IAPP AIGP Practice Test Questions and Exam Dumps Part 19 Q361-380

View Full IAPP AIGP Exam Dumps and Practice Test Dumps.

 

Question 361

What is the primary purpose of conducting a disparate impact analysis for an AI system?

  1. To determine whether the system requires more computing resources.
  2. To identify whether the system may produce disproportionately adverse outcomes for certain groups.
  3. To determine the model’s storage capacity.
  4. To eliminate the need for human oversight.

Correct Answer: 2

Explanation

A disparate impact analysis helps an organization examine whether an AI system may produce disproportionately adverse outcomes for a particular group, even when the system does not explicitly use a protected characteristic. This type of assessment can reveal differences in selection rates, error rates, approval rates, or other relevant outcomes across groups. The analysis should be interpreted within the context of the AI system’s purpose and the applicable governance requirements. Finding a disparity does not automatically establish unlawful discrimination or identify its cause, so additional investigation may be necessary. Organizations can use the results to determine whether changes to data, models, thresholds, processes, or human oversight are appropriate.

Question 362

Why should fairness evaluation be performed using data that reflects the intended deployment population?

  1. Because deployment populations have no effect on model performance.
  2. Because representative evaluation can reveal performance differences that may otherwise remain hidden.
  3. Because representative data guarantees perfect fairness.
  4. Because only production data can be used for testing.

Correct Answer: 2

Explanation

Fairness evaluation is more informative when the evaluation data reasonably reflects the population and conditions in which the AI system will operate. If important groups or use cases are missing from the evaluation dataset, the organization may fail to identify performance differences that appear after deployment. Representative evaluation can help reveal differences in error rates, outcomes, or other relevant measures across groups. However, representative data does not guarantee fairness because bias can exist in the labels, model design, decision process, or deployment environment. Evaluation should therefore be combined with other governance controls, including subgroup analysis, monitoring, documentation, and appropriate human oversight.

Question 363

What is a potential risk of excluding sensitive demographic attributes from fairness testing?

  1. The organization may lose the ability to detect certain disparities.
  2. The AI model will automatically become more accurate.
  3. The system will always comply with applicable requirements.
  4. Bias testing becomes unnecessary.

Correct Answer: 1

Explanation

Sensitive demographic attributes may need to be restricted from inappropriate model use, but they can still be valuable for controlled fairness evaluation. If organizations remove all information about demographic groups from testing, they may lose the ability to compare outcomes across those groups and detect potential disparities. Governance teams should distinguish between using sensitive information for an appropriate evaluation purpose and allowing the AI system to use that information in an inappropriate decision process. Access to such information should itself be governed through suitable privacy and security controls. Carefully designed testing can help organizations identify problems while limiting unnecessary exposure of sensitive information.

Question 364

Which statement best describes a fairness-accuracy trade-off in AI governance?

  1. Improving fairness always reduces accuracy.
  2. Improving accuracy always eliminates fairness concerns.
  3. Changes intended to improve one performance objective can sometimes affect other objectives and should be evaluated in context.
  4. Fairness and accuracy can never be evaluated together.

Correct Answer: 3

Explanation

AI governance sometimes involves balancing multiple objectives, including accuracy, fairness, robustness, explainability, and operational performance. A change that improves outcomes for one group may alter overall accuracy or affect another subgroup. Conversely, optimizing overall accuracy can sometimes preserve or increase disparities between groups. These relationships are not universal, so organizations should avoid assuming that fairness always requires sacrificing accuracy. Instead, teams should evaluate the relevant trade-offs in the context of the intended use, affected individuals, risk level, and applicable requirements. Governance decisions should document the evidence considered and explain why the selected approach is appropriate for the specific deployment.

Question 365

What should an organization do when a fairness metric is difficult to interpret for a particular AI use case?

  1. Treat the metric as automatically decisive.
  2. Ignore all fairness considerations.
  3. Examine whether the metric is appropriate for the context and supplement it with other evidence where necessary.
  4. Deploy the system without testing.

Correct Answer: 3

Explanation

Fairness metrics are useful only when they meaningfully relate to the system’s purpose and potential harms. A metric that is appropriate for one application may be less informative for another. Organizations should therefore understand what a metric measures, what assumptions it makes, and what it may fail to capture. If a metric provides an incomplete picture, teams can supplement it with other quantitative measures, qualitative analysis, stakeholder input, and review of actual operational outcomes. The goal is not simply to achieve a favorable numerical result but to understand whether the system is producing acceptable outcomes in its intended context. This supports more defensible and risk-based governance decisions.

Question 366

Why should organizations monitor AI systems for changes in subgroup performance after deployment?

  1. Because subgroup performance can change as data and operating conditions change.
  2. Because fairness is permanently established after initial testing.
  3. Because monitoring eliminates all model risks.
  4. Because only technical failures matter after deployment.

Correct Answer: 1

Explanation

An AI system’s performance can change after deployment as user behavior, data distributions, business processes, or external conditions evolve. These changes may affect demographic groups differently. A system that showed acceptable subgroup performance during pre-deployment testing may therefore develop disparities later. Monitoring relevant performance measures can help organizations identify these changes and investigate their causes. Depending on the findings, corrective action may include retraining, recalibration, changes to thresholds, additional human review, or restricting the system’s use. Ongoing monitoring is particularly important for higher-impact applications because the consequences of emerging disparities may be significant. Initial testing should be treated as a baseline rather than a permanent guarantee.

Question 367

What is the main governance concern when an AI system uses a proxy variable for a protected characteristic?

  1. The proxy can indirectly influence outcomes in ways that create or reinforce disparities.
  2. Proxy variables always make models computationally slower.
  3. Proxy variables are prohibited in every AI system.
  4. Proxy variables guarantee accurate predictions.

Correct Answer: 1

Explanation

A proxy variable can be correlated with a protected characteristic and may indirectly reproduce patterns that an organization intended to avoid. For example, a variable related to location or historical behavior might reflect demographic differences even when the protected characteristic itself is excluded. This creates a governance concern because simply removing the protected field may not prevent unequal outcomes. Organizations should examine relevant features, assess subgroup outcomes, and consider whether the variable is necessary and appropriate for the intended purpose. If a proxy contributes materially to harmful disparities, mitigation may be appropriate. The presence of a proxy does not automatically prove wrongdoing, but it warrants careful risk assessment and contextual analysis.

Question 368

Which control is most appropriate when an AI system is used to recommend candidates for employment?

  1. Allowing recruiters to accept every recommendation automatically.
  2. Providing trained human reviewers with sufficient information and authority to evaluate recommendations.
  3. Disabling documentation of recruitment decisions.
  4. Preventing candidates from raising concerns about the process.

Correct Answer: 2

Explanation

AI-supported employment processes can significantly affect individuals, so meaningful human oversight is an important governance control. Human reviewers should understand the AI system’s role, receive appropriate training, and have enough authority to question or override recommendations when warranted. Organizations should also establish criteria for escalation and document relevant decisions. Simply requiring a person to click an approval button is not meaningful oversight if the reviewer lacks information or practical authority to challenge the AI output. Appropriate governance may also include fairness testing, transparency, accessibility, data-quality controls, and monitoring. The objective is to ensure that AI recommendations support responsible decision-making rather than becoming unquestioned substitutes for human judgment.

Question 369

What is a key risk of using historical hiring data to train an AI recruitment model?

  1. Historical data may reproduce past biases or unequal practices.
  2. Historical data is always unbiased.
  3. Historical data cannot contain useful information.
  4. Historical data automatically guarantees representative outcomes.

Correct Answer: 1

Explanation

Historical hiring data reflects decisions and practices from the period in which it was collected. If those practices contained bias, unequal access, inconsistent evaluation, or other structural problems, an AI model trained on that data may learn patterns associated with those outcomes. The resulting system could reproduce or amplify existing disparities even if sensitive characteristics are not directly included. Organizations should therefore assess the provenance, quality, representativeness, labeling, and historical context of training data. They should also conduct appropriate subgroup testing before deployment. Historical data can provide useful information, but it should not automatically be treated as an objective description of what future decisions ought to be.

Question 370

Why is accessibility testing important for AI systems used by the public?

  1. It helps determine whether people with different accessibility needs can meaningfully use the system.
  2. It guarantees that the AI model is unbiased.
  3. It eliminates the need for security testing.
  4. It ensures that every user receives the same result.

Correct Answer: 1

Explanation

Public-facing AI systems may serve people with a wide range of abilities and interaction needs. Accessibility testing helps identify barriers that could prevent some users from accessing information, submitting requests, understanding outputs, or completing important tasks. Testing can involve different assistive technologies, input methods, communication formats, and user needs. Accessibility is separate from model accuracy and fairness, although it can contribute to equitable access to an AI-enabled service. Organizations should consider accessibility during design and testing rather than attempting to fix barriers only after deployment. Appropriate accessibility controls can help ensure that AI systems are usable by a broader population and that people are not excluded because of interface or interaction limitations.

Question 371

What is the purpose of establishing a clear intended-use statement for an AI system?

  1. To define the approved purpose and boundaries within which the system is expected to operate.
  2. To guarantee that users cannot make mistakes.
  3. To allow unlimited reuse of the system.
  4. To eliminate the need for risk assessment.

Correct Answer: 1

Explanation

An intended-use statement defines what an AI system is designed and approved to do. It can describe the business purpose, target users, relevant inputs, expected outputs, and important limitations or restrictions. This provides a baseline for governance because testing, risk assessment, monitoring, and approval decisions can be evaluated against the documented purpose. If users begin applying the system to a materially different purpose, the organization can determine whether additional assessment or approval is necessary. An intended-use statement does not prevent every misuse, but it establishes a clear boundary for responsible operation. It also supports communication between developers, business users, risk teams, and governance stakeholders.

Question 372

What should happen when an AI system is proposed for a materially different purpose than its approved intended use?

  1. The new use should be assessed to determine whether additional risk evaluation or approval is required.
  2. The new use should automatically be approved.
  3. Existing documentation should be deleted.
  4. Monitoring should be disabled.

Correct Answer: 1

Explanation

A material change in intended use can alter the system’s risks, affected populations, data requirements, performance expectations, and applicable controls. An AI system approved for one purpose may therefore not be appropriate for another purpose without additional evaluation. Organizations should assess the proposed change against their governance framework and determine whether updated risk assessments, testing, privacy reviews, fairness analysis, security controls, or approval are necessary. This does not mean every minor operational adjustment requires a completely new governance process. Instead, the organization should apply a risk-based change assessment. Documenting the decision creates traceability and helps ensure that important changes do not bypass established governance controls.

Question 373

What is the purpose of maintaining a record of AI system versions?

  1. To identify which version was used when a particular outcome or incident occurred.
  2. To prevent all future model changes.
  3. To eliminate the need for testing.
  4. To ensure every model version has identical performance.

Correct Answer: 1

Explanation

Version records provide traceability across the AI lifecycle. Organizations may need to determine which model, configuration, prompt, dataset, software dependency, or other relevant artifact was active when a particular decision, output, or incident occurred. Without version information, investigating an unexpected result can become difficult because the system may have changed since the event. Version records can support incident investigation, rollback, audit activities, reproducibility, and change management. They do not prevent changes from occurring and cannot guarantee identical performance between versions. A strong governance process should connect version records with approval decisions, testing evidence, deployment dates, and relevant changes so that teams can understand the history of the system.

Question 374

What is a key benefit of conducting impact assessments before deploying a high-risk AI system?

  1. They help identify potential effects on individuals and determine appropriate safeguards before deployment.
  2. They guarantee that no incidents will occur.
  3. They remove the need for technical testing.
  4. They allow the organization to avoid documenting risks.

Correct Answer: 1

Explanation

An impact assessment provides a structured opportunity to examine how an AI system may affect individuals, groups, organizations, or other stakeholders before deployment. Depending on the system, the assessment may consider privacy, fairness, security, safety, accessibility, human rights, operational, or other relevant impacts. Identifying risks early gives the organization an opportunity to introduce safeguards before problems occur in production. An assessment cannot guarantee that incidents or harmful outcomes will never happen, and it does not replace technical testing. Instead, it complements technical and operational evaluation by considering the broader consequences of the system. The results can inform deployment decisions, mitigation measures, monitoring requirements, and human oversight.

Question 375

Which practice best supports reproducibility of an AI evaluation?

  1. Changing the evaluation dataset after every test without documentation.
  2. Recording relevant model versions, datasets, configurations, and evaluation procedures.
  3. Avoiding all documentation of test conditions.
  4. Running tests only once and discarding the results.

Correct Answer: 2

Explanation

Reproducibility requires enough information for an organization to understand and, where practical, repeat an evaluation under comparable conditions. Relevant records may include the model version, dataset version, evaluation methodology, configuration parameters, software dependencies, prompts, thresholds, and other factors that could affect results. Without this information, teams may struggle to determine whether a change in results reflects a model update, data change, environment difference, or methodological variation. Reproducibility is especially valuable for high-impact systems because it supports validation, auditability, incident investigation, and change management. It does not necessarily require every execution to produce identical results, particularly for stochastic systems, but it does require disciplined documentation of evaluation conditions.

Question 376

What is the primary purpose of adversarial testing for an AI system?

  1. To intentionally probe the system for weaknesses, unexpected behavior, or exploitable conditions.
  2. To guarantee that the system cannot be attacked.
  3. To replace all normal functional testing.
  4. To increase the model’s training dataset automatically.

Correct Answer: 1

Explanation

Adversarial testing intentionally challenges an AI system to identify weaknesses that may not appear during ordinary testing. Depending on the system, testers may examine prompt manipulation, unsafe inputs, unexpected combinations of inputs, unauthorized actions, data leakage, model robustness, or other attack scenarios. The purpose is to discover weaknesses so they can be addressed before or during deployment. Successful adversarial testing does not guarantee that the system is immune to future attacks because threats and system conditions can change. It should therefore complement other security and quality practices such as threat modeling, vulnerability management, access controls, monitoring, and incident response. Findings should be documented and prioritized according to risk.

Question 377

What is the purpose of threat modeling for an AI system?

  1. To identify potential threats, attack paths, assets, and security controls before or during system development.
  2. To determine the marketing budget for the AI product.
  3. To guarantee perfect model accuracy.
  4. To remove the need for security monitoring.

Correct Answer: 1

Explanation

Threat modeling provides a structured way to identify how an AI system could be attacked or misused and what assets or processes could be affected. Teams may consider threats involving data, models, APIs, identities, prompts, external tools, infrastructure, or downstream systems. The results can guide security controls and testing priorities. For example, a system with access to sensitive information may require stronger authorization and retrieval controls than a low-risk public chatbot. Threat modeling does not guarantee that every attack will be prevented and does not replace monitoring or incident response. Its value comes from identifying plausible threats early and helping organizations prioritize safeguards based on the system’s architecture and risk profile.

Question 378

Why should AI development pipelines include controls for software and model dependencies?

  1. Dependencies can introduce vulnerabilities, unexpected changes, or supply-chain risks.
  2. Dependencies never affect AI systems.
  3. Dependency controls guarantee perfect model performance.
  4. Dependencies only matter after system retirement.

Correct Answer: 1

Explanation

AI systems often depend on libraries, frameworks, model components, packages, APIs, containers, and other third-party artifacts. A vulnerability or unauthorized change in one of these dependencies can affect the security or reliability of the broader system. Dependency management can include maintaining inventories, monitoring for vulnerabilities, controlling versions, reviewing sources, and testing updates before production use. These practices support software and AI supply-chain security. Dependency controls do not guarantee that a system will perform perfectly, but they reduce the likelihood that unmanaged external components introduce avoidable risks. Strong governance also helps organizations identify which systems may be affected when a dependency is found to contain a vulnerability or undergoes a significant change.

Question 379

What is an important security control for protecting sensitive information retrieved by an AI application?

  1. Applying appropriate access controls to retrieval sources and retrieved content.
  2. Giving every user unrestricted access to the entire knowledge base.
  3. Disabling authentication for faster responses.
  4. Storing all sensitive information in publicly accessible locations.

Correct Answer: 1

Explanation

AI applications that retrieve information from internal databases, documents, or knowledge repositories must enforce appropriate authorization. The AI system should not retrieve or expose information simply because the underlying source is technically accessible. Access controls should consider the user’s permissions, the sensitivity of the information, and the application’s intended purpose. Retrieval systems should also be evaluated for indirect data exposure, prompt manipulation, and unauthorized cross-user access. Giving every user unrestricted access increases the risk of confidentiality breaches, while disabling authentication removes an important security control. Proper authorization and retrieval filtering help ensure that AI-generated responses are based only on information the requesting user is permitted to access.

Question 380

What is the purpose of sandboxing an AI agent that can interact with external tools?

  1. To limit the potential impact of unsafe or unauthorized actions performed by the agent.
  2. To guarantee that the agent will never make an incorrect decision.
  3. To provide the agent with unlimited system access.
  4. To eliminate the need for monitoring.

Correct Answer: 1

Explanation

Sandboxing can isolate an AI agent and restrict what it can access or modify when interacting with external tools and systems. This is particularly useful for agents that can execute code, access files, make API calls, or perform other actions on behalf of users. If the agent behaves unexpectedly or is manipulated by malicious input, sandbox restrictions can reduce the potential impact. Effective sandboxing should be combined with least-privilege permissions, authentication, action logging, monitoring, and appropriate approval controls. It does not guarantee that an agent will never make an incorrect decision. Instead, it establishes a controlled execution environment that limits the consequences of mistakes, misuse, or compromise.