Isaca AAISM Practice Test Questions and Exam Dumps Part2 Q21-40

View Full Isaca AAISM Exam Dumps and Practice Test Dumps

 

Question 21. Which governance activity helps ensure that AI initiatives remain aligned with organizational objectives?

  1. Increasing model complexity
  2. Establishing AI strategy and oversight
  3. Removing business stakeholders
  4. Disabling performance monitoring

Correct Answer: 2. Establishing AI strategy and oversight

Explanation:

AI governance should connect AI initiatives with the organization’s strategic objectives, risk appetite, policies, and responsibilities. Establishing an AI strategy and appropriate oversight helps management determine which AI use cases are acceptable, what resources are required, and which risks need additional controls. Governance bodies can establish decision-making responsibilities, approval processes, monitoring expectations, and escalation procedures. This prevents AI development from becoming disconnected from organizational priorities. Effective oversight does not require management to control every technical implementation detail. Instead, it provides direction and accountability while allowing qualified teams to handle model development, deployment, security, and operational activities within defined governance boundaries.

Question 22. Which concept describes the requirement that AI systems operate according to applicable laws, regulations, policies, and standards?

  1. Compliance
  2. Compression
  3. Replication
  4. Scalability

Correct Answer: 1. Compliance

Explanation:

Compliance requires an organization to ensure that AI systems and related processes satisfy applicable legal, regulatory, contractual, policy, and standards-based requirements. Depending on the AI use case and jurisdiction, requirements may address privacy, data protection, discrimination, transparency, cybersecurity, recordkeeping, intellectual property, or sector-specific obligations. Compliance should be considered throughout the AI lifecycle rather than only before deployment. Organizations should identify applicable requirements, assign responsibilities, document controls, monitor changes, and retain appropriate evidence. A compliant AI system may still present operational or ethical risks, so compliance should be treated as one component of a broader AI governance and risk-management program.

Question 23. Why should an organization define an AI risk appetite?

  1. To establish the level and types of AI risk the organization is willing to accept
  2. To guarantee perfect model accuracy
  3. To eliminate all AI experimentation
  4. To replace security testing

Correct Answer: 1. To establish the level and types of AI risk the organization is willing to accept

Explanation:

An AI risk appetite establishes boundaries around the level and types of risk an organization is prepared to accept when using artificial intelligence. It provides management with a basis for evaluating proposed AI use cases and determining when additional controls, approvals, or restrictions are necessary. Risk appetite can help distinguish between acceptable experimentation and deployments that require extensive oversight because of their potential impact. It should consider factors such as privacy, security, fairness, operational resilience, regulatory obligations, and business consequences. Risk appetite is not a guarantee of model accuracy; rather, it provides governance direction for making informed and consistent risk decisions.

Question 24. Which activity helps identify AI systems that may process sensitive personal information?

  1. Data classification
  2. Interface redesign
  3. Network cabling
  4. Model compression

Correct Answer: 1. Data classification

Explanation:

Data classification categorizes information according to characteristics such as sensitivity, confidentiality, business value, or regulatory requirements. Within AI environments, classification can help identify datasets containing personal, confidential, financial, proprietary, or otherwise sensitive information. Once data is classified, appropriate controls can be applied to collection, storage, access, processing, sharing, and retention. This is particularly important because AI systems may process large datasets across development, testing, and production environments. Classification should be supported by clear handling requirements and access controls. It also helps governance teams understand which AI projects require additional privacy or security review because of the information involved.

Question 25. What is the primary purpose of privacy-by-design in an AI system?

  1. Incorporate privacy protections into system design and lifecycle processes
  2. Collect as much personal data as possible
  3. Disable all AI monitoring
  4. Avoid documenting data processing

Correct Answer: 1. Incorporate privacy protections into system design and lifecycle processes

Explanation:

Privacy-by-design means that privacy considerations are incorporated into the architecture, development, deployment, and operation of a system rather than being added only after problems occur. For AI systems, this can involve data minimization, purpose limitation, appropriate access controls, retention limits, transparency, privacy risk assessments, and controls for sensitive information. Privacy-by-design helps organizations identify potential privacy risks early, when changes are generally easier and less costly to implement. It does not mean that personal information can never be used by AI systems. Instead, it encourages organizations to establish appropriate safeguards and ensure that data processing is consistent with defined purposes and applicable requirements.

Question 26. Which approach can reduce unnecessary exposure of sensitive information during AI development?

  1. Data minimization
  2. Unlimited data collection
  3. Shared administrator accounts
  4. Public disclosure of confidential datasets

Correct Answer: 1. Data minimization

Explanation:

Data minimization involves collecting, processing, and retaining only the information necessary for a defined purpose. In AI development, minimizing unnecessary sensitive data can reduce privacy exposure, security risk, storage requirements, and the potential consequences of unauthorized access. Teams should evaluate whether every data element is required for training, testing, validation, or operational use. Where sensitive information is not necessary, it may be excluded, transformed, anonymized, or otherwise protected according to applicable requirements. Data minimization should work together with access controls, retention policies, encryption, monitoring, and secure development practices because reducing data does not eliminate all risks associated with AI processing.

Question 27. What is the purpose of anonymization when preparing data for an AI system?

  1. Reduce the ability to associate data with identifiable individuals
  2. Increase the number of personal identifiers
  3. Guarantee model fairness
  4. Improve network bandwidth

Correct Answer: 1. Reduce the ability to associate data with identifiable individuals

Explanation:

Anonymization aims to reduce or eliminate the ability to associate information with an identifiable individual. When properly implemented, it can reduce privacy risks associated with using datasets for AI development and analysis. Organizations must carefully evaluate whether the transformation is genuinely sufficient for the intended purpose because seemingly anonymous information may sometimes be combined with other datasets to re-identify individuals. Anonymization also does not automatically address every privacy concern or guarantee that an AI model will be unbiased. It should therefore be considered as one privacy control within a broader data-governance framework that includes access management, purpose limitation, retention, and security measures.

Question 28. Which activity helps determine whether an AI model produces materially different outcomes across relevant demographic groups?

  1. Fairness testing
  2. Disk defragmentation
  3. Network routing
  4. Password rotation

Correct Answer: 1. Fairness testing

Explanation:

Fairness testing evaluates whether an AI system produces significantly different outcomes across relevant groups or populations. Depending on the use case, organizations may examine measures such as error rates, selection rates, false positives, false negatives, or other outcome differences. The appropriate fairness criteria depend on the system’s purpose, population, legal requirements, and organizational policies. Testing should be performed using representative and appropriately governed data, and results should be interpreted carefully because different fairness measures can sometimes lead to different conclusions. Identified disparities should be investigated to determine whether they arise from data, model design, deployment context, or other parts of the AI lifecycle.

Question 29. Which factor should be considered when selecting a fairness metric for an AI system?

  1. The system’s purpose, population, and potential impact
  2. The color of the development interface
  3. The number of office printers
  4. The physical size of the server room

Correct Answer: 1. The system’s purpose, population, and potential impact

Explanation:

There is no single fairness metric that is appropriate for every AI system. The selection of fairness measures should consider the system’s purpose, affected population, decision context, potential harms, data characteristics, and applicable legal or organizational requirements. For example, a classification system may require analysis of different error rates across groups, while another application may require different outcome comparisons. Governance teams should document why particular metrics were selected and what thresholds or tolerances apply. Fairness evaluation should also be repeated when data, models, populations, or use cases change because a fairness result observed during initial testing may not remain valid in production.

Question 30. What is transparency in the context of AI governance?

  1. Providing appropriate information about an AI system and its operation to relevant stakeholders
  2. Publishing every confidential model parameter
  3. Giving unrestricted access to training data
  4. Removing all system documentation

Correct Answer: 1. Providing appropriate information about an AI system and its operation to relevant stakeholders

Explanation:

AI transparency involves providing relevant and appropriate information about an AI system to stakeholders who need it. Depending on the context, this may include information about the system’s purpose, capabilities, limitations, data sources, decision processes, performance, risks, and human oversight. Transparency does not necessarily require publishing confidential source code, sensitive training data, or proprietary model parameters. The appropriate level of transparency should reflect stakeholder needs, system risk, privacy obligations, security concerns, and intellectual property considerations. Clear transparency practices can support accountability and informed use by helping stakeholders understand what an AI system does and what limitations should be considered.

Question 31. Which governance mechanism helps ensure that significant AI decisions receive appropriate management review?

  1. AI approval and escalation processes
  2. Uncontrolled model deployment
  3. Removal of audit records
  4. Shared administrative credentials

Correct Answer: 1. AI approval and escalation processes

Explanation:

Approval and escalation processes establish formal pathways for reviewing significant AI decisions and addressing risks that exceed defined thresholds. An organization can require higher levels of approval for systems classified as high risk or for changes that materially affect data processing, decision outcomes, security, or regulatory exposure. Escalation procedures also help employees raise concerns when an AI system behaves unexpectedly or creates a potential policy violation. These mechanisms should identify decision authorities, required documentation, risk criteria, and response timelines. Effective governance depends on these processes being practical and understood by personnel rather than existing only as undocumented expectations.

Question 32. Why is segregation of duties valuable in AI governance?

  1. It reduces the risk of inappropriate control by separating critical responsibilities
  2. It allows one person to control every AI function
  3. It eliminates the need for authentication
  4. It prevents all model updates

Correct Answer: 1. It reduces the risk of inappropriate control by separating critical responsibilities

Explanation:

Segregation of duties reduces the possibility that one individual can independently perform conflicting or high-risk activities without appropriate oversight. In an AI environment, responsibilities for developing models, approving deployments, managing sensitive data, validating results, and administering production systems can be separated where appropriate. This creates additional checks and balances and can reduce the likelihood of unauthorized changes, fraud, accidental errors, or conflicts of interest. The exact separation should reflect organizational size and risk. Smaller organizations may use compensating controls when complete separation is impractical, such as independent review, approval workflows, enhanced logging, or periodic audits.

Question 33. Which activity provides evidence that an AI system continues to meet defined requirements after deployment?

  1. Ongoing assurance and monitoring
  2. One-time installation only
  3. Removing performance measurements
  4. Disabling user feedback

Correct Answer: 1. Ongoing assurance and monitoring

Explanation:

Ongoing assurance and monitoring help determine whether an AI system continues to operate according to defined requirements after deployment. Production conditions can differ from development and testing environments, and changes in data, users, threats, regulations, or business processes can affect system behavior. Monitoring may include performance indicators, fairness measures, security events, data quality, model drift, availability, and compliance requirements. Periodic reviews can then determine whether corrective actions, retraining, configuration changes, or additional controls are needed. Continuous assurance is important because successful initial validation does not guarantee that an AI system will remain reliable and appropriate throughout its operational lifecycle.

Question 34. Which security control protects AI data and model artifacts from unauthorized modification?

  1. Integrity controls
  2. Data publication
  3. Anonymous administration
  4. Unrestricted write access

Correct Answer: 1. Integrity controls

Explanation:

Integrity controls help ensure that AI datasets, model artifacts, configurations, and other important resources are not modified without authorization. Controls may include access restrictions, cryptographic hashes, digital signatures, version control, change management, approval workflows, and monitoring. Protecting integrity is important because unauthorized modification of training data or model files could alter system behavior without immediately being obvious. Organizations should protect both development and production artifacts and maintain traceability between approved versions and deployed versions. Integrity controls should work with confidentiality and availability measures because trustworthy AI requires protection against unauthorized disclosure, unauthorized alteration, and disruptive loss of access.

Question 35. What is model version control primarily used for?

  1. Track changes between different versions of an AI model
  2. Increase Internet bandwidth
  3. Replace user authentication
  4. Automatically classify all data

Correct Answer: 1. Track changes between different versions of an AI model

Explanation:

Model version control provides traceability across different versions of an AI model and its associated artifacts. It helps teams determine which model version was trained, tested, approved, and deployed at a particular point in time. This is important for reproducibility, troubleshooting, rollback, auditability, and change management. Version information can be linked with training datasets, code, configuration, evaluation results, and approval records to create a stronger lifecycle history. Without effective version control, organizations may have difficulty determining why model behavior changed or identifying exactly which artifact was responsible for a particular production outcome.

Question 36. Which practice helps ensure that an AI model can be reproduced or investigated after deployment?

  1. Maintaining appropriate model and data documentation
  2. Deleting training records immediately
  3. Avoiding version numbers
  4. Sharing administrator credentials

Correct Answer: 1. Maintaining appropriate model and data documentation

Explanation:

Maintaining appropriate documentation helps organizations understand how an AI model was developed, evaluated, approved, and deployed. Useful records may include model versions, training data characteristics, preprocessing steps, evaluation results, configuration settings, dependencies, known limitations, and deployment information. This documentation supports reproducibility and investigation when unexpected outcomes occur. It can also provide evidence during audits or governance reviews. Documentation should be protected and updated when significant changes occur. The objective is not to record every minor development activity indefinitely, but to maintain sufficient information for responsible teams to understand the model lifecycle and reconstruct important decisions when necessary.

Question 37. Which risk can arise when an AI model is trained using data containing confidential proprietary information?

  1. Unauthorized disclosure or inappropriate reuse of sensitive information
  2. Automatic improvement of all security controls
  3. Guaranteed compliance
  4. Elimination of privacy concerns

Correct Answer: 1. Unauthorized disclosure or inappropriate reuse of sensitive information

Explanation:

Using confidential proprietary information in AI training can create risks related to unauthorized disclosure, inappropriate reuse, intellectual property, access control, and contractual obligations. Depending on the system architecture and implementation, sensitive information may also appear in logs, outputs, model-related artifacts, or downstream services. Organizations should therefore determine whether the data is necessary, whether its use is authorized, and what safeguards are required before incorporating it into an AI workflow. Controls can include data minimization, access restrictions, encryption, contractual protections, secure development practices, monitoring, and output testing. Governance should address these risks before sensitive information enters the AI lifecycle.

Question 38. What is the purpose of an AI incident response process?

  1. Provide a structured method for detecting, investigating, containing, and recovering from AI-related incidents
  2. Prevent all AI development
  3. Eliminate security monitoring
  4. Replace organizational policies

Correct Answer: 1. Provide a structured method for detecting, investigating, containing, and recovering from AI-related incidents

Explanation:

An AI incident response process establishes a structured approach for handling security, privacy, safety, compliance, or operational incidents involving AI systems. The process should define how incidents are detected, reported, triaged, investigated, contained, remediated, and reviewed after resolution. AI-specific considerations may include compromised models, manipulated inputs, data leakage, harmful outputs, unauthorized model changes, third-party service failures, and unexpected behavior. Response plans should identify responsible teams, escalation criteria, communication requirements, evidence-preservation procedures, and recovery actions. Exercises and periodic reviews can help determine whether the response process remains effective as AI systems and threats evolve.

Question 39. Which principle supports retaining only the data needed for a defined AI purpose?

  1. Data minimization
  2. Data accumulation
  3. Unlimited retention
  4. Universal disclosure

Correct Answer: 1. Data minimization

Explanation:

Data minimization supports responsible data governance by limiting collection, processing, and retention to information that is necessary for a defined purpose. In AI environments, this principle can reduce privacy exposure and security risk while also helping organizations control unnecessary data-management costs. Before collecting information for training or inference, teams should determine why each data element is needed and whether a less sensitive alternative exists. Retention should also be limited according to documented requirements rather than keeping data indefinitely by default. Data minimization should be integrated with purpose limitation, access controls, secure disposal, and appropriate privacy assessments.

Question 40. Why should AI governance policies be reviewed periodically?

  1. AI technology, risks, regulations, and organizational requirements can change
  2. Policies never need updates after approval
  3. Reviews automatically eliminate all AI risks
  4. Periodic reviews prevent all model failures

Correct Answer: 1. AI technology, risks, regulations, and organizational requirements can change

Explanation:

AI governance policies should be reviewed periodically because the environment in which AI systems operate is continually changing. New technologies, emerging threats, regulatory developments, organizational objectives, data practices, and lessons from incidents can make existing policies incomplete or outdated. Reviews provide an opportunity to determine whether responsibilities, risk classifications, approval requirements, security controls, monitoring practices, and acceptable-use requirements remain appropriate. Significant changes to an organization’s AI portfolio may also require updates to governance documentation. Periodic review does not guarantee that every AI risk will be eliminated, but it helps maintain a governance framework that remains relevant and aligned with current conditions.