{"id":18345,"date":"2026-09-22T06:51:08","date_gmt":"2026-09-22T06:51:08","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=18345"},"modified":"2026-09-22T06:51:08","modified_gmt":"2026-09-22T06:51:08","slug":"isaca-aair-practice-test-questions-and-exam-dumps-part11-q201-220","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/isaca-aair-practice-test-questions-and-exam-dumps-part11-q201-220\/","title":{"rendered":"Isaca AAIR Practice Test Questions and Exam Dumps Part11 Q201-220"},"content":{"rendered":"<p><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/aair-exam-dumps\"><b>Isaca AAIR Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/p>\n<p><b><br \/>\n<\/b><b>Q201. An organization has an enterprise AI policy, but several business units interpret the requirement for \u201cmeaningful human oversight\u201d differently. What should the AI risk function do FIRST?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Allow each business unit to define the term independently<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Establish enterprise criteria describing when and how meaningful human oversight must operate<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Require human approval for every AI-generated output<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Remove the requirement because it is difficult to measure<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Establish enterprise criteria describing when and how meaningful human oversight must operate<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Governance terminology should be translated into consistent operational expectations. The organization should define what meaningful human oversight requires based on factors such as decision impact, reviewer authority, information available to reviewers, timing of intervention, override capability, competence, and escalation procedures. Different systems may require different levels of oversight, but the underlying criteria should be consistent. Requiring human approval for every AI output can create unnecessary burden and automation bias, while allowing every business unit to define the concept independently creates inconsistent treatment of similar risks.<\/span><\/p>\n<p><b>Q202. A multinational organization is preparing evidence to demonstrate compliance with AI-related regulatory obligations. Which evidence is MOST useful?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A list of AI vendors only<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Marketing descriptions of AI systems<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> The number of AI developers employed<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Traceable documentation linking applicable requirements to controls, owners, testing, and evidence**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Traceable documentation linking applicable requirements to controls, owners, testing, and evidence<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Regulatory compliance is strongest when the organization can demonstrate how specific obligations are implemented and monitored. Traceability should connect applicable requirements to responsible owners, policies, technical or procedural controls, testing results, exceptions, and supporting evidence. This helps identify gaps and supports audits, regulatory inquiries, and management assurance. A vendor list or marketing description provides little evidence that regulatory requirements are actually being met. Compliance evidence should also remain current as systems, regulations, and business uses change.<\/span><\/p>\n<p><b>Q203. A company is assessing whether an autonomous AI agent should be allowed to approve customer refunds. Which factor should have the GREATEST influence on the permitted autonomy level?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The potential business and customer impact if the agent makes an incorrect decision<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> The number of parameters in the underlying model<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> The age of the AI vendor<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> The programming language used to build the agent<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. The potential business and customer impact if the agent makes an incorrect decision<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Autonomy should be proportionate to the consequences of error, reversibility, affected stakeholders, and organizational risk appetite. A low-value, easily reversible transaction may justify more automation than a high-value refund with fraud, legal, or customer implications. The organization should consider thresholds, human approval, transaction limits, monitoring, tool permissions, and rollback mechanisms. Model size, vendor age, and programming language do not directly determine the acceptable level of autonomous authority. AI governance should focus on risk created by the use case rather than technical novelty alone.<\/span><\/p>\n<p><b>Q204. An AI governance committee notices that most policy exceptions originate from one business process. What is the BEST next action?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Automatically approve future exceptions from that process<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Remove the process from governance requirements<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Analyze the root cause to determine whether the policy, control, tooling, or process design needs improvement<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Stop tracking exceptions to reduce reporting volume<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Analyze the root cause to determine whether the policy, control, tooling, or process design needs improvement<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Repeated exceptions are valuable governance signals. They may indicate that a control is impractical, a business process has unique requirements, users lack suitable tools, or policy language is unclear. Management should analyze the pattern before deciding whether stronger enforcement, process redesign, additional tooling, or policy revision is appropriate. Automatically approving recurring exceptions can normalize unmanaged risk. Good governance uses exception trends to improve the control environment rather than treating each exception as an isolated administrative event.<\/span><\/p>\n<p><b>Q205. A model-development team uses external workers to label sensitive training data. What risk should receive PARTICULAR attention?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Whether workers use identical monitors<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> The color scheme of the labeling tool<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Whether the dataset is large enough<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Confidentiality, access control, labeling quality, and third-party handling of sensitive data**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Confidentiality, access control, labeling quality, and third-party handling of sensitive data<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> External data labeling can create privacy, security, quality, and supply-chain risk. The organization should determine what information workers can access, whether access is limited to legitimate need, how confidentiality is enforced, how labeling quality is verified, and whether subcontractors are involved. Poor labeling can degrade model performance or introduce bias, while excessive data access can create privacy or intellectual-property exposure. Contracts, access restrictions, quality sampling, monitoring, and secure work environments may all be appropriate depending on the sensitivity and importance of the data.<\/span><\/p>\n<p><b>Q206. A high-risk AI model is tested using a benchmark selected by the same team that optimized the model against that benchmark. What is the PRIMARY concern?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Lack of sufficiently independent validation evidence<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> The benchmark will always be too difficult<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Independent testing is unnecessary if accuracy is high<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> The model cannot be deployed in the cloud<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Lack of sufficiently independent validation evidence<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> When the same team selects and optimizes against the evaluation benchmark, there is a risk that the model is effectively tuned to the test rather than independently assessed. High-risk systems benefit from validation that provides objective challenge and uses representative evaluation data not overly influenced by model-development decisions. Independence can reduce confirmation bias and provide stronger evidence for approval. This does not necessarily require a completely separate organization in every case, but the degree of independence should reflect system impact and risk.<\/span><\/p>\n<p><b>Q207. An organization is procuring an AI model through an API, but the provider may update the underlying model without changing the API endpoint. Which control is MOST important?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Increase the organization&#8217;s network bandwidth<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Require version transparency, material-change notification, and reassessment when the underlying model changes<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Assume an unchanged API means model behavior cannot change<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Remove post-deployment monitoring<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Require version transparency, material-change notification, and reassessment when the underlying model changes<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> An API can remain technically stable while the underlying model changes materially. Such changes may affect accuracy, fairness, safety, privacy, security, explainability, or output format and can invalidate earlier testing. Contracts and technical integrations should provide sufficient model-version visibility and notification of material changes. The organization should determine when revalidation or approval is required. Post-deployment monitoring remains important because not every behavioral change will be fully described by the provider.<\/span><\/p>\n<p><b>Q208. An AI application retrieves internal documents to answer employee questions. What is the MOST important control for preventing one employee from receiving another department&#8217;s restricted information?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Increase retrieval result counts<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Use a larger language model<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Enforce access authorization at the retrieval layer before content reaches the model<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Ask the model not to reveal restricted information<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Enforce access authorization at the retrieval layer before content reaches the model<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Sensitive information should be filtered before it enters the language model&#8217;s context. Retrieval systems should use authenticated identity and document permissions to ensure users receive only information they are authorized to access. Prompt instructions are not a reliable security boundary because information already supplied to a model may be disclosed or indirectly exposed. Metadata filtering, tenant restrictions, document-level authorization, and audit logging can support secure retrieval. Access controls should be enforced deterministically rather than depending on model judgment.<\/span><\/p>\n<p><b>Q209. A risk workshop identifies dozens of possible AI failure events but struggles to prioritize them. What should participants do NEXT?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Evaluate each material scenario using defined likelihood, impact, exposure, and risk appetite criteria<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Prioritize scenarios alphabetically<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Focus only on scenarios that have already occurred<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Remove scenarios that lack precise historical statistics<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Evaluate each material scenario using defined likelihood, impact, exposure, and risk appetite criteria<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Risk identification should be followed by structured assessment. Defined criteria help participants compare scenarios consistently and determine which require treatment, escalation, monitoring, or acceptance. Emerging AI risks may not have extensive historical data, so expert judgment, scenario analysis, uncertainty ranges, and threat intelligence may also be needed. Prioritizing only previously observed events can miss novel risks. Assessment should connect technical scenarios to business consequences and organizational risk appetite.<\/span><\/p>\n<p><b>Q210. An organization has very limited historical loss data for a new AI threat. Which risk assessment approach is MOST appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Assign zero likelihood because no losses have occurred<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Refuse to assess the risk<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Use only the most optimistic estimate<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Use structured expert judgment, scenarios, external evidence, and documented uncertainty**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Use structured expert judgment, scenarios, external evidence, and documented uncertainty<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Emerging risks often lack sufficient internal historical data for purely statistical estimation. Organizations can still assess them using structured expert judgment, threat intelligence, industry events, scenario analysis, analogies, and probability or impact ranges. Assumptions and uncertainty should be documented clearly so decision-makers understand the confidence level. Treating a lack of past losses as proof of zero risk is especially dangerous in fast-moving AI environments where new attack techniques or regulatory requirements may emerge quickly.<\/span><\/p>\n<p><b>Q211. An AI risk is mitigated by three controls, but all three depend on the same identity system. What should the risk professional consider?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The controls are automatically independent because there are three of them<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Only the strongest control matters<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Common-mode failure could reduce the effectiveness of all three controls simultaneously<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Residual risk must therefore be zero<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Common-mode failure could reduce the effectiveness of all three controls simultaneously<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Multiple controls do not necessarily provide true defense in depth when they share a critical dependency. If the same identity service supports access control, approvals, and monitoring, compromise or outage of that system may weaken all three controls at once. Risk assessment should identify common dependencies and determine whether additional independent safeguards are needed. Control counts alone can create false confidence. Effective layered protection considers independence, failure modes, and whether one event can bypass several safeguards simultaneously.<\/span><\/p>\n<p><b>Q212. An organization decides to accept an AI risk because the cost of treatment exceeds the expected benefit. What is MOST important before formal acceptance?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Remove the risk from monitoring<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Confirm that residual risk is understood, within authorized tolerance, and accepted by the appropriate risk owner<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Ensure no one documents the rationale<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Transfer accountability to the AI vendor<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Confirm that residual risk is understood, within authorized tolerance, and accepted by the appropriate risk owner<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Cost-benefit analysis can inform treatment decisions, but risk acceptance must remain within governance boundaries. The risk owner should understand the scenario, expected consequences, control environment, uncertainty, and remaining exposure before accepting it. Acceptance should be documented and may include review dates or monitoring conditions. If exposure exceeds risk appetite, the appropriate higher-level authority may need to decide whether strategy or appetite should change. Acceptance does not eliminate the risk or transfer accountability to a supplier.<\/span><\/p>\n<p><b>Q213. An automated AI control blocks certain high-risk transactions. Which testing BEST demonstrates that the control is operating effectively?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Verify through representative test cases and production evidence that prohibited transactions are actually blocked as designed<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Review only the control&#8217;s written description<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Ask the developer whether the control works<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Measure only model accuracy<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Verify through representative test cases and production evidence that prohibited transactions are actually blocked as designed<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Operating effectiveness requires evidence that a control functions consistently in practice. Testing should include representative allowed and prohibited scenarios and confirm that actual behavior matches the control objective. Production monitoring or samples can supplement controlled testing. Documentation shows design intent but not whether implementation works. The organization should also assess failure handling and whether authorized exceptions are processed correctly. For critical automated controls, periodic or continuous testing can provide stronger assurance.<\/span><\/p>\n<p><b>Q214. An organization has several AI controls with no identified owner. What is the GREATEST risk?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Controls will necessarily increase model accuracy<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> The AI inventory will become unnecessary<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Vendor contracts will automatically expire<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Control operation, monitoring, remediation, and evidence collection may not be performed consistently**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Control operation, monitoring, remediation, and evidence collection may not be performed consistently<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Controls require clear ownership so someone is accountable for operating, monitoring, maintaining, testing, and remediating them. Without an owner, failures can persist unnoticed, evidence may not be collected, and required changes may be delayed. Control ownership should be documented and aligned with organizational authority and expertise. Ownership does not mean one person performs every activity; responsibilities may be distributed, but accountability must remain clear. This is particularly important for AI controls spanning business, technical, privacy, security, and compliance functions.<\/span><\/p>\n<p><b>Q215. A KRI reports the number of harmful AI outputs, but reporting occurs six months after the outputs occur. What is the PRIMARY weakness?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The metric necessarily has the wrong formula<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> The KRI may be too untimely to support effective risk response<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> All AI KRIs must be reported daily<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Harmful outputs should not be measured<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. The KRI may be too untimely to support effective risk response<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Effective risk indicators must be sufficiently timely to influence decisions. A technically accurate measure that arrives six months late may be of limited value for fast-moving AI risks. Reporting frequency should reflect risk velocity, control response time, and business consequences. Some exposures require near-real-time monitoring, while others can be reviewed monthly or quarterly. The organization should determine whether the current frequency enables meaningful intervention before exposure becomes unacceptable.<\/span><\/p>\n<p><b>Q216. A board receives AI risk ratings but cannot tell whether risk is increasing or decreasing. What reporting improvement would be MOST useful?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Add trend information, key drivers, tolerance status, and treatment progress<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Remove prior-period comparisons<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Show only raw technical logs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Replace risk ratings with model parameter counts<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Add trend information, key drivers, tolerance status, and treatment progress<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Board reporting should provide context around current exposure. Trends show whether risk is improving or deteriorating; key drivers explain why; tolerance status highlights where action may be necessary; and treatment progress indicates whether management is responding effectively. A static rating without context may not support strategic decisions. Detailed technical data can remain available for specialists, but executive reporting should focus on material changes, business implications, and decisions requiring leadership attention.<\/span><\/p>\n<p><b>Q217. A critical AI provider uses several subcontractors but does not disclose changes to those subcontractors. What contractual requirement would BEST reduce this risk?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Require notification and appropriate oversight of material subcontractor changes<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Prohibit the vendor from using any technology providers<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Remove supply-chain requirements from the contract<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Allow unrestricted subcontracting without customer visibility<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Require notification and appropriate oversight of material subcontractor changes<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Changes in material subcontractors can affect data handling, security, resilience, compliance, and geographic processing. Contracts should require appropriate visibility into significant subcontractor changes and may provide objection, assessment, or remediation rights depending on risk. The organization does not necessarily need control over every minor supplier, but critical dependencies should be governed. Supply-chain risk extends beyond direct vendors, so contractual provisions should support ongoing visibility rather than only initial due diligence.<\/span><\/p>\n<p><b>Q218. An AI vendor stores customer data after contract termination even though the agreement requires deletion. What is the BEST evidence that the termination requirement was completed?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The vendor&#8217;s verbal statement<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Appropriate deletion certification or other independently supportable evidence<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> The original sales proposal<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> The number of users who stopped logging in<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Appropriate deletion certification or other independently supportable evidence<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Contract termination should include verification that data return, migration, retention, and deletion obligations were performed. Depending on risk, evidence might include a deletion certificate, audit report, technical confirmation, or other independently supportable documentation. A verbal statement provides weaker assurance, particularly for sensitive or regulated information. Exit processes should also address backups, subprocessors, residual accounts, encryption keys, logs, and other data locations where applicable. Supplier offboarding is part of lifecycle and supply-chain risk management.<\/span><\/p>\n<p><b>Q219. An AI incident involves a model producing discriminatory outcomes for a group of customers. Which incident-response participant is MOST important in addition to technical teams?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only infrastructure operations<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Only the model vendor<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Relevant legal, compliance, risk, business, and potentially privacy or ethics stakeholders<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> No additional stakeholders because this is a model issue<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Relevant legal, compliance, risk, business, and potentially privacy or ethics stakeholders<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> AI incidents can involve legal, regulatory, customer, ethical, reputational, and business consequences that extend beyond technical remediation. A discrimination-related incident may require assessment of affected individuals, regulatory obligations, remediation of decisions, communications, legal exposure, and fairness controls. Incident-response plans should therefore identify cross-functional stakeholders in advance. Technical teams remain important for containment and root-cause analysis, but they may not have authority or expertise to address all consequences of the event.<\/span><\/p>\n<p><b>Q220. A disaster recovery test restores the AI model and data successfully, but authentication services required by the application remain unavailable. What does this demonstrate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Recovery is complete because model data was restored<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Authentication is unrelated to AI recovery<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> The DR plan should exclude shared services<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Recovery testing must include critical dependencies required for end-to-end service operation**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Recovery testing must include critical dependencies required for end-to-end service operation<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> An AI service is not recovered simply because model files and data are available. Identity services, APIs, databases, networks, feature stores, encryption keys, and other shared dependencies may be required for end-to-end operation. Business impact analysis and disaster recovery planning should identify these dependencies and define recovery sequencing and objectives. Testing should verify that the complete business service works, not merely that individual components start. Dependency failures discovered during exercises should be used to improve recovery architecture and procedures.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Isaca AAIR Exam Dumps and Practice Test Dumps. Q201. An organization has an enterprise AI policy, but several business units interpret the requirement for \u201cmeaningful human oversight\u201d differently. What should the AI risk function do FIRST? Allow each business unit to define the term independently 2. Establish enterprise criteria describing when and how [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18345"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=18345"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18345\/revisions"}],"predecessor-version":[{"id":18346,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18345\/revisions\/18346"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=18345"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=18345"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=18345"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}