{"id":18341,"date":"2026-09-22T06:47:59","date_gmt":"2026-09-22T06:47:59","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=18341"},"modified":"2026-09-22T06:47:59","modified_gmt":"2026-09-22T06:47:59","slug":"isaca-aair-practice-test-questions-and-exam-dumps-part9-q161-180","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/isaca-aair-practice-test-questions-and-exam-dumps-part9-q161-180\/","title":{"rendered":"Isaca AAIR Practice Test Questions and Exam Dumps Part9 Q161-180"},"content":{"rendered":"<p><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/aair-exam-dumps\"><b>Isaca AAIR Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/p>\n<p><b><br \/>\n<\/b><b>Q161. An organization allows a high-impact AI system to make decisions affecting customers. What governance mechanism is MOST important for customers who believe an AI-supported decision is incorrect?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Increasing model complexity<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Publishing the model&#8217;s source code<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Removing human review to ensure consistency<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Providing a documented challenge, appeal, or redress process<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Providing a documented challenge, appeal, or redress process<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> High-impact AI decisions may affect financial interests, employment, access to services, or other significant outcomes. A documented challenge or appeal mechanism gives affected individuals a meaningful way to question an outcome, supply additional information, and obtain appropriate human review. The process should define authority, timelines, evidence requirements, escalation, and how corrections are recorded. Such mechanisms support accountability and trustworthy AI governance. Publishing source code does not necessarily help an individual obtain a remedy, while removing human oversight can make errors harder to correct. Redress is particularly important when decisions have significant or difficult-to-reverse consequences.<\/span><\/p>\n<p><b>Q162. A business unit develops an AI application using personal information originally collected for a different purpose. What should be evaluated FIRST?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Whether the new AI use is compatible with the original purpose and applicable privacy requirements<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Whether the development team can increase model accuracy<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Whether more personal information can be collected<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Whether the AI model uses open-source libraries<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Whether the new AI use is compatible with the original purpose and applicable privacy requirements<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Personal data collected for one purpose cannot automatically be reused for any later AI initiative. The organization should evaluate purpose limitation, lawful basis, consent or notice requirements where applicable, contractual restrictions, and whether the proposed processing is compatible with the reason the data was originally collected. Data minimization and retention should also be considered. A highly accurate model can still create unacceptable privacy risk if the underlying use of personal information is inappropriate. The assessment should occur before development proceeds so privacy requirements can influence architecture and data selection rather than becoming an after-the-fact remediation issue.<\/span><\/p>\n<p><b>Q163. An AI governance committee wants to understand which AI systems would create the greatest enterprise impact if compromised or unavailable. Which activity BEST supports this?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Ranking systems by development cost only<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Reviewing only model parameter counts<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Classifying AI assets according to business criticality, data sensitivity, and dependency impact<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Listing systems alphabetically<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Classifying AI assets according to business criticality, data sensitivity, and dependency impact<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Asset classification helps an organization apply risk management resources proportionately. An AI system that supports a critical service, processes highly sensitive data, or has many downstream dependencies generally requires stronger security, continuity, monitoring, and governance controls than a low-impact internal tool. Development cost does not reliably indicate business criticality. Classification also supports incident prioritization, recovery planning, control selection, and supply-chain assessment. The methodology should be consistent and integrated with the organization&#8217;s broader asset and risk classification practices so AI assets can be compared with other important enterprise resources.<\/span><\/p>\n<p><b>Q164. An AI project team updates the system prompt of a production generative AI application. What should determine whether formal change management is required?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Whether the prompt contains more than 100 words<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> The potential material effect of the prompt change on system behavior and risk<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Whether the prompt was edited by a developer<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Whether the change took less than one hour<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. The potential material effect of the prompt change on system behavior and risk<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Prompt changes can materially alter the behavior of generative AI applications even when the underlying model remains unchanged. Changes may affect output restrictions, tool selection, data disclosure, decision logic, or interaction with downstream systems. Change-management requirements should therefore be based on potential impact rather than superficial characteristics such as length or development effort. Material changes should be versioned, tested, reviewed, and approved according to the system&#8217;s risk classification. This ensures that behavioral modifications do not bypass controls merely because they occur in prompts rather than conventional software code.<\/span><\/p>\n<p><b>Q165. An organization acquires an AI system composed of a foundation model, third-party libraries, external datasets, and several APIs. Which artifact would MOST improve supply-chain visibility?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Employee directory<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Marketing requirements document<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Model accuracy dashboard only<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> An AI bill of materials identifying material models, software, data, and service dependencies**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. An AI bill of materials identifying material models, software, data, and service dependencies<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> An AI bill of materials can provide structured visibility into important components and dependencies that make up an AI solution. Depending on organizational needs, it may identify foundation models, software packages, datasets, APIs, cloud services, licensing information, and suppliers. This information supports vulnerability management, licensing review, incident response, supply-chain analysis, and concentration-risk assessment. A single accuracy dashboard does not show what the system depends on. Better component visibility also makes it easier to respond when a provider, library, dataset, or model is later found to be vulnerable, compromised, unavailable, or legally unsuitable.<\/span><\/p>\n<p><b>Q166. A model is evaluated against a benchmark that closely resembles the data used during its development. What is the PRIMARY risk?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The benchmark will always underestimate performance<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> The evaluation may not provide an independent measure of generalization<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Benchmarking automatically causes model drift<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> The model can no longer be monitored in production<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. The evaluation may not provide an independent measure of generalization<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Evaluation should provide credible evidence that a model performs well on data or scenarios not effectively memorized during development. If a benchmark is too similar to development data, performance may appear stronger than it will be in real-world conditions. Independent or held-out evaluation helps determine whether the model generalizes to representative future inputs. The organization should also ensure that benchmarks reflect the actual business use case rather than optimizing to an abstract score. Good validation considers suitability, robustness, fairness, and operational context in addition to a headline performance metric.<\/span><\/p>\n<p><b>Q167. An AI system generates synthetic records that will be used for testing. What is the MOST important privacy check before those records are distributed broadly?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Confirm that the synthetic data does not enable practical re-identification or reveal sensitive source information<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Verify only that file size is smaller than the original dataset<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Assume synthetic data contains no privacy risk<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Remove all metadata without evaluating record content<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Confirm that the synthetic data does not enable practical re-identification or reveal sensitive source information<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Synthetic data can reduce privacy risk, but it may still reproduce rare attributes, combinations, or memorized records from the original data. Before broad distribution, the organization should evaluate whether individuals could reasonably be re-identified or whether sensitive source information can be inferred. The evaluation should consider the generation method, source dataset sensitivity, intended recipients, and permitted use. Simply labeling information synthetic does not guarantee anonymity. Where risk remains, additional controls such as access restrictions, aggregation, privacy-enhancing methods, or more conservative generation parameters may be needed.<\/span><\/p>\n<p><b>Q168. A production AI system begins receiving input values far outside the ranges observed during training. What should monitoring identify this as?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Normal model maintenance<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> A guaranteed cyberattack<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Out-of-distribution input requiring investigation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Proof that the model needs no further validation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Out-of-distribution input requiring investigation<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Out-of-distribution inputs differ materially from the conditions represented in training or validation data. Models can behave unpredictably when they encounter such inputs, even if they performed strongly on known data. Monitoring should identify material shifts and trigger investigation, additional validation, input rejection, human review, or other controls depending on the use case. Not every unusual input is malicious, so it should not automatically be treated as an attack. The key concern is that existing performance evidence may no longer be applicable when operational data moves beyond the model&#8217;s tested domain.<\/span><\/p>\n<p><b>Q169. A risk assessment identifies a scenario that could affect many AI systems simultaneously because they all rely on the same foundation model. What should the risk team assess?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Systemic and concentration risk across the AI portfolio<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Only the individual application with the highest revenue<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Only the foundation model&#8217;s accuracy<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Employee training completion rates<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Systemic and concentration risk across the AI portfolio<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> A shared foundation model can become a common point of failure across multiple otherwise separate applications. A model defect, provider outage, security incident, licensing change, or regulatory restriction could affect many systems at once. Portfolio-level risk assessment should therefore identify common dependencies and aggregate the potential impact rather than assessing each application in isolation. This can influence diversification, fallback strategies, vendor management, continuity planning, and monitoring. Concentration risk is especially important in AI because organizations may build numerous services on a small number of foundation models or infrastructure providers.<\/span><\/p>\n<p><b>Q170. An organization wants to understand how an extreme but plausible failure of an autonomous AI system could affect the enterprise. Which technique is MOST appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Routine code formatting review<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Employee satisfaction survey<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Model parameter counting<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Stress testing using severe but plausible scenarios**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Stress testing using severe but plausible scenarios<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Stress testing examines how systems and controls behave under severe but plausible conditions that may not appear in ordinary operating data. For an autonomous AI system, scenarios might include cascading incorrect actions, loss of key data, provider outages, malicious tool manipulation, or simultaneous control failures. The goal is to identify vulnerabilities, recovery limitations, and potential business impacts before such conditions occur. Stress testing complements ordinary validation because average-case performance may not reveal tail risks. Results should inform continuity plans, control design, risk tolerances, and escalation procedures.<\/span><\/p>\n<p><b>Q171. A risk treatment plan requires implementation of three controls by different teams. What is MOST important for ensuring the plan is completed?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Assign clear control owners, due dates, milestones, and escalation requirements<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Allow all teams to choose whether to implement their actions<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Remove due dates to reduce pressure<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Close the risk once the plan is documented<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Assign clear control owners, due dates, milestones, and escalation requirements<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> A risk treatment plan becomes actionable when responsibilities and timelines are explicit. Each action should have an accountable owner, expected completion date, status tracking, and escalation procedure for delay. Material dependencies and interim controls should also be documented where appropriate. Writing a plan does not reduce risk by itself; risk remains until treatment is implemented and shown to be effective. Clear ownership allows management to track progress and determine whether delays are increasing residual exposure. This is particularly important when AI risk treatment spans multiple teams such as legal, privacy, security, data science, and operations.<\/span><\/p>\n<p><b>Q172. A control requires a monthly review of privileged access to AI model repositories. What evidence BEST demonstrates operating effectiveness?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The written access-review policy only<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> The repository&#8217;s model accuracy score<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Completed periodic reviews showing exceptions were identified and remediated<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> A statement from the model owner that access is secure<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Completed periodic reviews showing exceptions were identified and remediated<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Operating effectiveness requires evidence that the control actually occurred as designed and produced appropriate action. Completed review records should show who performed the review, what access was evaluated, what exceptions were identified, and how inappropriate permissions were removed or escalated. A policy demonstrates control design but not execution. Similarly, verbal assurance from an owner is weaker than objective records. For material AI assets, access reviews help ensure privilege remains appropriate as employees change roles, projects end, or external collaborators lose legitimate need for repository access.<\/span><\/p>\n<p><b>Q173. An AI governance program has accumulated several controls that address the same risk in nearly identical ways. What should management consider?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Control rationalization to remove unnecessary duplication while preserving risk coverage<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Adding more duplicate controls automatically<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Eliminating the underlying risk from the register<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Stopping all control testing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Control rationalization to remove unnecessary duplication while preserving risk coverage<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Control rationalization evaluates overlapping safeguards to determine whether they provide distinct value or merely create unnecessary complexity and cost. Duplicate controls can increase administrative burden, produce inconsistent evidence, and make accountability unclear without materially reducing risk. Management should map controls to risk objectives, evaluate their effectiveness, and retain an appropriate combination of preventive, detective, and corrective coverage. Rationalization is not simply cost cutting; controls should be removed or consolidated only when adequate risk reduction remains. Simplified control environments can improve ownership, testing, and reporting when designed carefully.<\/span><\/p>\n<p><b>Q174. Management wants continuous assurance that a critical automated AI access control remains correctly configured. Which approach is BEST?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Continuous control monitoring using automated configuration or compliance checks<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Review the control once when initially implemented<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Wait for an incident before testing it<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Depend only on annual employee training<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Continuous control monitoring using automated configuration or compliance checks<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Some technical controls can be monitored continuously or at high frequency using automated checks. For example, the organization can verify that privileged access restrictions, encryption settings, or approved configurations remain in place and alert when drift occurs. Continuous monitoring provides faster detection than periodic manual review and can be particularly valuable for rapidly changing AI environments. It does not eliminate the need for independent assurance or broader control assessment, but it strengthens ongoing visibility into operational effectiveness. The monitoring logic itself should also be governed, tested, and protected from unauthorized modification.<\/span><\/p>\n<p><b>Q175. An AI risk dashboard shows the number of prompt-injection attempts detected each week. What makes this metric useful as a KRI?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> It is easy to count regardless of relevance<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Trends may indicate changing exposure to a defined AI threat scenario<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> It guarantees that every attack is successfully blocked<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> It replaces incident analysis<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Trends may indicate changing exposure to a defined AI threat scenario<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> A KRI is useful when it has a clear relationship to the underlying risk. Increasing prompt-injection attempts may indicate rising adversarial attention or exposure and can prompt review of controls, detection, or user-facing interfaces. The metric must be interpreted carefully because higher detection counts could also result from improved monitoring. It should therefore be considered alongside control effectiveness, successful bypasses, exposure levels, and other contextual information. A KRI does not prove that every attempt was prevented; rather, it provides information that helps management understand whether the risk environment is changing.<\/span><\/p>\n<p><b>Q176. A risk report compares this quarter&#8217;s AI residual risk scores with last quarter&#8217;s scores. What additional information would make the report MOST useful?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Explanation of material changes, causes, trends, and treatment status<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Only the colors used in the dashboard<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Removal of prior-period values<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> The number of words in each risk description<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Explanation of material changes, causes, trends, and treatment status<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Risk reporting should explain why exposure changed, not merely present two numbers. Management needs to understand whether movements resulted from new threats, ineffective controls, business expansion, model changes, regulatory developments, incidents, or completed remediation. Trend context also helps distinguish temporary variation from sustained deterioration. Treatment status shows whether responsible owners are responding appropriately. A dashboard that displays scores without explanation can create false confidence or unnecessary alarm. Good risk communication links metrics to causes, business implications, ownership, and required decisions.<\/span><\/p>\n<p><b>Q177. An AI service relies on a third-party API that is not contractually required to provide incident notifications. What is the PRIMARY concern?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The organization may learn too late about vendor events that affect its own risk or obligations<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> The API will necessarily be unavailable<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> The AI model cannot be trained<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> The vendor will automatically own all customer data<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. The organization may learn too late about vendor events that affect its own risk or obligations<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Timely vendor incident notification enables customers to assess exposure, invoke continuity measures, investigate data impact, and meet their own regulatory or contractual deadlines. Without notification obligations, a customer may remain unaware of an event that affects its AI services or sensitive information. Contracts should define appropriate notification triggers, timelines, communication channels, investigation cooperation, and evidence availability based on service criticality. The lack of a clause does not mean an incident will occur, but it weakens the customer&#8217;s ability to respond effectively if one does.<\/span><\/p>\n<p><b>Q178. A critical AI provider announces that it will discontinue a service in 90 days. What should the organization do FIRST?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Wait until the last week before migration<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Activate the documented exit and transition plan and assess business impact<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Delete all existing AI data immediately<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Assume the provider will reverse the decision<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Activate the documented exit and transition plan and assess business impact<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Service discontinuation is exactly the type of scenario an exit strategy should address. The organization should identify affected business processes and dependencies, review contractual obligations, confirm data portability, evaluate alternatives, establish a transition schedule, and communicate with stakeholders. Ninety days may be a short period for complex AI services, particularly when retraining, integration, validation, or regulatory approvals are required. Acting quickly provides more options and reduces the likelihood of business disruption. Exit readiness is an important component of AI supply-chain and concentration-risk management.<\/span><\/p>\n<p><b>Q179. An AI incident did not cause actual harm because an operator detected the problem immediately before an automated action executed. How should the event be treated?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Ignore it because no loss occurred<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Delete all evidence of the event<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Record and analyze it as a near miss to improve risk controls<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Automatically classify it as a disaster<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Record and analyze it as a near miss to improve risk controls<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Near misses provide valuable information about weaknesses that could produce future incidents. The organization should capture what occurred, why existing controls nearly failed, which safeguard prevented harm, and whether improvements are needed. Near-miss trends can reveal emerging threats or control deterioration before material losses occur. Treating them as learning opportunities strengthens proactive risk management. The event should not automatically receive the same severity as an actual major incident, but it should be assessed according to potential impact and incorporated into relevant risk scenarios, control reviews, and training.<\/span><\/p>\n<p><b>Q180. A disaster recovery test restores an AI application successfully but cannot restore the model artifact version that was active when the backup was created. What does this MOST directly indicate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Business continuity objectives have automatically been met<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> The model no longer requires version control<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> The incident response plan is unnecessary<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Recovery procedures do not adequately protect required AI assets and configuration state**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Recovery procedures do not adequately protect required AI assets and configuration state<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> AI recovery requires more than restoring application servers. The organization may need model artifacts, configuration, prompts, dependencies, feature definitions, datasets, credentials, and other components associated with an approved version. If the application is restored but the required model cannot be recovered, the service may produce different behavior or fail validation. Disaster recovery testing should therefore verify that the complete set of necessary AI assets can be restored consistently and within defined objectives. Testing exposes these gaps before a real disruption, allowing backup and recovery procedures to be strengthened.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Isaca AAIR Exam Dumps and Practice Test Dumps. Q161. An organization allows a high-impact AI system to make decisions affecting customers. What governance mechanism is MOST important for customers who believe an AI-supported decision is incorrect? Increasing model complexity 2. Publishing the model&#8217;s source code 3. Removing human review to ensure consistency 4. [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18341"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=18341"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18341\/revisions"}],"predecessor-version":[{"id":18342,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18341\/revisions\/18342"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=18341"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=18341"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=18341"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}