guarantee that an external model never changes, so the focus should be on managing and communicating the resulting lifecycle risk.

Q277. An AI incident is initially classified as low severity, but investigators later discover affected decisions involving thousands of customers. What should happen?

  1. Keep the original severity because incident classifications cannot change
    2. Reassess and escalate severity based on the expanded impact
    3. Close the incident before changing classification
    4. Remove customer impact from the assessment

Correct Answer: 2. Reassess and escalate severity based on the expanded impact

Explanation: Incident classification should reflect the best current understanding of scope and consequence. Early information is often incomplete, so severity should be updated when new evidence shows greater customer, regulatory, financial, safety, or operational impact. Escalation can trigger additional response resources, communications, legal review, and notification obligations. A static classification process can delay appropriate action as an incident evolves. Incident procedures should therefore support reassessment as facts become clearer.

Q278. A business continuity plan assumes employees can perform an AI-supported task manually, but no employees have performed the manual process in two years. What is the BEST action?

  1. Test and refresh the manual procedure and required staff capability
    2. Assume employees will remember the process during an outage
    3. Remove the fallback from the plan without replacement
    4. Increase the AI system’s model size

Correct Answer: 1. Test and refresh the manual procedure and required staff capability

Explanation: A fallback procedure is useful only if it can actually be executed when needed. Skills can deteriorate as organizations rely increasingly on automation, and supporting documentation may become outdated. Continuity exercises should test whether employees can perform the process, whether required systems and data remain available, and whether fallback capacity meets minimum business requirements. Training or updated procedures may be needed. Untested manual fallback creates false confidence and can fail at the exact time the AI service is unavailable.

Q279. An AI disaster recovery test restores the correct model but fails because the feature-generation pipeline is unavailable. What does this demonstrate?

  1. Recovery planning overlooked a critical dependency required for usable AI outputs
    2. The model itself should be deleted
    3. Feature pipelines are unrelated to AI recovery
    4. RTO should automatically be increased

Correct Answer: 3. Recovery planning overlooked a critical dependency required for usable AI outputs

Explanation: AI services depend on more than the model artifact. Feature pipelines, source data, APIs, authentication, infrastructure, configuration, and other services can all be necessary to produce valid outputs. Recovery testing should verify the entire end-to-end service rather than whether individual components can be restored independently. Discovering a missing dependency during a test is valuable because the organization can update BIA, recovery sequencing, backup arrangements, and technical architecture before a real incident occurs.

Q280. An organization uses AI to identify potential new enterprise risks from external news and internal data. What is the BEST use of the AI-generated results?

  1. Automatically add every suggested risk to the enterprise risk register
    2. Replace all risk workshops with the AI system
    3. Ignore existing risk taxonomy
    4. Use the suggestions as inputs for professional review, validation, and risk assessment**

Correct Answer: 4. Use the suggestions as inputs for professional review, validation, and risk assessment

Explanation: AI can assist risk professionals by scanning large volumes of information and identifying possible emerging risks, patterns, and scenarios. However, generated suggestions may be irrelevant, duplicate existing risks, or lack organizational context. Qualified professionals should validate the evidence, map credible scenarios to the approved taxonomy, assess likelihood and impact, and determine whether the risk merits formal inclusion. This approach captures AI’s analytical value while retaining human accountability for enterprise risk decisions and official governance records.