{"id":18359,"date":"2026-09-22T06:53:45","date_gmt":"2026-09-22T06:53:45","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=18359"},"modified":"2026-09-22T06:53:45","modified_gmt":"2026-09-22T06:53:45","slug":"isaca-aair-practice-test-questions-and-exam-dumps-part18-q341-360","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/isaca-aair-practice-test-questions-and-exam-dumps-part18-q341-360\/","title":{"rendered":"Isaca AAIR Practice Test Questions and Exam Dumps Part18 Q341-360"},"content":{"rendered":"<p><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/aair-exam-dumps\"><b>Isaca AAIR Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/p>\n<p><b><br \/>\n<\/b><b>Q341. An AI governance committee includes strong technical experts but lacks legal, privacy, business, and risk representation. What is the BEST improvement?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Give technical members authority over all nontechnical issues<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Add cross-functional members with expertise relevant to material AI risks<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Remove technical experts from the committee<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Ask the AI vendor to make governance decisions<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Add cross-functional members with expertise relevant to material AI risks<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> AI risk crosses traditional organizational boundaries. Technical experts can evaluate model and system behavior, but legal, privacy, compliance, business, security, risk, and other stakeholders may be needed to evaluate regulatory obligations, affected individuals, strategic alignment, contractual exposure, and ethical concerns. The exact committee composition should reflect the organization&#8217;s AI use cases and risk profile. Cross-functional participation also improves challenge and reduces the likelihood that one discipline overlooks important consequences. Vendors can provide information, but accountability for enterprise AI governance should remain with the organization.<\/span><\/p>\n<p><b>Q342. An organization uses several AI governance standards with overlapping requirements. What is the BEST way to reduce inconsistent implementation?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Apply only whichever standard has the fewest controls<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Let each business unit choose its preferred standard<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Remove all common requirements<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Create a crosswalk mapping overlapping requirements to a harmonized control framework**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Create a crosswalk mapping overlapping requirements to a harmonized control framework<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> A standards crosswalk helps identify where different frameworks, regulations, and internal policies address the same underlying governance objective. The organization can then design common controls and evidence that satisfy several requirements where appropriate, while separately addressing unique obligations. This reduces duplicated work and inconsistent terminology without ignoring differences among standards. A harmonized control framework also improves testing and reporting because teams understand which enterprise controls support which external requirements. Choosing only the easiest standard can create compliance gaps when multiple frameworks genuinely apply.<\/span><\/p>\n<p><b>Q343. Two organizational AI principles conflict in a specific use case: maximum personalization would increase business value but require substantially more personal data. What should management do?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Evaluate the tradeoff using business objectives, privacy principles, stakeholder impact, and risk appetite<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Always maximize personalization<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Ignore privacy because business value is measurable<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Stop using AI in every personalized service<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Evaluate the tradeoff using business objectives, privacy principles, stakeholder impact, and risk appetite<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Responsible AI governance often requires balancing legitimate but competing objectives. Greater personalization may improve customer experience while increasing privacy, consent, retention, and data-security exposure. Management should identify the minimum information needed, consider alternative designs, evaluate affected stakeholders, and determine whether residual risk remains within approved appetite. Organizational principles should guide decision-making rather than being treated as slogans that always produce one automatic answer. Documenting the rationale also supports consistency and later review when technology, expectations, or regulations change.<\/span><\/p>\n<p><b>Q344. An enterprise operates AI services in multiple countries and notices employees interpret the AI policy differently because of language and cultural differences. What is the BEST response?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Require every employee to interpret the original policy independently<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Create entirely different governance principles for every office<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Provide localized, role-appropriate guidance while preserving consistent enterprise requirements<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Remove employee training requirements<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Provide localized, role-appropriate guidance while preserving consistent enterprise requirements<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Enterprise AI governance should remain consistent while being communicated in a way employees can understand and apply. Localization can include translated policies, region-specific regulatory context, practical examples, and role-based training without weakening core requirements. Different business units may also need guidance tailored to their activities. Simply publishing one global document may not create effective awareness, especially when terminology or local law differs. Training effectiveness should be assessed through understanding and behavior rather than assuming policy distribution alone creates compliance.<\/span><\/p>\n<p><b>Q345. A company uses a vector database containing embeddings created from sensitive internal documents. What should the risk team recognize?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Embeddings and derived indexes may still require protection as sensitive AI data assets<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Embeddings can never reveal meaningful information<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Vector databases are outside AI asset governance<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Access controls are unnecessary because embeddings are numerical<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Embeddings and derived indexes may still require protection as sensitive AI data assets<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Embeddings are numerical representations, but they are derived from underlying information and may still create confidentiality, privacy, or inference risk. Organizations should classify and protect vector stores based on the sensitivity of their source material and possible exposure pathways. Appropriate measures can include access control, encryption, tenant isolation, retention, deletion, and monitoring. Governance should also address whether removing a source document requires removal of associated derived artifacts. Treating embeddings as automatically anonymous can create a blind spot in retrieval-augmented AI architectures.<\/span><\/p>\n<p><b>Q346. A customer requests deletion of information that was indexed into both a retrieval database and backup systems. What is the MOST appropriate response?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Delete only the visible source document<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Ignore derived or backup copies<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Retrain every enterprise AI model immediately<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Follow applicable deletion requirements across source, derived, indexed, and retained copies where required**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Follow applicable deletion requirements across source, derived, indexed, and retained copies where required<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> AI data can exist in several forms, including source documents, embeddings, caches, indexes, backups, logs, and potentially model-training datasets. When deletion is legally or contractually required, the organization should use lineage and retention information to determine which copies fall within scope and how they should be removed or restricted. Backup treatment may follow special legal and operational rules, so immediate physical deletion is not always required. A defined process helps ensure deletion obligations are applied consistently across the AI data lifecycle instead of addressing only the most visible copy.<\/span><\/p>\n<p><b>Q347. A model&#8217;s ranking accuracy remains stable, but its predicted probabilities become increasingly unreliable over time. What should monitoring identify?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Vendor concentration<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Calibration drift<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Model extraction<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Business continuity failure<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Calibration drift<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Calibration measures how closely predicted probabilities correspond to observed outcome frequencies. A model can continue ranking cases correctly while its confidence estimates become unreliable. This matters when business decisions use probability thresholds\u2014for example, when cases above a certain confidence level are automatically approved. Monitoring should therefore evaluate calibration where confidence scores influence action. Recalibration, retraining, or threshold adjustment may be needed after investigation. Focusing only on overall accuracy can miss meaningful deterioration in how decision-makers should interpret model confidence.<\/span><\/p>\n<p><b>Q348. Which situation provides the STRONGEST justification for retiring an AI model?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A newer model exists in the market<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> The original developers have moved to another team<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> The model no longer provides sufficient business value or acceptable risk despite feasible remediation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> The model has been in production for one year<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. The model no longer provides sufficient business value or acceptable risk despite feasible remediation<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Retirement decisions should reflect business value, risk, maintainability, regulatory suitability, and operational feasibility rather than model age alone. A model that no longer supports strategic objectives, cannot meet required performance, or retains unacceptable residual risk may warrant decommissioning. Conversely, an older model can remain appropriate when it continues to meet business and governance requirements. Retirement should follow a controlled process addressing dependencies, records, access, archival, data retention, user transition, and replacement processes so removing the system does not create new operational risks.<\/span><\/p>\n<p><b>Q349. An AI agent has access to email, payment, and customer-record tools. Which activity is MOST important when assessing its threat exposure?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Count the number of tools only<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Review only the underlying language model<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Assume tool authorization eliminates all risk<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Threat-model how prompts, identities, tool permissions, and external inputs could combine to cause unauthorized actions**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Threat-model how prompts, identities, tool permissions, and external inputs could combine to cause unauthorized actions<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Agentic AI risk depends heavily on system interactions. The language model may interpret untrusted prompts, retrieve external content, and invoke tools with real business consequences. Threat modeling should therefore examine identity, authorization, prompt injection, excessive agency, data leakage, tool chaining, transaction limits, and approval mechanisms. Looking only at the model misses risks created by the surrounding architecture. Least privilege and deterministic tool controls can significantly reduce impact when model reasoning is incorrect or manipulated.<\/span><\/p>\n<p><b>Q350. A risk team wants to understand the different ways attackers could cause an autonomous AI system to execute an unauthorized payment. Which method is MOST useful?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Attack-tree analysis<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Model accuracy benchmarking only<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Employee satisfaction surveys<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Data-retention schedules<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Attack-tree analysis<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Attack trees break an undesirable outcome into possible attack paths and prerequisite conditions. For unauthorized AI-driven payments, branches might include credential compromise, prompt injection, tool-permission abuse, malicious retrieved content, or control bypass. This structure helps teams identify multiple pathways to the same consequence and determine whether preventive and detective controls cover them adequately. Attack trees can complement broader risk scenarios and threat modeling. They are especially useful for complex AI architectures where attackers may combine weaknesses across models, identities, APIs, and business processes.<\/span><\/p>\n<p><b>Q351. Management accepts an AI risk only while a specific monitoring control remains effective. What type of acceptance is this?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Unconditional permanent acceptance<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Risk avoidance<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Conditional risk acceptance<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Full risk transfer<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Conditional risk acceptance<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Conditional acceptance means management is willing to retain risk only while specified conditions remain true. Conditions may include monitoring, transaction limits, enhanced oversight, compensating controls, or a time-bound review. If the condition fails, the acceptance should be reconsidered and escalation or further treatment may be required. Documenting conditions makes the decision more precise than a simple \u201caccept\u201d status. This is particularly useful for changing AI environments where risk may remain acceptable only while performance, controls, or business circumstances stay within defined boundaries.<\/span><\/p>\n<p><b>Q352. An AI model&#8217;s production monitoring alert is consistently acknowledged but never investigated. What is the PRIMARY control weakness?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The alert threshold is necessarily too low<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> The monitoring process lacks effective investigation and follow-through<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Monitoring should be eliminated<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> The model must automatically be retrained<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. The monitoring process lacks effective investigation and follow-through<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> A monitoring control is only useful when meaningful alerts lead to appropriate investigation and response. Acknowledging an alert without determining its cause, impact, or required action creates the appearance of control without effective risk reduction. Procedures should identify alert ownership, response time, investigation steps, escalation, and closure evidence. Management should also monitor unresolved or repeatedly acknowledged alerts. The weakness may be procedural rather than technical, demonstrating why operating effectiveness must consider the complete control process rather than merely whether an alerting system generates notifications.<\/span><\/p>\n<p><b>Q353. Two business units report AI incident rates as \u201cincidents per month,\u201d but one unit has 100 AI systems and the other has 5. What reporting improvement BEST supports comparison?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Use only raw incident counts<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Stop comparing business units<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Report only the larger business unit<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Normalize the metric using an appropriate denominator such as systems, transactions, or exposure**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Normalize the metric using an appropriate denominator such as systems, transactions, or exposure<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Raw incident counts can be misleading when business units differ greatly in scale. Normalization provides context by relating incidents to a meaningful exposure measure, such as number of systems, decisions, users, or transactions. The correct denominator depends on the risk and business process. A smaller unit with fewer incidents may actually have a higher incident rate once exposure is considered. Risk reporting should define calculations consistently so management compares like with like rather than drawing conclusions from unadjusted totals.<\/span><\/p>\n<p><b>Q354. Which metric is MOST likely to function as a leading AI risk indicator rather than a lagging indicator?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Increasing percentage of overdue high-risk model reviews<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Financial loss already incurred from AI incidents<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Number of completed historical incident reports<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Total compensation already paid to affected customers<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Increasing percentage of overdue high-risk model reviews<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Leading indicators provide warning that risk exposure may be increasing before losses materialize. A growing backlog of overdue reviews suggests that important systems may be operating with outdated assumptions or unaddressed changes. Financial loss and customer compensation are lagging indicators because they measure consequences that have already occurred. Both types are useful, but leading indicators can support proactive intervention. The organization should select KRIs with clear relationships to risk scenarios and define thresholds and escalation procedures before indicators breach acceptable levels.<\/span><\/p>\n<p><b>Q355. A critical AI vendor claims customer data can be exported easily if the contract ends. What provides the BEST assurance of data portability?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The sales representative&#8217;s statement<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> The existence of an export button<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> A tested export and migration exercise using required data and formats<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> A long-term contract extension<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. A tested export and migration exercise using required data and formats<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Portability should be demonstrated through testing. An export function may omit metadata, model settings, prompts, logs, or other information required to recreate the service elsewhere. A practical migration exercise can reveal incompatible formats, large transfer times, missing dependencies, licensing issues, or transformation requirements. Critical AI services may not require full migration testing frequently, but important assumptions should be verified. Tested portability strengthens exit readiness and reduces vendor lock-in when providers become unavailable or no longer meet organizational needs.<\/span><\/p>\n<p><b>Q356. An AI supplier becomes subject to new international sanctions that may affect service delivery. What should the customer do?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Ignore the issue until the service stops<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Assess legal applicability, operational dependency, alternatives, and continuity or exit actions<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Automatically violate sanctions to preserve continuity<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Remove the supplier from the vendor inventory<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Assess legal applicability, operational dependency, alternatives, and continuity or exit actions<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Geopolitical and sanctions developments can create legal and operational risks quickly. The organization should engage legal and compliance stakeholders to determine applicability, assess affected contracts and data flows, and evaluate whether continuity or exit plans must be activated. Alternative providers, migration timelines, and customer impacts may need urgent review. Automatically continuing prohibited activity is unacceptable, while waiting for an actual outage may leave too little time for orderly transition. Supply-chain monitoring should therefore include external events capable of changing vendor viability or legality.<\/span><\/p>\n<p><b>Q357. An AI incident affects a small number of individuals but potentially violates important legal rights. How should severity be determined?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Classify it as low because few people are affected<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Consider the nature and seriousness of the rights impact, not only the number of affected individuals<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Use only financial-loss estimates<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Ignore legal consequences until litigation begins<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Consider the nature and seriousness of the rights impact, not only the number of affected individuals<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Incident severity should reflect the full consequence of the event. A small number of cases can still be highly material when safety, discrimination, legal rights, or sensitive personal information are involved. Severity criteria should therefore consider qualitative harm as well as scope, financial loss, regulatory obligations, and service impact. Overreliance on affected-user counts can systematically underrate serious but narrowly distributed incidents. AI incident frameworks should recognize stakeholder harm and legal implications when determining escalation and response requirements.<\/span><\/p>\n<p><b>Q358. A manual continuity workaround exists for an AI-supported business process, but only one employee still knows how to perform it. What is the PRIMARY concern?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The model may become more accurate<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> The workaround has a key-person dependency that threatens continuity<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> The AI vendor needs more training data<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Manual processes never require testing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. The workaround has a key-person dependency that threatens continuity<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> A fallback procedure is vulnerable when only one individual knows how to execute it. Absence, turnover, or unavailability of that person during an outage could make the continuity plan ineffective. The organization should document the process, train sufficient backup personnel, and test execution under realistic conditions. Skills can also decay when manual procedures are rarely used. Business continuity planning must therefore consider people, knowledge, technology, data, facilities, and suppliers rather than assuming that a written statement saying \u201cmanual fallback\u201d creates practical resilience.<\/span><\/p>\n<p><b>Q359. A disaster recovery test restores an AI model from backup. What validation should occur BEFORE the recovered model is returned to service?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Confirm only that the model file exists<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Trust the backup because it was previously approved<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Skip validation to meet the RTO<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Verify artifact integrity, version, required dependencies, and expected functional behavior**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Verify artifact integrity, version, required dependencies, and expected functional behavior<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Successful file restoration does not automatically mean the recovered AI service is trustworthy. The organization should confirm that the intended model version was restored, that integrity has not been compromised, and that necessary dependencies, data, configuration, and interfaces are compatible. Appropriate functional or smoke testing can verify that the recovered model behaves as expected before normal processing resumes. Recovery procedures should be designed to meet RTO requirements while still preserving essential validation. Returning an incorrect or corrupted model to service can turn a continuity event into a new AI risk incident.<\/span><\/p>\n<p><b>Q360. An AI tool proposes new enterprise risk scenarios and cites sources that do not exist. What should the risk team do?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Add all proposed scenarios immediately because AI identified them<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Ignore every AI-generated scenario permanently<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Validate the scenarios and supporting evidence independently before using them in formal risk analysis<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Allow the AI to create supporting sources automatically<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Validate the scenarios and supporting evidence independently before using them in formal risk analysis<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Generative AI can assist risk identification but may hallucinate facts, citations, or external evidence. Risk professionals should independently verify proposed scenarios and supporting information before incorporating them into official risk records. A scenario may still be useful even if an AI-generated citation is wrong, but it must be supported by credible evidence, organizational context, and professional assessment. AI can improve coverage and brainstorming efficiency while humans retain responsibility for validating evidence, assessing materiality, assigning ownership, and making formal enterprise risk decisions.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Isaca AAIR Exam Dumps and Practice Test Dumps. Q341. An AI governance committee includes strong technical experts but lacks legal, privacy, business, and risk representation. What is the BEST improvement? Give technical members authority over all nontechnical issues 2. Add cross-functional members with expertise relevant to material AI risks 3. Remove technical experts [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18359"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=18359"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18359\/revisions"}],"predecessor-version":[{"id":18360,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18359\/revisions\/18360"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=18359"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=18359"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=18359"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}