{"id":18357,"date":"2026-09-22T06:53:29","date_gmt":"2026-09-22T06:53:29","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=18357"},"modified":"2026-09-22T06:53:29","modified_gmt":"2026-09-22T06:53:29","slug":"isaca-aair-practice-test-questions-and-exam-dumps-part17-q321-340","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/isaca-aair-practice-test-questions-and-exam-dumps-part17-q321-340\/","title":{"rendered":"Isaca AAIR Practice Test Questions and Exam Dumps Part17 Q321-340"},"content":{"rendered":"<p><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/aair-exam-dumps\"><b>Isaca AAIR Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/p>\n<p><b><br \/>\n<\/b><b>Q321. An organization allows business units to propose AI projects, but many proposals contain no defined business problem or expected benefit. What should the AI risk function recommend FIRST?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Require each proposed use case to define business objectives, expected value, and relevant risk assumptions<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Approve projects if the technology is innovative<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Prioritize projects according to model size<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Evaluate risk only after implementation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Require each proposed use case to define business objectives, expected value, and relevant risk assumptions<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> AI governance should begin with a clearly defined business purpose. A use case should explain the problem being addressed, expected value, affected stakeholders, and important assumptions before significant development begins. This provides context for evaluating whether potential benefits justify privacy, fairness, security, operational, or regulatory exposure. Without a business objective, management cannot determine whether an AI system is suitable or whether its risks are proportionate to expected value. ISACA\u2019s AAIR scope emphasizes evaluating AI use cases against organizational objectives and risk appetite rather than treating AI deployment as an end in itself.<\/span><\/p>\n<p><b>Q322. An AI governance body routinely approves projects but never reviews whether previously approved systems remain aligned with business objectives. What governance improvement is MOST appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Increase the number of development approvals<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Remove business owners from the governance process<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Review only systems that experience incidents<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Establish periodic lifecycle reviews of continued business value, risk, and suitability**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Establish periodic lifecycle reviews of continued business value, risk, and suitability<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> AI governance should continue after initial approval. Business priorities, regulations, data, models, stakeholders, and risk can change substantially during the life of an AI system. Periodic lifecycle reviews help determine whether the system still provides sufficient value, operates within approved risk tolerance, and remains suitable for its intended purpose. Reviews can also identify systems that should be modified or retired. Limiting governance to initial deployment creates the risk that outdated or unnecessary AI systems remain operational even after their business rationale or control assumptions are no longer valid.<\/span><\/p>\n<p><b>Q323. A company must provide evidence that an AI-supported process complies with several internal policies and external standards. Which mechanism provides the BEST traceability?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A control matrix mapping requirements to policies, controls, owners, and evidence<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> A list of developers assigned to the project<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> A model performance chart only<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Vendor marketing documentation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. A control matrix mapping requirements to policies, controls, owners, and evidence<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> A control matrix provides traceability between requirements and the mechanisms used to satisfy them. It can connect internal policy statements, regulatory or framework requirements, responsible owners, specific controls, test procedures, and evidence. This helps management identify gaps and reduces duplicated controls when several requirements overlap. Model performance alone cannot demonstrate compliance with governance, privacy, legal, or security obligations. Traceability also supports audits and reassessment after changes because the organization can determine which requirements and controls may be affected by a modified model, process, or regulatory environment.<\/span><\/p>\n<p><b>Q324. An AI system will provide recommendations used by employees, but management is concerned that users may believe every output is objective. What control is MOST appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Hide the fact that AI is used<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Prevent employees from challenging recommendations<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Communicate relevant limitations and train users to apply appropriate professional judgment<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Increase automation so human judgment is unnecessary<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Communicate relevant limitations and train users to apply appropriate professional judgment<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> AI outputs can appear objective even when they reflect imperfect data, assumptions, biases, or probabilistic reasoning. Users should understand the system\u2019s intended purpose, known limitations, uncertainty, and circumstances requiring additional verification. Training can reduce automation bias and reinforce that accountability remains with authorized employees when decisions require professional judgment. Hiding AI involvement may reduce transparency, while preventing challenge weakens effective oversight. Trustworthy AI governance considers how people interpret and use outputs, not just whether the model performs well under technical evaluation conditions.<\/span><\/p>\n<p><b>Q325. A customer withdraws permission for use of personal data that was previously included in an AI development dataset. What should the organization do FIRST?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Ignore the request because model development already began<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Determine applicable legal obligations, data lineage, and whether the data must be removed or processing restricted<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Delete the entire model immediately<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Permanently retain all related data for model accuracy<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Determine applicable legal obligations, data lineage, and whether the data must be removed or processing restricted<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> The correct response depends on applicable privacy law, the legal basis for processing, technical feasibility, contractual obligations, and how the data has been used. Strong data lineage is important because it allows the organization to identify affected datasets, model-development activities, and derived artifacts. A request does not always require immediate model deletion, but it must be evaluated under applicable obligations. Governance should define procedures for data-subject requests and other privacy changes that can affect AI lifecycle activities. Ignoring the request simply because development has begun may create legal and trust risks.<\/span><\/p>\n<p><b>Q326. An AI development environment allows the same users to modify training data and promote resulting models directly into production. Which control weakness is MOST significant?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Insufficient segregation of duties across data modification and production deployment<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Lack of a larger training dataset<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Excessive model explainability<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Too many independent reviewers<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Insufficient segregation of duties across data modification and production deployment<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Allowing one individual to modify training data and promote the resulting model directly to production creates an opportunity for error, fraud, or unauthorized behavior to bypass independent review. Segregation of duties can separate data preparation, model development, validation, approval, and production deployment according to risk. Complete separation is not always practical in small organizations, but compensating controls such as peer approval, immutable logs, and restricted deployment rights may be necessary. The objective is to ensure that material changes affecting model behavior cannot move into production without appropriate challenge and authorization.<\/span><\/p>\n<p><b>Q327. A model registry contains many experimental models alongside production-approved models. What control MOST reduces the risk that an experimental model is deployed accidentally?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Allow every model to use the same status<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Remove model version identifiers<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Use controlled lifecycle states, approval metadata, and restricted production promotion<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Let developers select any artifact during deployment<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Use controlled lifecycle states, approval metadata, and restricted production promotion<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> A model registry should clearly distinguish experimental, validation, approved, retired, and other lifecycle states where relevant. Production deployment mechanisms should permit only appropriately approved artifacts and should preserve version and approval evidence. This reduces the chance that a development model bypasses validation. Access controls, immutable model identifiers, signing or integrity mechanisms, and deployment gates can strengthen the process further. Merely storing models centrally provides limited governance if lifecycle status and promotion rights are not controlled.<\/span><\/p>\n<p><b>Q328. A model is evaluated successfully using current data, but management expects a major change in customer behavior after a new product launch. What is the BEST lifecycle action?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Assume current validation remains sufficient indefinitely<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Define enhanced post-launch monitoring and reassessment triggers for the expected data shift<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Stop monitoring because the change is expected<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Automatically accept any future performance degradation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Define enhanced post-launch monitoring and reassessment triggers for the expected data shift<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Known changes in the operating environment should influence monitoring and validation plans. A new product may alter input distributions, user populations, transaction patterns, or decision consequences. Even if the model is suitable today, its assumptions may become less valid after launch. The organization should therefore define relevant monitoring indicators and thresholds that trigger review, recalibration, retraining, restriction, or rollback. Anticipating environmental change is stronger risk management than waiting for a major performance failure to reveal that current validation evidence is no longer representative.<\/span><\/p>\n<p><b>Q329. An AI risk scenario could cause harm that is difficult or impossible to reverse once a decision is executed. Which risk characteristic should management consider?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Irreversibility of impact<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Number of model parameters<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Vendor office location<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Length of the model documentation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Irreversibility of impact<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Some AI harms can be corrected relatively easily, while others may be difficult to reverse. For example, an incorrect recommendation shown internally may be recoverable, whereas a harmful decision affecting safety, legal rights, or public reputation may have lasting consequences. Irreversibility can therefore influence risk prioritization, autonomy limits, approval requirements, preventive control strength, and monitoring. It complements likelihood and impact by helping management understand whether remediation after an event is realistic. High-impact irreversible actions often justify stronger preventive and human-oversight controls.<\/span><\/p>\n<p><b>Q330. A risk analyst is comparing two AI risk treatments. One reduces risk substantially but costs more than the expected loss reduction. What should management consider?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Select the control regardless of cost because all risk must be minimized<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Evaluate cost-effectiveness together with risk appetite, nonfinancial impacts, and regulatory requirements<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Reject every control whose cost exceeds expected financial loss<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Remove the risk from the assessment<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Evaluate cost-effectiveness together with risk appetite, nonfinancial impacts, and regulatory requirements<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Risk treatment should consider economic efficiency but should not rely solely on expected financial loss. Some controls may be legally mandatory, protect safety or rights, or address reputational harm that is difficult to quantify. Management should compare implementation and operating costs with expected risk reduction while also considering regulatory requirements, stakeholder impacts, business objectives, and risk appetite. Conversely, implementing extremely expensive controls for negligible risk reduction may be inefficient. Treatment decisions should be proportionate and supported by transparent assumptions rather than driven by cost alone.<\/span><\/p>\n<p><b>Q331. An AI risk treatment introduces a new dependency on a third-party monitoring provider. What should happen to the risk assessment?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Update the assessment to include risks introduced by the treatment itself<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Assume treatments cannot create new risks<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Remove the original risk immediately<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Ignore third-party dependencies because the control is beneficial<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Update the assessment to include risks introduced by the treatment itself<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Controls and treatments can create secondary risks. Adding a monitoring provider may reduce detection risk while introducing third-party, privacy, availability, concentration, or supply-chain exposure. Management should assess these tradeoffs and determine the net effect on residual risk. This does not mean the treatment is inappropriate; it means risk reduction should be evaluated holistically. Treating controls as risk-free can result in unexpected dependencies or exposures that become significant later. Risk assessment should therefore consider both benefits and new risks created by proposed treatments.<\/span><\/p>\n<p><b>Q332. A detective AI control produces excellent alerts but there is no process for investigating or responding to them. What is the PRIMARY weakness?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The detection algorithm should be made less accurate<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> The control lacks an effective response process, reducing its practical risk mitigation value<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Every detective control should automatically block activity<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Alerts eliminate the need for incident response<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. The control lacks an effective response process, reducing its practical risk mitigation value<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Detection alone may not materially reduce risk if no one is accountable for reviewing alerts and taking appropriate action. A complete control design should define alert ownership, prioritization, investigation procedures, escalation thresholds, and remediation or containment actions. Automated blocking may be appropriate in some use cases but can also create operational risk when false positives occur. Control effectiveness should therefore be evaluated end to end\u2014from detection through response\u2014not simply by measuring the quality of alert generation.<\/span><\/p>\n<p><b>Q333. An AI control was effective when implemented two years ago but the underlying model architecture has since changed substantially. What should occur?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Assume the control remains effective because it previously passed testing<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Stop control testing to avoid inconsistent results<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Revalidate the control against the changed AI architecture and current risk scenario<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Lower the risk score automatically<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Revalidate the control against the changed AI architecture and current risk scenario<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Control effectiveness can degrade when the system it protects changes. New architectures, model types, APIs, tool permissions, or data flows may alter the relevant threats and bypass assumptions built into older controls. Material AI changes should therefore trigger control-impact analysis and, when appropriate, renewed validation. Historical effectiveness provides useful evidence but does not guarantee continued protection. Change management and control management should be integrated so system modifications cannot silently invalidate important safeguards.<\/span><\/p>\n<p><b>Q334. An organization uses an AI risk metric that varies significantly depending on which analyst calculates it. What is MOST likely needed?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A clear metric definition, data source, calculation method, and ownership<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> More analysts calculating the same metric independently<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Removal of all metric documentation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> A larger AI model<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. A clear metric definition, data source, calculation method, and ownership<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Risk metrics need consistent definitions to be comparable over time and across teams. Documentation should specify what the metric measures, which systems provide source data, how the value is calculated, how exceptions are handled, reporting frequency, thresholds, and who owns the metric. Without this information, analysts can make reasonable but inconsistent choices and produce conflicting results. Data quality and lineage should also be addressed. Standardization improves management confidence and ensures changes in the metric reflect changes in risk rather than differences in calculation methods.<\/span><\/p>\n<p><b>Q335. A board asks whether the organization&#8217;s AI risk exposure is increasing faster than its control capability. Which reporting information is MOST useful?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only the number of AI applications<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Comparative trends in AI exposure, control maturity, incidents, and treatment progress<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Only the number of completed policies<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Total model parameter counts<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Comparative trends in AI exposure, control maturity, incidents, and treatment progress<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Management needs both sides of the risk equation: how quickly exposure is expanding and whether governance and controls are keeping pace. Trends in use-case criticality, autonomy, sensitive-data processing, incidents, control deficiencies, maturity, and remediation progress can reveal whether risk is growing faster than organizational capability. Counting systems alone can be misleading because ten low-impact tools may create less exposure than one highly autonomous critical system. Board reporting should therefore connect AI adoption and business value with corresponding risk-management capacity.<\/span><\/p>\n<p><b>Q336. A critical AI provider wants to change the country where customer data is processed. What should the customer do FIRST?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Automatically reject every geographic change<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Ignore the change because the provider remains the same<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Assess privacy, residency, legal, contractual, security, and operational implications before accepting the change<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Remove location requirements from the contract<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Assess privacy, residency, legal, contractual, security, and operational implications before accepting the change<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Data-processing location can affect privacy law, cross-border transfer requirements, contractual obligations, government-access concerns, latency, resilience, and customer commitments. A material location change should therefore trigger impact assessment before implementation. The organization may determine that the new location is acceptable, requires additional safeguards, or cannot be used for certain datasets. Supplier agreements should provide appropriate notification of such changes. Automatically rejecting all changes can be unnecessarily restrictive, while ignoring them can create significant compliance and third-party risk.<\/span><\/p>\n<p><b>Q337. An AI vendor relies on a proprietary component that may become unavailable if the vendor fails financially. Which contractual mechanism could MOST improve continuity?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Appropriate escrow or access arrangements for critical artifacts where practical<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Removing all exit provisions<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Increasing marketing commitments<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Allowing the vendor to retain all customer data indefinitely<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Appropriate escrow or access arrangements for critical artifacts where practical<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> For some critical proprietary technologies, escrow or equivalent arrangements can provide customers access to source code, models, documentation, or other essential artifacts if specific triggering events occur, such as provider failure. Such arrangements are not suitable for every AI service, particularly highly complex cloud platforms, but they can strengthen continuity for certain critical dependencies. The organization should assess practicality, legal rights, licensing, operational usability, and whether the escrowed material would actually enable continued service. Escrow complements rather than replaces vendor monitoring and exit planning.<\/span><\/p>\n<p><b>Q338. An AI incident involves unauthorized changes to model behavior, but investigators cannot determine whether the change resulted from malicious activity or an approved deployment. What control would have MOST improved the investigation?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Strong configuration and change logs tied to approved model versions and identities<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> More user-interface documentation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> A larger production model<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Fewer deployment records<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Strong configuration and change logs tied to approved model versions and identities<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Investigation requires evidence linking production changes to specific model versions, deployment events, identities, approvals, and timestamps. Strong configuration and change-management records help distinguish authorized lifecycle activity from malicious or accidental modification. Integrity protection for these logs further strengthens assurance. Without traceability, responders may know that behavior changed but remain unable to determine who or what caused it. Good change evidence therefore supports routine governance as well as security incident response and forensic analysis.<\/span><\/p>\n<p><b>Q339. A business impact analysis determines that an AI-supported process becomes unacceptable after 12 hours of disruption. What does this information MOST directly define?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The model&#8217;s minimum accuracy<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Maximum tolerable period of disruption for the business process<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> The system&#8217;s RPO automatically<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> The vendor&#8217;s incident-notification deadline<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Maximum tolerable period of disruption for the business process<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> The maximum tolerable period of disruption represents how long a business activity can remain disrupted before consequences become unacceptable. This information can guide recovery strategy and help establish more specific recovery objectives. The RTO would normally be set within the maximum tolerable period to provide sufficient time for recovery before unacceptable impact occurs. RPO concerns tolerable data loss rather than service downtime. Understanding these distinctions helps organizations design continuity and disaster recovery capabilities that reflect actual business impact rather than arbitrary technical targets.<\/span><\/p>\n<p><b>Q340. An organization uses AI to analyze risk-register history and recommend which risks may be duplicates. What should happen before records are merged?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Merge every pair identified by the AI automatically<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Delete both records and create a new one<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Let the AI change risk ownership automatically<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Have a qualified risk professional verify that the scenarios, causes, impacts, and ownership are genuinely duplicative**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Have a qualified risk professional verify that the scenarios, causes, impacts, and ownership are genuinely duplicative<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> AI can identify similarities across large risk registers, but textual similarity does not prove that two risks are truly the same. Risks may use similar language while differing in cause, affected asset, impact, jurisdiction, owner, or treatment. A qualified professional should review the evidence before consolidation. Incorrect merging can obscure distinct exposures and weaken accountability. AI should therefore be used to improve the efficiency of risk analysis and data quality while authorized humans retain responsibility for material changes to official enterprise risk records.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Isaca AAIR Exam Dumps and Practice Test Dumps. Q321. An organization allows business units to propose AI projects, but many proposals contain no defined business problem or expected benefit. What should the AI risk function recommend FIRST? Require each proposed use case to define business objectives, expected value, and relevant risk assumptions 2. [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18357"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=18357"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18357\/revisions"}],"predecessor-version":[{"id":18358,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18357\/revisions\/18358"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=18357"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=18357"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=18357"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}