{"id":18330,"date":"2026-09-22T06:45:45","date_gmt":"2026-09-22T06:45:45","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=18330"},"modified":"2026-09-22T06:45:45","modified_gmt":"2026-09-22T06:45:45","slug":"isaca-aair-practice-test-questions-and-exam-dumps-part4-q61-80","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/isaca-aair-practice-test-questions-and-exam-dumps-part4-q61-80\/","title":{"rendered":"Isaca AAIR Practice Test Questions and Exam Dumps Part4 Q61-80"},"content":{"rendered":"<p><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/aair-exam-dumps\"><b>Isaca AAIR Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/p>\n<p><b><br \/>\n<\/b><b>Q61. An enterprise has defined a broad risk appetite for responsible AI adoption. What is the BEST next step to make this guidance actionable for individual AI projects?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Translate the appetite into measurable AI risk tolerances and decision thresholds<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Allow every development team to define its own unrestricted appetite<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Replace enterprise risk appetite with model accuracy targets<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Wait until an AI incident occurs before defining thresholds<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Translate the appetite into measurable AI risk tolerances and decision thresholds<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Enterprise risk appetite provides high-level guidance about the amount and type of risk the organization is willing to pursue or retain. AI teams need more specific tolerances and thresholds to apply that guidance consistently. Examples can include maximum error rates, acceptable fairness variation, autonomy limits, privacy thresholds, or service-availability requirements. These operational limits can trigger escalation or treatment when exceeded. Allowing every project to establish an unrelated appetite undermines enterprise governance. Model accuracy is only one dimension of AI risk and cannot replace broader considerations such as legal, ethical, operational, security, and reputational exposure.<\/span><\/p>\n<p><b>Q62. An AI project requires an exception from an approved governance policy because a required control cannot currently be implemented. What is the MOST appropriate action?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Allow the project manager to approve the exception informally<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Remove the control requirement from the policy<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Document the exception, assess residual risk, obtain authorized approval, and establish an expiration or review date<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Treat the exception as permanent once approved<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Document the exception, assess residual risk, obtain authorized approval, and establish an expiration or review date<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Policy exceptions should be handled through a controlled governance process. The organization should document why the standard control cannot be implemented, identify any compensating controls, assess resulting residual risk, and obtain approval from the appropriate authority or risk owner. Exceptions should normally have an expiration or reassessment date so temporary deviations do not become permanent unnoticed weaknesses. Simply removing the requirement avoids rather than manages the issue. Formal exception governance also provides traceability for audit, regulatory review, management reporting, and future remediation planning.<\/span><\/p>\n<p><b>Q63. An organization is expanding AI operations into a new country. What governance artifact would MOST help ensure relevant legal obligations are identified and assigned to controls?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A list of model parameter values<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> A regulatory requirements inventory mapped to applicable AI processes and controls<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> A vendor marketing comparison<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> A list of employee job titles only<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. A regulatory requirements inventory mapped to applicable AI processes and controls<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> A regulatory requirements inventory helps the organization identify which laws, regulations, standards, and contractual obligations apply to specific AI activities. Mapping those obligations to processes and controls supports accountability, compliance testing, evidence collection, and gap identification. Requirements may vary according to jurisdiction, industry, data type, affected individuals, and AI use-case impact. Model parameters and marketing information do not establish compliance obligations. A maintained requirements inventory also helps the risk program adapt when regulations or business activities change and provides a structured basis for legal and compliance assessments.<\/span><\/p>\n<p><b>Q64. A public-sector organization plans to deploy AI for prioritizing access to an essential social service. Which additional assessment is MOST appropriate because of the potential effect on individuals?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Hardware utilization assessment only<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Source-code formatting review<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Vendor profitability analysis<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Human rights and stakeholder impact assessment**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Human rights and stakeholder impact assessment<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> AI used in access to essential services can significantly affect individuals and communities. In addition to technical testing, the organization should assess potential impacts on fairness, accessibility, dignity, discrimination, transparency, due process, and other stakeholder or human-rights considerations. The assessment should identify affected populations and evaluate whether protections, appeal mechanisms, human oversight, or alternative processes are needed. Technical efficiency alone does not determine whether a system is responsible or acceptable. High-impact use cases generally require broader societal and ethical scrutiny because harms can extend beyond conventional cybersecurity or operational risk.<\/span><\/p>\n<p><b>Q65. An organization has hundreds of AI applications. What is the BEST basis for deciding which systems require the strongest governance and validation requirements?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A risk-based classification considering impact, autonomy, data sensitivity, and use-case criticality<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> The order in which systems were purchased<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> The number of developers assigned to each system<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Whether the user interface contains generative AI features<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. A risk-based classification considering impact, autonomy, data sensitivity, and use-case criticality<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Governance should be proportionate to risk. An AI system that makes or influences high-impact decisions, processes highly sensitive data, operates autonomously, or supports a critical business service generally warrants stronger controls than a low-impact internal productivity tool. A classification methodology helps the organization consistently determine requirements for validation, documentation, monitoring, approval, explainability, human oversight, and incident readiness. The number of developers or purchase date does not reliably indicate risk. Risk-based tiering also allows the organization to focus limited governance resources on AI systems where failure could cause the greatest harm.<\/span><\/p>\n<p><b>Q66. An organization fine-tunes a pretrained third-party foundation model using confidential internal data. Which risk should receive particular attention?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Whether the model&#8217;s logo matches corporate branding<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Whether developers prefer the model&#8217;s API syntax<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Whether the model is the largest available option<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Whether confidential fine-tuning data could be memorized, exposed, or mishandled**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Whether confidential fine-tuning data could be memorized, exposed, or mishandled<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Fine-tuning introduces additional data governance and privacy risk because proprietary or sensitive records become part of the model-development process. The organization should evaluate whether the model or training platform could retain, memorize, expose, or reuse that information and whether contractual terms permit the intended processing. Access controls, data minimization, retention rules, isolation, testing for leakage, and vendor assurances may be necessary. A technically suitable foundation model can still be inappropriate if confidential data is not adequately protected. The risk assessment should consider the complete data flow through training, storage, inference, and vendor systems.<\/span><\/p>\n<p><b>Q67. A model development team accidentally includes examples from the final evaluation dataset in its training data. What is the PRIMARY concern?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The model will always become less accurate<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Evaluation results may be artificially optimistic because of data leakage<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> The model can no longer be encrypted<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> The training infrastructure will necessarily fail<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Evaluation results may be artificially optimistic because of data leakage<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Evaluation data should remain independent from training so it can provide credible evidence of how the model generalizes to unseen examples. If evaluation records leak into training, the model may effectively learn those examples and achieve inflated test results that do not reflect real-world performance. This can lead management to approve a model based on misleading evidence. Data separation, lineage controls, dataset versioning, and independent validation help prevent this problem. The concern is not that the model necessarily becomes less accurate; rather, confidence in the measured performance becomes unreliable.<\/span><\/p>\n<p><b>Q68. An AI system performs well under normal operating conditions. What testing BEST evaluates whether it remains reliable when inputs are incomplete, noisy, or outside expected ranges?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Testing only average-case production samples<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Reviewing the user interface<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Robustness and stress testing using abnormal and boundary conditions<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Increasing the number of model parameters<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Robustness and stress testing using abnormal and boundary conditions<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Robustness testing evaluates how an AI system behaves when inputs or operating conditions differ from ideal assumptions. Test cases can include missing data, corrupted values, unusual distributions, extreme values, unexpected sequences, or degraded dependencies. The goal is to identify whether the system fails safely, produces unreliable outputs, or behaves unpredictably under adverse conditions. Average-case testing alone may miss serious weaknesses. Risk-based testing should reflect plausible real-world conditions and the consequences of failure, particularly for high-impact systems where unusual situations may be precisely when reliable behavior matters most.<\/span><\/p>\n<p><b>Q69. A critical AI solution has completed development and validation. What is the BEST control before it is moved into production?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A formal deployment approval confirming required validation, risk treatment, and documentation are complete<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Automatic deployment whenever the development team finishes coding<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Removal of all model documentation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Elimination of business-owner involvement<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. A formal deployment approval confirming required validation, risk treatment, and documentation are complete<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> A production approval gate ensures that required lifecycle activities have been completed before a critical AI system begins affecting real users or business processes. The gate may verify independent validation, unresolved issues, residual risk acceptance, documentation, monitoring readiness, privacy and security controls, business-owner approval, and rollback plans. The process should be proportionate to risk rather than bureaucratic for its own sake. Development completion alone does not demonstrate that the system is ready for production. Formal approval creates accountability and prevents projects from bypassing essential governance steps under schedule pressure.<\/span><\/p>\n<p><b>Q70. An AI system remains within accuracy thresholds, but its average response time has doubled and is affecting a critical business process. Which conclusion is MOST appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> No risk exists because accuracy is unchanged<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Operational performance should be monitored as part of the AI system&#8217;s risk profile<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Latency is irrelevant to AI risk management<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> The model should automatically be retrained<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Operational performance should be monitored as part of the AI system&#8217;s risk profile<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> AI risk monitoring should address all characteristics important to the business, not only predictive accuracy. Significant latency can affect service availability, customer experience, process deadlines, or downstream system performance even when model outputs remain correct. Relevant operational indicators might include response time, throughput, resource consumption, error rates, availability, and dependency health. The organization should investigate the cause and compare performance with defined tolerances. Retraining may not solve an infrastructure or capacity problem. Monitoring should therefore reflect the complete set of requirements that determine whether an AI service remains fit for purpose.<\/span><\/p>\n<p><b>Q71. An attacker queries a model to determine whether a particular individual&#8217;s record was included in its training dataset. Which AI privacy attack is this?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Model drift<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Prompt compression<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Membership inference<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Risk transfer<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Membership inference<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> A membership inference attack attempts to determine whether a specific record was part of a model&#8217;s training data by observing model outputs or confidence behavior. This can create privacy risk, particularly when membership in the dataset itself reveals sensitive information. Controls can include limiting exposed output detail, privacy-preserving training methods, access controls, rate limiting, differential privacy where appropriate, and targeted privacy testing. Membership inference differs from model extraction, which aims to reproduce model behavior, and model inversion, which seeks to reconstruct information about underlying data or features.<\/span><\/p>\n<p><b>Q72. An attacker uses repeated model outputs to reconstruct sensitive characteristics of the data used to train the model. Which threat does this MOST closely represent?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Model inversion<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Business interruption<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Shadow AI<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Environmental risk<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Model inversion<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Model inversion attacks attempt to infer or reconstruct information about training data or sensitive attributes by analyzing model outputs. The exact techniques vary according to the model and interface, but the underlying concern is that the trained model may unintentionally expose information derived from its training data. Organizations should assess privacy leakage risks, control output detail, restrict access, monitor abnormal query behavior, and consider privacy-enhancing techniques during development. Model inversion is distinct from membership inference, which asks whether a particular record was present in training rather than attempting to reconstruct underlying information.<\/span><\/p>\n<p><b>Q73. An AI risk has a financial impact that the organization wants another party to assume contractually. Which risk treatment strategy is being used?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Risk avoidance<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Risk mitigation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Risk transfer<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Risk acceptance<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Risk transfer<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Risk transfer shifts some financial or contractual consequences of a risk to another party, commonly through insurance, indemnification, warranties, or contractual obligations. Transfer does not necessarily eliminate the underlying operational or reputational impact. For example, an insurer may reimburse certain financial losses while customers still experience harm or service disruption. The organization must understand which portions of the exposure are actually transferred and which remain. Treatment decisions should compare cost, feasibility, residual risk, and organizational risk appetite. Transfer may also be combined with mitigation controls rather than used as a substitute for them.<\/span><\/p>\n<p><b>Q74. An AI control generates an alert whenever unauthorized model configuration changes occur. What type of control is this PRIMARILY?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Preventive<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Detective<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Corrective<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Directive only<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Detective<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> A control that identifies and alerts on an unauthorized change after or as it occurs is primarily detective. Its purpose is to reveal a potentially harmful condition so response or remediation can begin. A preventive control would aim to block unauthorized changes before they occur, while a corrective control would restore an approved state afterward. Effective AI control environments often combine all three. For example, role-based access can prevent unauthorized changes, integrity monitoring can detect them, and automated rollback can correct them. Classification helps management understand how different controls collectively reduce risk.<\/span><\/p>\n<p><b>Q75. Who should ideally validate a control designed to manage a material AI risk when independence is important?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The same individual who designed and operates the control, with no review<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> The AI model itself<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Any employee unrelated to the control objective<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> A sufficiently independent and competent party**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. A sufficiently independent and competent party<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Independence reduces the risk that control weaknesses are overlooked because the same individuals who designed or operate the control are judging their own work. The degree of independence should be proportionate to the risk and organizational structure. Validation may be performed by a second-line risk function, independent testing team, assurance function, or another qualified party. Independence alone is not enough; the validator must also understand the control objective and AI risk being addressed. High-impact AI controls generally warrant stronger evidence and more objective challenge than low-risk, routine controls.<\/span><\/p>\n<p><b>Q76. Management wants an early-warning indicator that third-party AI service reliability is deteriorating before formal service-level breaches occur. Which metric is MOST useful?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A trend of increasing service errors and latency approaching agreed thresholds<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Number of vendor marketing announcements<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Number of pages in the contract<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Total number of vendor employees<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. A trend of increasing service errors and latency approaching agreed thresholds<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> A leading risk indicator should provide warning before a formal tolerance or service-level breach occurs. Rising errors and latency can show that reliability is deteriorating even while current service levels remain technically within agreed limits. Management can then investigate capacity, provider incidents, regional failures, or architectural dependencies before business disruption becomes significant. Contract length and vendor staffing do not directly indicate current service reliability. Useful KRIs should relate clearly to the exposure being monitored, have defined thresholds, and support timely escalation or treatment when trends worsen.<\/span><\/p>\n<p><b>Q77. An AI risk dashboard shows that a defined risk tolerance has been exceeded for three consecutive reporting periods. What should happen NEXT?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Follow the established escalation and risk treatment process<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Adjust the dashboard so the breach is no longer visible<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Automatically increase risk tolerance to match performance<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Stop reporting the metric<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Follow the established escalation and risk treatment process<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> A sustained tolerance breach indicates that actual exposure is outside the boundary management has approved. The organization should follow predefined escalation procedures, identify the cause, assess whether the risk has changed, and determine appropriate treatment or temporary restrictions. Simply raising tolerance to match current performance undermines governance unless authorized decision-makers deliberately reconsider the organization&#8217;s appetite based on valid business reasons. Reliable risk metrics are useful only when threshold breaches trigger defined management action. Repeated breaches may also indicate that existing controls are ineffective or that underlying assumptions require reassessment.<\/span><\/p>\n<p><b>Q78. A critical AI vendor provides limited information about the security controls used by an important subcontractor. What is the BEST response?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Ignore the subcontractor because no direct contract exists<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Assess the resulting fourth-party risk and obtain appropriate assurance through the primary vendor<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Assume the subcontractor uses identical controls to the primary vendor<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Remove all supplier requirements from the contract<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Assess the resulting fourth-party risk and obtain appropriate assurance through the primary vendor<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Organizations can be exposed to risk from subcontractors and other upstream providers even when they have no direct contractual relationship with them. The primary vendor may depend on these parties for models, data, infrastructure, or critical services. The organization should identify material fourth-party dependencies, evaluate their impact, and obtain appropriate assurance through contractual obligations, reports, certifications, or other evidence from the direct supplier. Ignoring upstream dependencies creates blind spots in supply-chain risk. The depth of due diligence should be proportionate to the dependency&#8217;s criticality and potential impact.<\/span><\/p>\n<p><b>Q79. An organization wants to reduce dependence on a single proprietary AI vendor. Which strategy MOST directly improves exit readiness?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Increase the number of proprietary vendor-specific interfaces<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Eliminate documentation of data formats<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Maintain data portability, documented interfaces, transition procedures, and alternative options<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Renew the contract automatically without review<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Maintain data portability, documented interfaces, transition procedures, and alternative options<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Exit readiness reduces lock-in and supports continuity if a provider becomes unavailable, too expensive, noncompliant, or strategically unsuitable. The organization should understand how models, prompts, configurations, data, logs, and integrations can be migrated or replaced. Documented interfaces and portable formats make transition more practical, while tested alternative providers or fallback processes reduce concentration risk. Exit provisions should also be reflected in contracts, including data return or deletion requirements. Increasing proprietary dependencies makes transition more difficult and can increase both concentration and operational risk.<\/span><\/p>\n<p><b>Q80. A business impact analysis determines that an AI service can tolerate no more than 30 minutes of data loss after a disruption. Which continuity metric should capture this requirement?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Recovery Time Objective<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Mean Time to Detect<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Recovery Point Objective<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Model accuracy threshold<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Recovery Point Objective<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Recovery Point Objective, or RPO, defines the maximum tolerable amount of data loss measured in time. An RPO of 30 minutes means recovery arrangements should restore data to a point no older than approximately 30 minutes before the disruption. This requirement influences backup frequency, replication, storage, and recovery architecture. Recovery Time Objective answers a different question: how quickly the service itself must be restored. AI services may depend on model artifacts, feature stores, datasets, prompts, logs, or configuration that require suitable recovery objectives. BIA results should therefore inform both technology resilience and business continuity planning.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Isaca AAIR Exam Dumps and Practice Test Dumps. Q61. An enterprise has defined a broad risk appetite for responsible AI adoption. What is the BEST next step to make this guidance actionable for individual AI projects? Translate the appetite into measurable AI risk tolerances and decision thresholds 2. Allow every development team to [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18330"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=18330"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18330\/revisions"}],"predecessor-version":[{"id":18331,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18330\/revisions\/18331"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=18330"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=18330"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=18330"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}