{"id":18332,"date":"2026-09-22T06:46:03","date_gmt":"2026-09-22T06:46:03","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=18332"},"modified":"2026-09-22T06:46:03","modified_gmt":"2026-09-22T06:46:03","slug":"isaca-aair-practice-test-questions-and-exam-dumps-part5-q81-100","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/isaca-aair-practice-test-questions-and-exam-dumps-part5-q81-100\/","title":{"rendered":"Isaca AAIR Practice Test Questions and Exam Dumps Part5 Q81-100"},"content":{"rendered":"<p><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/aair-exam-dumps\"><b>Isaca AAIR Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/p>\n<p><b><br \/>\n<\/b><b>Q81. An organization uses several established risk frameworks and is considering an additional AI-specific framework. What should the risk professional do FIRST?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Replace every existing framework with the AI-specific framework<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Map the AI framework to existing governance and risk processes to identify overlaps and gaps<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Apply the AI framework only to the data science team<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Delay adoption until all AI regulations worldwide are finalized<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Map the AI framework to existing governance and risk processes to identify overlaps and gaps<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> AI governance should complement the organization&#8217;s established risk practices rather than unnecessarily duplicate or replace them. Mapping an AI-specific framework against current enterprise risk, security, privacy, compliance, and governance frameworks reveals which requirements are already addressed and where AI-specific gaps remain. This reduces duplicated controls and conflicting terminology while preserving enterprise consistency. The organization can then incorporate appropriate new controls, responsibilities, and metrics. ISACA\u2019s AAIR scope emphasizes integrating AI risk into existing enterprise frameworks and programs instead of managing AI as an isolated discipline.<\/span><\/p>\n<p><b>Q82. The board wants assurance that management is not focusing exclusively on the technical accuracy of AI systems. Which reporting approach is BEST?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Report a balanced set of material AI risks, business impacts, compliance issues, control status, and performance trends<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Report only model accuracy<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Provide raw model source code at every board meeting<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Report only the number of AI projects underway<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Report a balanced set of material AI risks, business impacts, compliance issues, control status, and performance trends<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Board-level AI risk reporting should provide a strategic view of whether AI adoption remains aligned with objectives and risk appetite. Relevant information can include material risk trends, regulatory exposure, significant control weaknesses, tolerance breaches, major incidents, third-party concerns, business impacts, and management actions. Accuracy is important but is only one dimension of AI risk. A technically accurate model may still create privacy, fairness, legal, security, availability, or reputational issues. Board reporting should therefore connect AI risk information to enterprise objectives and decisions rather than overwhelm directors with low-level technical detail.<\/span><\/p>\n<p><b>Q83. An enterprise AI policy has not been reviewed since the organization began deploying generative AI agents with tool access. What is the BEST action?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Leave the policy unchanged because it was previously approved<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Replace the policy with vendor documentation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Review and update the policy to reflect material changes in AI use, risk, and control requirements<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Eliminate the policy and rely on employee judgment<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Review and update the policy to reflect material changes in AI use, risk, and control requirements<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> AI policies should evolve when the organization&#8217;s technology, use cases, regulatory environment, or risk profile changes materially. Generative AI agents with external tool access introduce risks such as excessive agency, prompt injection, data disclosure, and unauthorized actions that may not have existed when the original policy was written. Governance should therefore include periodic and event-driven policy review. Updates can clarify acceptable use, approval requirements, autonomy limits, monitoring, data handling, and accountability. An outdated policy may provide false assurance because it no longer addresses the organization&#8217;s actual AI activities.<\/span><\/p>\n<p><b>Q84. Which role should be MOST directly accountable for ensuring the quality and authorized use of a dataset used across multiple AI models?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Every end user equally<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> External auditors<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> The AI vendor regardless of data ownership<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> A formally designated data owner or steward**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. A formally designated data owner or steward<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> AI data governance requires clear accountability for datasets. A designated data owner or steward should help define authorized uses, quality expectations, classification, retention, access, lineage, and remediation responsibilities. Model owners remain accountable for appropriate model use, but they may not own enterprise data used across several systems. External auditors provide assurance and should not normally own operational data responsibilities. Clear data ownership reduces ambiguity when quality problems, privacy concerns, access requests, or regulatory obligations arise. Governance works best when responsibilities for data, models, business processes, and risks are explicitly distinguished.<\/span><\/p>\n<p><b>Q85. Management wants to know whether mandatory AI awareness training is actually changing employee behavior. Which measure provides the BEST evidence?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Number of slides in the training course<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Number of employees invited to training<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Reduction in observed policy violations together with assessment or simulation results<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Cost of the learning-management platform<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Reduction in observed policy violations together with assessment or simulation results<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Training effectiveness should be measured through outcomes rather than attendance alone. Completion rates show participation but do not demonstrate understanding or behavioral improvement. A stronger evaluation combines knowledge assessments, realistic simulations, monitoring results, and trends in violations such as improper use of public AI services or mishandling of confidential information. Results can identify groups needing additional education or controls. Effective awareness programs should align with AI policies and actual organizational risks. ISACA specifically includes developing and integrating AI risk concepts into enterprise awareness and training activities.<\/span><\/p>\n<p><b>Q86. An AI development team receives customer records from several source systems. Before training begins, which control MOST improves confidence in the dataset&#8217;s reliability?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Increase model size<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Define and test data-quality criteria such as completeness, accuracy, consistency, and validity<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Remove all metadata<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Assume source systems always provide correct data<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Define and test data-quality criteria such as completeness, accuracy, consistency, and validity<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Model quality depends heavily on the quality of data used for training and validation. Organizations should define measurable criteria appropriate to the use case, such as completeness, accuracy, consistency, validity, timeliness, and representativeness. Data-quality testing can identify missing fields, inconsistent labels, outliers, duplicates, or corrupted records before those problems influence model behavior. Increasing model complexity cannot compensate reliably for poor input data. Documented thresholds also support governance because teams can determine when a dataset is suitable for use and when remediation or escalation is required.<\/span><\/p>\n<p><b>Q87. An organization must reproduce a model that generated a disputed decision six months ago. Which capability is MOST important?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The current production model only<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> The latest training dataset only<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> The model owner&#8217;s recollection of the deployment<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Versioned model artifacts, data lineage, code, configuration, and deployment records**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Versioned model artifacts, data lineage, code, configuration, and deployment records<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Reproducibility requires more than retaining the latest model. Investigators may need to know the exact model version, training and preprocessing data, source code, parameters, environment, dependencies, and configuration that existed when a particular outcome was produced. Strong lineage and versioning support regulatory investigations, customer disputes, internal reviews, and incident response. Without this evidence, the organization may be unable to explain or reproduce historical behavior. AI lifecycle governance should therefore preserve sufficient artifacts and metadata according to risk, legal, and retention requirements.<\/span><\/p>\n<p><b>Q88. A new AI service replaces an existing manual process. What is the BEST resilience design if the AI service becomes temporarily unavailable?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Maintain a tested fallback or degraded operating procedure where business requirements justify it<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Assume the AI service will never fail<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Immediately terminate the business process permanently<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Remove all manual knowledge after deployment<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Maintain a tested fallback or degraded operating procedure where business requirements justify it<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Critical AI dependencies should be included in resilience planning. If a business process cannot tolerate complete loss of an AI service, management should consider fallback procedures such as manual review, a simpler rules-based process, a backup provider, or another degraded mode. The fallback should be documented and tested rather than assumed to work during an emergency. The appropriate level of resilience depends on business impact analysis and risk appetite. Removing all prior process capability can increase concentration and continuity risk if the AI service later fails.<\/span><\/p>\n<p><b>Q89. An AI model&#8217;s probability scores remain stable, but actual outcomes show that a predicted 80% likelihood is correct only about 55% of the time. What problem is MOST directly indicated?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Poor model calibration<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Third-party concentration<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Data-retention failure<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Physical security weakness<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Poor model calibration<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Calibration refers to how well predicted probabilities correspond to observed real-world frequencies. A well-calibrated model that assigns 80% probability to many events should see approximately 80% of those events occur over an appropriate sample. If only 55% occur, the scores may create unjustified confidence even if ranking performance remains acceptable. Calibration can be important when decisions depend directly on probability thresholds. Monitoring should therefore consider not only accuracy but also whether confidence scores remain meaningful for the business process. Recalibration or other model adjustments may be necessary.<\/span><\/p>\n<p><b>Q90. An organization wants to identify AI risks that may emerge from rapid changes in technology and regulation before they appear in incident statistics. Which activity is MOST useful?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Reviewing only historical incidents<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Monitoring only financial losses<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Eliminating external information sources<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Horizon scanning for emerging technologies, threats, regulations, and industry developments**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Horizon scanning for emerging technologies, threats, regulations, and industry developments<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Emerging AI risks may develop faster than internal loss data can reveal them. Horizon scanning systematically monitors developments in technology, adversarial techniques, legal requirements, standards, vendor practices, and industry incidents to identify changes that could alter the organization&#8217;s risk profile. Findings can trigger risk reassessment, new scenarios, policy updates, or additional controls before direct losses occur. Historical events remain useful, but relying only on past incidents can leave the organization unprepared for novel AI threats. ISACA\u2019s AAIR practice includes continuously assessing and monitoring the emerging AI risk landscape.<\/span><\/p>\n<p><b>Q91. Several moderate AI risks depend on the same central identity provider. What should the enterprise risk assessment consider?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only each risk individually<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Only the identity provider&#8217;s purchase cost<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Aggregation and common-cause risk created by the shared dependency<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> The risks should be removed because none is individually high<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Aggregation and common-cause risk created by the shared dependency<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Risks that appear moderate independently can become significant when they share a common dependency. If numerous AI services depend on one identity provider, a single outage or compromise could affect all of them simultaneously. Enterprise risk assessment should therefore consider aggregation, concentration, and correlated failure rather than evaluating every scenario in isolation. Common-cause analysis can reveal exposures that individual project assessments miss. Management may then consider redundancy, fallback authentication, stronger controls, or continuity arrangements depending on the criticality of the affected AI services.<\/span><\/p>\n<p><b>Q92. A risk professional is estimating the potential financial consequences of an AI service outage under several plausible durations and customer-impact levels. Which technique is MOST appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Source-code review only<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Scenario-based quantitative risk analysis<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Model explainability testing<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Employee awareness training<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Scenario-based quantitative risk analysis<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Quantitative scenario analysis can estimate the financial effect of different plausible events by considering variables such as outage duration, transaction loss, contractual penalties, recovery expense, customer compensation, and reputational impact. The estimates may include ranges and uncertainty rather than a single precise figure. This approach can help management compare treatment costs with expected exposure and prioritize investment. Code reviews and awareness training may be controls, but they do not directly estimate the business consequences of the risk scenario. Quantification should be based on reasonable assumptions and documented uncertainty.<\/span><\/p>\n<p><b>Q93. A manager tracks the percentage of AI projects delivered on schedule. Is this metric necessarily an AI risk indicator?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Yes, every project metric is automatically a KRI<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> No; it is primarily a performance metric unless a defined relationship to risk exposure is established<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Yes, because schedules measure model bias directly<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> No, because AI programs should never use metrics<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. No; it is primarily a performance metric unless a defined relationship to risk exposure is established<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Key performance indicators and key risk indicators serve different purposes, although a metric can sometimes support both. Schedule performance usually measures project delivery effectiveness rather than directly signaling changes in AI risk exposure. If delays are shown to increase a specific risk\u2014for example, delayed implementation of a regulatory control\u2014the metric might support risk monitoring. The important point is that KRIs should have a defined relationship to risk conditions and thresholds. Labeling every operational KPI as a KRI creates dashboards that are large but provide little meaningful early warning.<\/span><\/p>\n<p><b>Q94. An organization learns of a newly published attack against a class of AI models it operates. What should the risk function do FIRST?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Determine whether the organization&#8217;s models are exposed or vulnerable to the reported technique<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Shut down every AI system immediately<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Ignore the attack until the organization experiences it directly<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Remove the attack from threat-intelligence reports<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Determine whether the organization&#8217;s models are exposed or vulnerable to the reported technique<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> External threat intelligence should be translated into organizational relevance. The first step is to identify whether affected model types, components, interfaces, or deployment patterns exist in the environment and whether current controls mitigate the reported technique. If exposure exists, the organization can assess likelihood and impact, prioritize remediation, add monitoring, or temporarily restrict affected systems. Automatically shutting down every AI service may be disproportionate, while waiting for an actual attack is unnecessarily reactive. Threat intelligence creates value when it informs risk scenarios and control decisions.<\/span><\/p>\n<p><b>Q95. A critical AI application uses an open-source model obtained from a public repository. Which supply-chain control is MOST important before deployment?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Assume popularity proves the model is trustworthy<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Verify provenance, integrity, licensing, maintenance status, and security of the acquired artifact<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Disable all internal validation because the source is public<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Use the model only if it has the largest download count<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Verify provenance, integrity, licensing, maintenance status, and security of the acquired artifact<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Open-source AI components can provide significant value but introduce software and model supply-chain risks. Organizations should verify where the artifact originated, whether its integrity can be validated, what license applies, whether it is actively maintained, and whether known malicious or vulnerable behavior has been identified. They should also evaluate model limitations and suitability for the intended use. Popularity and download counts do not provide adequate assurance. Open-source assets should be inventoried, versioned, monitored, and governed according to their business impact and risk.<\/span><\/p>\n<p><b>Q96. A high-risk AI vendor refuses to permit direct customer audits but provides a recent independent assurance report covering relevant controls. What should the organization do?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Reject the report automatically because only direct audits provide evidence<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Ignore vendor controls completely<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Evaluate whether the independent assurance report provides sufficient relevant evidence for the identified risks<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Assume the report proves all vendor risks are eliminated<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Evaluate whether the independent assurance report provides sufficient relevant evidence for the identified risks<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Third-party assurance should be evaluated for relevance, scope, period, independence, control coverage, exceptions, and applicability to the organization&#8217;s actual use of the service. A credible independent report can provide valuable evidence when direct audit rights are unavailable or impractical, but it should not be accepted automatically. Gaps may require supplemental questionnaires, technical evidence, contractual controls, or compensating measures. Likewise, an assurance report does not eliminate all third-party risk. The goal is to obtain enough reliable evidence to assess residual risk and make an informed vendor decision.<\/span><\/p>\n<p><b>Q97. An enterprise wants consistent AI incident severity classification. What is the BEST basis for defining severity levels?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Number of developers working on the affected model<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Business impact, affected stakeholders, data sensitivity, regulatory implications, scope, and service criticality<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> The model&#8217;s parameter count<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> The length of the incident ticket<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Business impact, affected stakeholders, data sensitivity, regulatory implications, scope, and service criticality<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Incident severity should reflect the consequence and scope of the event rather than arbitrary technical characteristics. Factors can include harm to individuals, business disruption, sensitive-data exposure, regulatory notification requirements, safety implications, financial losses, number of affected systems, and criticality of the service. Consistent severity criteria support escalation, communication, response SLAs, executive involvement, and regulatory coordination. An AI incident involving a small model can be severe if it affects critical decisions, while a technically large model may generate only a minor operational issue.<\/span><\/p>\n<p><b>Q98. What is the PRIMARY purpose of conducting an AI incident response tabletop exercise?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To test roles, decisions, escalation, communications, and procedures in a simulated scenario<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> To prove that no real incident can occur<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> To replace technical security testing<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> To determine model training accuracy<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. To test roles, decisions, escalation, communications, and procedures in a simulated scenario<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> A tabletop exercise allows participants to work through a realistic AI incident without disrupting production. It can reveal ambiguity in escalation paths, decision authority, communications, legal notification, business continuity, model shutdown procedures, evidence preservation, and vendor coordination. The objective is to improve preparedness rather than demonstrate perfect performance. Tabletop exercises complement technical testing because many incident failures arise from unclear roles and coordination rather than purely technical weaknesses. Findings should be documented and used to improve response plans, training, controls, and continuity arrangements.<\/span><\/p>\n<p><b>Q99. A critical AI service fails, but the underlying business activity can continue using a slower manual procedure. What does the manual procedure primarily provide?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A business continuity workaround<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Model extraction protection<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Data poisoning detection<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Risk appetite definition<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. A business continuity workaround<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> A manual fallback can allow a critical business process to continue when the supporting AI system becomes unavailable or unsafe. The procedure may provide reduced capacity or slower service, but it can prevent complete interruption while technical recovery occurs. Such workarounds should be documented, staffed, and tested so employees understand when and how to invoke them. A fallback does not reduce the probability of the original failure, but it reduces operational impact. Business continuity planning should consider AI dependencies explicitly, particularly where organizations have replaced traditional processes with automated decision systems.<\/span><\/p>\n<p><b>Q100. Management wants to use an AI tool to draft enterprise risk reports. Which control is MOST important before reports are distributed to senior leadership?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Allow the AI to publish reports automatically<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Remove source data from the review process<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Require knowledgeable human review and validation of material statements, metrics, and conclusions<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Assume professional wording proves factual accuracy<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Require knowledgeable human review and validation of material statements, metrics, and conclusions<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Generative AI can accelerate risk-report drafting by summarizing data and suggesting narrative, but material information supplied to senior management must be accurate, complete, and appropriately contextualized. A knowledgeable reviewer should verify metrics, factual statements, conclusions, sources, and any recommendations before distribution. AI-generated text can sound authoritative even when it misinterprets data or invents details. Review should also ensure confidential information is handled appropriately and that the report reflects approved risk definitions and thresholds. AI should support the risk management process without replacing human accountability for formal risk reporting.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Isaca AAIR Exam Dumps and Practice Test Dumps. Q81. An organization uses several established risk frameworks and is considering an additional AI-specific framework. What should the risk professional do FIRST? Replace every existing framework with the AI-specific framework 2. Map the AI framework to existing governance and risk processes to identify overlaps and [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18332"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=18332"}],"version-history":[{"count":2,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18332\/revisions"}],"predecessor-version":[{"id":18334,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18332\/revisions\/18334"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=18332"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=18332"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=18332"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}