{"id":18361,"date":"2026-09-22T06:54:03","date_gmt":"2026-09-22T06:54:03","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=18361"},"modified":"2026-09-22T06:54:03","modified_gmt":"2026-09-22T06:54:03","slug":"isaca-aair-practice-test-questions-and-exam-dumps-part19-q361-380","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/isaca-aair-practice-test-questions-and-exam-dumps-part19-q361-380\/","title":{"rendered":"Isaca AAIR Practice Test Questions and Exam Dumps Part19 Q361-380"},"content":{"rendered":"<p><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/aair-exam-dumps\"><b>Isaca AAIR Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/p>\n<p><b><br \/>\n<\/b><b>Q361. Two companies form a joint venture that will operate a shared high-risk AI platform. What is MOST important before the platform goes live?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Allow each company to assume the other will manage AI risk<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Let the technology vendor accept all business risk<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Define shared and individual responsibilities for AI governance, controls, risk ownership, and incident response<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Use whichever company&#8217;s policy contains fewer requirements<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Define shared and individual responsibilities for AI governance, controls, risk ownership, and incident response<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Joint ventures can create accountability gaps when several organizations participate in operating one AI system. Before deployment, responsibilities should be documented for model ownership, data governance, control operation, residual-risk acceptance, regulatory compliance, monitoring, vendor oversight, incident response, and change approval. Shared responsibility does not mean unclear responsibility. Each party should understand which obligations it owns and which activities require joint decisions. This structure also helps prevent critical tasks from being assumed by both parties but performed by neither. Clear accountability is a foundational element of effective AI governance.<\/span><\/p>\n<p><b>Q362. An organization wants external stakeholders represented in discussions about a controversial public-facing AI service. What is the PRIMARY benefit?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Broader stakeholder perspectives can reveal harms and concerns internal teams may overlook<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> External participation guarantees regulatory approval<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Stakeholders can replace formal risk owners<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Technical validation becomes unnecessary<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Broader stakeholder perspectives can reveal harms and concerns internal teams may overlook<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> AI systems can affect customers, communities, employees, and other stakeholders in ways that internal project teams may not fully anticipate. Appropriate engagement can identify concerns involving fairness, accessibility, privacy, transparency, trust, cultural context, and societal impact. Stakeholder input does not replace governance, validation, legal review, or accountable decision-making. Instead, it provides additional evidence that can improve design and risk assessment. The extent of engagement should be proportionate to the use case and affected population, especially where the AI system has significant public or individual consequences.<\/span><\/p>\n<p><b>Q363. An organization must retain evidence demonstrating how a regulated AI system was governed for several years. Which approach is BEST?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Keep only the latest model file<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Allow project teams to delete evidence whenever storage becomes expensive<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Retain only emails from the model owner<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Establish a records-retention schedule covering required governance, model, decision, testing, and approval evidence**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Establish a records-retention schedule covering required governance, model, decision, testing, and approval evidence<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Regulated AI systems can require long-term evidence of how models were designed, approved, monitored, changed, and used. A defined records-retention schedule should identify which artifacts must be preserved, for how long, who owns them, and how they will be protected and eventually disposed of. Relevant evidence may include model versions, test results, approvals, risk assessments, change records, decision logs, and user notices. Keeping only the current model does not provide sufficient historical traceability. Retention requirements should align with legal, regulatory, contractual, audit, and business needs.<\/span><\/p>\n<p><b>Q364. Employees are permitted to use approved external AI assistants, but organizational policy prohibits giving those assistants authority to execute transactions. What control BEST enforces this requirement?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Ask employees to remember the restriction<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Prevent transaction-capable tool permissions from being granted to the approved assistants<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Increase the model&#8217;s system prompt length<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Allow transaction access but review activity quarterly<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Prevent transaction-capable tool permissions from being granted to the approved assistants<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Governance requirements are strongest when enforced through technical controls rather than relying solely on user awareness or prompt wording. If approved assistants are intended only for informational purposes, they should not receive credentials or tool permissions that allow them to perform transactions. Least privilege limits the consequences of hallucination, prompt injection, or human misuse. Training and monitoring remain useful, but they are weaker than preventing the capability altogether. This aligns autonomy with approved use and ensures that the system&#8217;s technical permissions reflect governance decisions.<\/span><\/p>\n<p><b>Q365. A smaller \u201cstudent\u201d model is trained to reproduce the behavior of a larger \u201cteacher\u201d model through knowledge distillation. What risk should be considered?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The student may inherit undesirable biases or weaknesses from the teacher model<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Distillation guarantees all teacher-model weaknesses are removed<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> The student no longer requires validation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Distilled models cannot create intellectual-property risk<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. The student may inherit undesirable biases or weaknesses from the teacher model<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Knowledge distillation transfers behavior from one model to another and can improve efficiency, but it can also propagate weaknesses. If the teacher produces biased, unsafe, or inaccurate outputs under certain conditions, the student may learn similar patterns. Distillation can also introduce new differences, so the student model should be independently validated for its intended use rather than assumed to inherit only desirable characteristics. Organizations should document model provenance, training methods, licensing rights, and evaluation results. A smaller model may reduce operational cost without reducing governance obligations.<\/span><\/p>\n<p><b>Q366. A model-development team selects hyperparameters repeatedly based on performance on the same validation dataset. What is the PRIMARY concern?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The model will automatically become easier to explain<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Validation costs will always decrease<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> The model may overfit the validation set, making reported performance overly optimistic<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> The training data will necessarily become corrupted<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. The model may overfit the validation set, making reported performance overly optimistic<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Repeatedly tuning decisions against the same validation dataset can cause development choices to become specialized to that dataset. Although the records are not used directly for ordinary training, the validation set effectively influences model development and may no longer provide an unbiased estimate of generalization. A separate final test set or independent evaluation can provide stronger evidence. Good model governance distinguishes training, tuning, and final evaluation activities and protects the integrity of evidence used to justify deployment decisions.<\/span><\/p>\n<p><b>Q367. A production model is quantized to reduce memory consumption and inference cost. What should happen before the quantized version replaces the approved model?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Deploy immediately because quantization affects only infrastructure<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Remove prior validation results<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Assume smaller numerical precision cannot affect outcomes<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Validate whether quantization materially changes accuracy, fairness, robustness, or other approved behavior**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Validate whether quantization materially changes accuracy, fairness, robustness, or other approved behavior<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Quantization changes how model parameters are represented and can affect outputs, especially when precision is reduced significantly. The impact may be negligible for some models but meaningful for others. Therefore, the quantized artifact should be treated as a model change and evaluated according to its risk and intended use. Validation should compare relevant performance, fairness, robustness, latency, and other requirements against the approved version. Operational efficiency gains do not justify assuming that model behavior is unchanged without evidence.<\/span><\/p>\n<p><b>Q368. A safety guardrail service used by a generative AI application becomes unavailable. What design decision should be made in advance?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Always allow AI output through when guardrails fail<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Define whether the application fails closed, degrades safely, or invokes another approved fallback based on risk<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Let users decide individually during the outage<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable monitoring whenever guardrails fail<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Define whether the application fails closed, degrades safely, or invokes another approved fallback based on risk<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Guardrails can become critical dependencies. If they fail, the application needs predefined behavior appropriate to the consequence of unfiltered output. A high-risk system may need to fail closed or switch to a safer fallback, while a low-risk use case may permit limited degraded operation. The decision should reflect business criticality, availability needs, and potential harm. Defining behavior during design is preferable to improvising during an outage. Monitoring should also identify guardrail failures so operators can respond and reassess service availability.<\/span><\/p>\n<p><b>Q369. A risk team discovers that three different AI risk scenarios can trigger one another, creating a cascading failure. Which analysis is MOST useful?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Review each risk independently and ignore relationships<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Count the number of controls assigned to each risk<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Map risk interdependencies and potential cascading pathways<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Select only the highest initial risk for further analysis<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Map risk interdependencies and potential cascading pathways<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> AI risks can interact. For example, a data-quality problem can cause model errors, which can trigger inappropriate automated actions and then create regulatory or reputational consequences. Assessing each scenario separately may underestimate aggregate exposure. Interdependency mapping helps the organization understand triggers, common causes, feedback loops, and cascading effects. This information can influence prioritization, control placement, incident response, and business continuity planning. Enterprise risk management should therefore consider relationships among material risks rather than assuming every risk scenario behaves independently.<\/span><\/p>\n<p><b>Q370. Management must choose between two AI risk treatments. One is less expensive, but a regulation explicitly requires the control provided by the more expensive option. What is the BEST decision basis?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Regulatory requirements must be satisfied even if the alternative appears cheaper<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Always choose the least expensive option<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Ignore regulatory requirements if expected loss is low<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Remove the risk from the register<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Regulatory requirements must be satisfied even if the alternative appears cheaper<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Cost-benefit analysis is useful when management has discretion among treatment alternatives, but mandatory legal or regulatory controls cannot generally be rejected solely because a cheaper alternative appears economically attractive. The organization should determine the exact obligation and whether another control can satisfy it equivalently. Where no compliant alternative exists, the required control should be implemented or the underlying activity may need to be changed or avoided. Risk management operates within legal constraints rather than treating every requirement as an optional economic tradeoff.<\/span><\/p>\n<p><b>Q371. An automated AI control depends on a configuration rule that has not been reviewed for two years despite significant system changes. What is the MOST important concern?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The control is automatically effective because it is automated<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> The control logic may have drifted away from the current risk and system environment<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Automated controls never require ownership<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Control documentation should be deleted after implementation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. The control logic may have drifted away from the current risk and system environment<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Automation can improve consistency but does not guarantee continued relevance. If the protected system, model, data, or threats change, an automated control may continue running exactly as coded while no longer addressing the important risk. Control owners should periodically review logic, assumptions, thresholds, dependencies, and exceptions and reassess them after material system changes. Continuous operation is not the same as continuous effectiveness. Automated safeguards require lifecycle governance just as the AI systems they protect do.<\/span><\/p>\n<p><b>Q372. A critical AI control can be operated only by one highly specialized employee. What risk should management address?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Model explainability risk<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Data minimization risk<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Key-person dependency in control operation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Algorithmic bias automatically<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Key-person dependency in control operation<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> A control is less resilient when its operation depends entirely on one person. Absence, departure, or unavailability of that employee can leave the organization unable to perform the control. Management should document procedures, cross-train additional staff, automate suitable portions, and establish backup responsibilities. The severity of the issue depends on the control&#8217;s criticality and how quickly it must operate. Key-person risk can affect both control effectiveness and business continuity even when the underlying AI system itself is technically resilient.<\/span><\/p>\n<p><b>Q373. An AI KRI suddenly doubles after the organization changes the denominator used in its calculation. What should happen BEFORE management concludes that risk has increased?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Validate whether the apparent trend results from the methodology change rather than actual exposure<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Automatically escalate the risk to critical<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Remove all historical values<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Keep the calculation change undocumented<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Validate whether the apparent trend results from the methodology change rather than actual exposure<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Metric changes can create artificial trends. If the denominator, data source, definition, or calculation method changes, values before and after the change may not be directly comparable. The risk team should document the methodology change, recalculate historical values where practical, and explain any discontinuity to report users. Otherwise, management may respond to a measurement artifact rather than a real change in exposure. Good risk reporting requires consistent definitions, data lineage, change control, and transparent interpretation of metrics.<\/span><\/p>\n<p><b>Q374. An AI risk report contains estimates with widely varying levels of evidence quality. What would BEST improve decision usefulness?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Hide uncertainty so the report appears more decisive<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Include confidence, assumptions, or evidence-quality information for material estimates<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Convert every estimate to the same exact number<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Remove all qualitative analysis<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Include confidence, assumptions, or evidence-quality information for material estimates<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Risk information varies in certainty. Some estimates may be based on robust operational data, while emerging risks may depend heavily on expert judgment. Reporting confidence levels, assumptions, and evidence quality helps decision-makers distinguish strong findings from preliminary estimates and determine where additional analysis is warranted. Concealing uncertainty creates false precision. Transparent reporting is especially important in AI risk because technologies, regulations, and threats evolve rapidly and historical data may be limited. Decision quality improves when uncertainty is made explicit rather than hidden.<\/span><\/p>\n<p><b>Q375. A critical AI vendor contract does not allow direct audits. Which alternative provides the BEST risk assurance when appropriately scoped?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Accept the vendor&#8217;s marketing claims<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Skip due diligence entirely<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Obtain relevant independent assurance reports and supplemental evidence addressing identified risks<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Assume a large vendor has effective controls<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Obtain relevant independent assurance reports and supplemental evidence addressing identified risks<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Direct audit rights may not always be commercially feasible, particularly with large service providers. Independent assurance reports, certifications, technical evidence, questionnaires, penetration-test summaries, and contractual commitments can provide alternative assurance when evaluated carefully. The organization should review scope, period, exceptions, independence, and whether the evidence addresses its actual use of the service. No single report automatically eliminates third-party risk. Assurance should be proportionate to vendor criticality and supplemented where material gaps remain.<\/span><\/p>\n<p><b>Q376. An AI supplier relies on a data provider located in a region experiencing increasing political instability. What should the organization assess?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only the direct vendor&#8217;s current service uptime<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> The upstream geopolitical and continuity risk that could affect the AI supply chain<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Only the model&#8217;s technical accuracy<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> The number of employees at the direct vendor<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. The upstream geopolitical and continuity risk that could affect the AI supply chain<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Fourth-party and upstream dependencies can introduce geopolitical risks that are not visible when reviewing only the direct supplier. Political instability can affect data availability, legal rights, cross-border transfer, sanctions, connectivity, or provider operations. The organization should assess the materiality of that dependency and consider alternatives, contractual obligations, portability, and continuity measures. Direct vendor uptime may remain strong until the upstream disruption occurs, so supply-chain monitoring should include external developments relevant to critical dependencies.<\/span><\/p>\n<p><b>Q377. During an AI incident, responders need to restore a prior model version quickly but also preserve evidence of the compromised version. What is the BEST approach?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Preserve required forensic evidence before or as part of controlled rollback, without delaying urgent containment unnecessarily<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Delete the compromised model immediately with no evidence capture<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Refuse to restore service until every investigation is complete<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Allow investigators to edit the model files directly<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Preserve required forensic evidence before or as part of controlled rollback, without delaying urgent containment unnecessarily<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Incident response must balance evidence preservation with timely containment and recovery. Relevant model artifacts, hashes, logs, configuration, prompts, and other evidence should be captured or preserved where practical so investigators can determine what happened. At the same time, evidence procedures should not create unreasonable delay when the system is causing ongoing harm. Predefined incident processes can identify what must be collected quickly and how rollback or isolation should proceed. Chain-of-custody and integrity controls improve the usefulness of preserved evidence.<\/span><\/p>\n<p><b>Q378. An AI incident response contact list has not been tested for a year. What is the BEST way to improve confidence that escalation will work?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Assume contact details remain correct<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Periodically test the notification and escalation tree through exercises<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Remove backup contacts<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Use only personal memory during incidents<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Periodically test the notification and escalation tree through exercises<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Incident response depends on reaching the correct people quickly. Staff changes, role changes, phone numbers, vendor contacts, and escalation responsibilities can become outdated. Periodic call-tree or tabletop exercises verify that contacts work and that participants understand their roles. Exercises can also test alternate contacts and after-hours procedures. Maintaining a documented list is necessary, but testing provides stronger evidence of operational readiness. AI incidents can involve technical, legal, business, privacy, communications, and vendor stakeholders, making reliable escalation particularly important.<\/span><\/p>\n<p><b>Q379. A disaster recovery plan identifies all systems needed for an AI service but does not specify the order in which they must be restored. What is the PRIMARY concern?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> All systems can always be restored simultaneously<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Recovery order is irrelevant when backups exist<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Missing recovery sequencing may delay restoration because dependent components must become available in the correct order<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> The organization should remove system dependencies from the BIA<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Missing recovery sequencing may delay restoration because dependent components must become available in the correct order<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> AI services can depend on identity systems, databases, feature pipelines, model registries, APIs, storage, networking, and other services. Restoring components in the wrong order may leave systems unavailable even though individual backups are usable. Disaster recovery procedures should therefore document dependencies and recovery sequencing, especially where RTO requirements are tight. Testing can confirm whether the sequence is realistic. Recovery planning should address the end-to-end business service rather than treating every technical component as independent.<\/span><\/p>\n<p><b>Q380. An AI tool groups similar control deficiencies and recommends which remediation actions could be consolidated. What should the risk team do before combining remediation plans?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Accept all clusters automatically<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Remove control owners from the decision<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Let the AI change risk ratings directly<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Verify that the deficiencies share the same root cause, risk objective, and remediation needs**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Verify that the deficiencies share the same root cause, risk objective, and remediation needs<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> AI can identify textual or statistical similarities among control findings, but similar descriptions do not necessarily mean the deficiencies have the same cause or require the same fix. Qualified professionals should verify affected systems, control objectives, root causes, ownership, severity, and regulatory implications before consolidation. Appropriate grouping can reduce duplicated remediation effort and reveal systemic issues. Incorrect grouping can hide distinct risks and weaken accountability. AI should support analysis of risk and control data while authorized professionals retain responsibility for formal remediation decisions.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Isaca AAIR Exam Dumps and Practice Test Dumps. Q361. Two companies form a joint venture that will operate a shared high-risk AI platform. What is MOST important before the platform goes live? Allow each company to assume the other will manage AI risk 2. Let the technology vendor accept all business risk 3. [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18361"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=18361"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18361\/revisions"}],"predecessor-version":[{"id":18362,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18361\/revisions\/18362"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=18361"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=18361"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=18361"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}