{"id":18347,"date":"2026-09-22T06:51:24","date_gmt":"2026-09-22T06:51:24","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=18347"},"modified":"2026-09-22T06:51:24","modified_gmt":"2026-09-22T06:51:24","slug":"isaca-aair-practice-test-questions-and-exam-dumps-part12-q221-240","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/isaca-aair-practice-test-questions-and-exam-dumps-part12-q221-240\/","title":{"rendered":"Isaca AAIR Practice Test Questions and Exam Dumps Part12 Q221-240"},"content":{"rendered":"<p><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/aair-exam-dumps\"><b>Isaca AAIR Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/p>\n<p><b><br \/>\n<\/b><b>Q221. An organization wants to measure whether its AI risk governance capability is improving over time. Which approach is MOST appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Count only the number of AI systems deployed<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Measure only annual AI spending<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Assess governance maturity against defined capabilities, outcomes, and improvement targets<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Compare the number of developers with competitors<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Assess governance maturity against defined capabilities, outcomes, and improvement targets<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> A maturity assessment evaluates how consistently and effectively AI risk practices are established, integrated, measured, and improved. It can examine areas such as ownership, policies, lifecycle controls, risk assessments, reporting, monitoring, incident response, and third-party governance. Comparing results over time helps management identify weaknesses and prioritize investment. Counting systems or spending does not demonstrate whether governance is effective. Maturity should also be interpreted in relation to organizational objectives and risk appetite; the goal is not necessarily maximum maturity in every area, but sufficient capability for the organization&#8217;s actual AI exposure.<\/span><\/p>\n<p><b>Q222. An AI inventory lists model names and technical owners but does not identify the business processes each model supports. What is the MOST important improvement?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Link each AI asset to its business purpose, accountable owner, and affected process<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Remove technical ownership information<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> List only externally purchased models<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Replace the inventory with a model-performance report<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Link each AI asset to its business purpose, accountable owner, and affected process<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> AI assets should be connected to the business context in which they operate. Knowing the supported process, intended use, accountable owner, criticality, and affected stakeholders helps the organization assess impact, classify risk, plan continuity, and identify appropriate controls. A purely technical inventory can show what exists but may not explain why it matters. Business linkage is also valuable during incidents, regulatory reviews, and decommissioning because teams can determine which processes depend on the affected system and who has authority to make risk decisions.<\/span><\/p>\n<p><b>Q223. An enterprise-level AI risk appetite statement allows moderate experimentation, but one business unit interprets this as permission to deploy high-impact autonomous systems without approval. What is the BEST response?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Permit the deployment because experimentation is encouraged<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Remove the enterprise risk appetite statement<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Allow each business unit to reinterpret risk appetite independently<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Cascade risk appetite into specific tolerances, approval thresholds, and autonomy limits**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Cascade risk appetite into specific tolerances, approval thresholds, and autonomy limits<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Broad risk appetite statements need operational interpretation. Specific tolerances and decision thresholds clarify what types of experimentation are allowed, which use cases require enhanced review, and what levels of autonomy or potential impact require senior approval. This prevents inconsistent interpretations across business units. High-impact autonomous systems may create substantially different exposure from low-risk experimentation even if both involve AI innovation. Cascading appetite into actionable limits enables teams to innovate within defined boundaries while preserving enterprise governance and accountability.<\/span><\/p>\n<p><b>Q224. An AI system becomes subject to a legal investigation. What should happen to records that would normally be deleted under the standard retention schedule?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Delete them according to the normal schedule regardless of the investigation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Preserve relevant records under an appropriate legal hold process<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Make the records publicly accessible<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Transfer all records to the AI vendor automatically<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Preserve relevant records under an appropriate legal hold process<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> A legal hold can suspend normal deletion or destruction of records that may be relevant to litigation, investigation, or regulatory review. Relevant AI evidence might include prompts, outputs, model versions, logs, approvals, datasets, configuration, and decision records. The hold should be implemented in coordination with legal counsel and appropriate records-management processes. Continuing normal deletion after a preservation obligation is known can create serious legal risk. The organization should also control access and maintain integrity while retaining only material information within the scope of the hold.<\/span><\/p>\n<p><b>Q225. An AI governance program requires reassessment only when source code changes. What is the PRIMARY weakness in this rule?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Material changes to data, prompts, models, dependencies, or business use can alter risk even without code changes<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Source code is never relevant to AI risk<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Every AI system must be reassessed daily<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Change management is unnecessary for AI systems<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Material changes to data, prompts, models, dependencies, or business use can alter risk even without code changes<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> AI behavior depends on more than application source code. Retraining data, system prompts, foundation-model versions, retrieved knowledge sources, third-party APIs, autonomy levels, and intended use can all materially change risk. Change-management criteria should therefore consider behavioral and contextual impact rather than only traditional code modifications. Risk-based reassessment thresholds can distinguish minor changes from those requiring renewed validation, approval, or documentation. A narrow code-only trigger can allow significant behavioral changes to bypass governance.<\/span><\/p>\n<p><b>Q226. Several AI models consume features from a shared enterprise feature store. Which governance concern is MOST important?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Whether every feature has the same name length<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Whether models use identical algorithms<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Whether the feature store uses the newest database engine<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Data quality, lineage, ownership, access, and change control for shared features**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Data quality, lineage, ownership, access, and change control for shared features<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> A shared feature store can influence many AI models simultaneously. Incorrect, stale, unauthorized, or poorly governed features can therefore create systemic risk across the portfolio. The organization should define ownership, lineage, data-quality requirements, access controls, versioning, and change procedures for important features. Changes should be evaluated for downstream impact because one modified feature can affect multiple models. Strong feature governance also helps support reproducibility, troubleshooting, and regulatory evidence when models rely on common transformed data.<\/span><\/p>\n<p><b>Q227. A model-training dataset contains labels generated automatically by another algorithm rather than by verified human review. What should the risk professional emphasize?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Automatically generated labels are always more accurate than human labels<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Label quality and potential systematic error should be validated before relying on the data<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Label provenance is irrelevant to model risk<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> The model should be deployed before label validation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Label quality and potential systematic error should be validated before relying on the data<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Labels directly influence what a supervised model learns. If labels are generated by another algorithm, errors or biases in the labeling mechanism may propagate into the trained model at scale. The organization should evaluate label accuracy, sampling methodology, known failure modes, and whether manual review or other validation is required. Label provenance should also be documented. Automatically generated labels can be useful for efficiency, but they are not inherently trustworthy and should be governed according to their impact on the resulting model.<\/span><\/p>\n<p><b>Q228. An organization performs adversarial testing against an AI system before deployment. What is the PRIMARY purpose of documenting the exact test scenarios and results?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To prove that future attacks are impossible<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> To eliminate the need for monitoring<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> To establish reproducible evidence of tested weaknesses, controls, and residual risk<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> To increase model size<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. To establish reproducible evidence of tested weaknesses, controls, and residual risk<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Documenting adversarial tests allows reviewers to understand which scenarios were evaluated, how the model behaved, which controls were effective, and what weaknesses remain. This supports approval, comparison between versions, regression testing, incident response, and regulatory or assurance activities. Testing can never prove that all future attacks will fail because adversarial techniques evolve. Reproducible evidence is therefore valuable for demonstrating what was reasonably tested at a particular time and for determining whether later model changes require retesting.<\/span><\/p>\n<p><b>Q229. A production AI model can be queried by thousands of external users. What control BEST reduces the risk of systematic model extraction through excessive querying?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Increase output detail for all users<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Remove authentication<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Publish training data<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Apply appropriate authentication, rate limits, monitoring, and anomaly detection**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Apply appropriate authentication, rate limits, monitoring, and anomaly detection<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Model extraction attacks often rely on large numbers of carefully selected queries. Restricting access, enforcing rate limits, monitoring query patterns, and identifying abnormal behavior can increase the cost and detectability of extraction attempts. The organization may also limit unnecessary output detail or apply contractual restrictions. These controls do not guarantee that extraction is impossible, but they can materially reduce exposure. Publicly exposing additional model or training information would generally increase rather than reduce intellectual-property and security risk.<\/span><\/p>\n<p><b>Q230. A quantitative AI risk estimate is based on several uncertain assumptions. What is the BEST way to communicate the result to management?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Present ranges, assumptions, and sensitivity rather than implying false precision<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Report only one exact number without qualifications<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Hide uncertainty to simplify decision-making<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Remove the risk from quantitative analysis<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Present ranges, assumptions, and sensitivity rather than implying false precision<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Quantitative analysis is useful only when uncertainty is communicated honestly. AI risks often involve limited historical data, rapidly changing threats, and uncertain consequences. Reporting ranges, confidence levels, assumptions, or sensitivity analysis helps decision-makers understand how robust the estimate is and which variables drive the result. A single precise number can create false confidence when underlying inputs are uncertain. Transparent uncertainty allows management to make better treatment decisions and identify where additional data would most improve the assessment.<\/span><\/p>\n<p><b>Q231. An organization wants to evaluate whether several AI controls together provide sufficient coverage for a risk scenario. Which analysis is MOST useful?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Count the total number of controls only<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Review only the least expensive control<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Map preventive, detective, and corrective controls to the risk scenario and identify coverage gaps<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Assume multiple controls automatically eliminate residual risk<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Map preventive, detective, and corrective controls to the risk scenario and identify coverage gaps<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Control coverage should be evaluated against the risk scenario rather than by counting safeguards. The organization should identify which controls prevent the event, which detect it, which limit consequences, and whether important failure paths remain unaddressed. It should also consider control dependencies and whether multiple controls could fail for the same reason. This mapping provides a stronger basis for residual-risk assessment than simply noting that several controls exist. Layered coverage is valuable only when controls address relevant parts of the scenario effectively.<\/span><\/p>\n<p><b>Q232. An AI risk treatment reduces likelihood but does not reduce the severity of consequences if failure occurs. What should the residual-risk assessment reflect?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Impact should automatically be set to zero<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Lower likelihood while preserving the relevant impact assessment<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> The risk should be removed from the register<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Treatment effectiveness should be ignored<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Lower likelihood while preserving the relevant impact assessment<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Risk treatments can affect likelihood, impact, or both. If a control makes the event less probable but does not reduce the consequence when it occurs, the residual-risk assessment should reflect that specific effect. Setting impact to zero would overstate the control&#8217;s benefit. Clear linkage between controls and the dimensions they affect improves transparency and prevents unrealistic residual-risk ratings. This is particularly important for AI scenarios where preventive controls may reduce frequency while severe customer, safety, or regulatory consequences remain possible if the event still occurs.<\/span><\/p>\n<p><b>Q233. Management wants to know whether AI control deficiencies are becoming more concentrated in one business unit. Which metric is MOST useful?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Trend of control exceptions or failures by business unit and severity<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Total enterprise revenue<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Number of AI model parameters<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Number of office locations<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Trend of control exceptions or failures by business unit and severity<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Segmenting control failures by organizational unit and severity can reveal whether weaknesses are concentrated in one area and whether the pattern is worsening. This helps management investigate local process issues, insufficient resources, training gaps, poor leadership reinforcement, or inappropriate control design. Enterprise totals alone can hide concentration. Metrics should also distinguish minor exceptions from failures affecting high-risk AI systems. Trend analysis is useful when linked to escalation thresholds and accountable owners who can address recurring weaknesses.<\/span><\/p>\n<p><b>Q234. A risk dashboard uses green, amber, and red statuses, but different teams apply the colors inconsistently. What should be done?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Eliminate all status reporting<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Define standardized thresholds and criteria for each status<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Let each team choose colors based on judgment alone<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Use only green to simplify reporting<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Define standardized thresholds and criteria for each status<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Risk dashboards need consistent definitions so management can compare information across systems and business units. Clear criteria should define what green, amber, and red represent, including quantitative thresholds, qualitative triggers, and escalation requirements where appropriate. Without consistency, the same exposure may appear green in one team and red in another. Standardization does not eliminate professional judgment but provides a common basis for its use. This improves aggregation, reporting reliability, and management confidence in AI risk metrics.<\/span><\/p>\n<p><b>Q235. A critical AI provider experiences financial distress but continues meeting technical service levels. What should the customer do?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Ignore the issue until an outage occurs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Terminate immediately without assessing impact<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Remove the vendor from supply-chain monitoring<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Reassess continuity, exit readiness, concentration exposure, and residual third-party risk**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Reassess continuity, exit readiness, concentration exposure, and residual third-party risk<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Technical performance can remain satisfactory even while a provider&#8217;s financial condition deteriorates. Financial distress may later affect staffing, investment, service continuity, ownership, contractual commitments, or long-term viability. The organization should therefore reassess supplier risk and determine whether additional contingency planning, alternative providers, data portability, or contract protections are needed. Immediate termination may be disproportionate, while ignoring the issue can leave the organization unprepared. Third-party monitoring should include material changes that could affect future service capability.<\/span><\/p>\n<p><b>Q236. A vendor contract states that all customer prompts may be used to improve the vendor&#8217;s models unless customers opt out. What should the organization do BEFORE using the service for confidential information?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Assess and negotiate data-use terms so confidential information is not used beyond approved purposes<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Assume confidential prompts cannot influence vendor training<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Disable internal data classification<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Allow all employees to submit sensitive content immediately<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Assess and negotiate data-use terms so confidential information is not used beyond approved purposes<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> AI service contracts may permit providers to retain or reuse customer prompts and outputs. Before sensitive information is submitted, the organization should understand these terms and ensure data use aligns with confidentiality, privacy, intellectual-property, and regulatory requirements. Enterprise service configurations or contractual amendments may prohibit training use or provide additional isolation. Employees should receive clear guidance about approved services and data categories. Vendor defaults should never be assumed to match the organization&#8217;s data-governance requirements.<\/span><\/p>\n<p><b>Q237. During an AI incident, investigators discover that logs needed to reconstruct model actions were overwritten after seven days. What is the PRIMARY improvement?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Remove logging entirely<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Store only model outputs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Align log retention with incident, regulatory, forensic, and business requirements<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Shorten retention further<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Align log retention with incident, regulatory, forensic, and business requirements<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Log retention should reflect how long evidence may be needed for investigations, regulatory obligations, customer disputes, security monitoring, and audit. Seven days may be insufficient for incidents discovered weeks later. At the same time, retaining all logs indefinitely can create privacy and storage risks, so retention should be purposeful and documented. Important AI logs may include model versions, prompts, outputs, tool calls, approvals, data sources, and system events. Retention should be integrated with records management and evidence-preservation requirements.<\/span><\/p>\n<p><b>Q238. A business continuity exercise shows that the manual fallback process for an AI-supported service can handle only 20% of normal transaction volume. What should management do?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Determine whether reduced fallback capacity meets minimum business requirements and improve the plan if necessary<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Assume any manual process is automatically sufficient<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Remove the AI service from continuity planning<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Increase production transaction volume during outages<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Determine whether reduced fallback capacity meets minimum business requirements and improve the plan if necessary<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> A degraded fallback does not need to match normal capacity if the business can tolerate reduced service, but its capacity must be compared with minimum continuity requirements established through BIA and operational planning. If 20% capacity cannot support critical transactions, management may need additional staffing, prioritization rules, alternate technology, or another recovery strategy. Exercises provide valuable evidence because they reveal whether theoretical fallback procedures can actually meet business needs under disruption.<\/span><\/p>\n<p><b>Q239. A disaster recovery plan assumes that a backup AI model can replace the primary model, but the backup has never been validated against current production data. What is the PRIMARY concern?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The backup model may not be fit for the current business environment<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Backup models never require validation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> DR plans should not include models<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Production data should never be used for validation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. The backup model may not be fit for the current business environment<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> A backup model provides little assurance if its behavior has not been validated against current data, requirements, and dependencies. Changes in customer behavior, features, regulations, or business processes may make an old fallback inaccurate or unsafe. Recovery planning should therefore verify not only that backup artifacts exist but also that they remain suitable for use. Periodic testing can identify stale dependencies or unacceptable performance before an emergency requires failover.<\/span><\/p>\n<p><b>Q240. An organization wants AI to recommend incident severity, but the recommendation could affect regulatory notification deadlines. What is the BEST governance approach?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Allow the AI recommendation to determine severity automatically in all cases<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Remove incident severity criteria<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Use AI as decision support while applying defined severity criteria and authorized human validation for material incidents<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Let the AI redefine regulatory deadlines dynamically<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Use AI as decision support while applying defined severity criteria and authorized human validation for material incidents<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> AI can help analyze incident scope, affected systems, data sensitivity, and potential business impact, but material severity decisions may carry legal, regulatory, and customer-notification consequences. The organization should therefore preserve deterministic severity criteria and accountable human decision-making where appropriate. AI recommendations can improve speed and consistency but should not override documented requirements or regulatory obligations. This approach allows the organization to leverage AI within the risk program while maintaining human accountability for consequential decisions.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Isaca AAIR Exam Dumps and Practice Test Dumps. Q221. An organization wants to measure whether its AI risk governance capability is improving over time. Which approach is MOST appropriate? Count only the number of AI systems deployed 2. Measure only annual AI spending 3. Assess governance maturity against defined capabilities, outcomes, and improvement [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18347"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=18347"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18347\/revisions"}],"predecessor-version":[{"id":18348,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18347\/revisions\/18348"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=18347"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=18347"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=18347"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}