{"id":18363,"date":"2026-09-22T06:54:18","date_gmt":"2026-09-22T06:54:18","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=18363"},"modified":"2026-09-22T06:54:18","modified_gmt":"2026-09-22T06:54:18","slug":"isaca-aair-practice-test-questions-and-exam-dumps-part20-q381-400","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/isaca-aair-practice-test-questions-and-exam-dumps-part20-q381-400\/","title":{"rendered":"Isaca AAIR Practice Test Questions and Exam Dumps Part20 Q381-400"},"content":{"rendered":"<p><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/aair-exam-dumps\"><b>Isaca AAIR Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/p>\n<p><b><br \/>\n<\/b><b>Q381. An organization plans to introduce AI into a process that directly supports a strategic corporate objective. What should the AI risk professional establish FIRST?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Which AI vendor offers the most features<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> How the proposed AI use case supports the objective and what risks could affect value realization<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Whether the model can operate without documentation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> How quickly the project can bypass normal governance<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. How the proposed AI use case supports the objective and what risks could affect value realization<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> AI risk management should support value creation rather than operate independently from business strategy. Before selecting technology or designing controls, the organization should understand the business problem, expected benefits, affected stakeholders, and risks that could prevent the AI initiative from creating the intended value. This creates the context needed to determine appropriate risk appetite, governance, and lifecycle requirements. A sophisticated AI implementation that does not address a meaningful business objective may create cost and exposure without sufficient benefit. ISACA emphasizes alignment of AI use cases with organizational goals and risk appetite.<\/span><\/p>\n<p><b>Q382. An AI governance committee wants to delegate some low-risk approvals to business units while retaining oversight of high-risk systems. What governance design is MOST appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Require the board to approve every AI change<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Eliminate central governance entirely<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Permit unrestricted self-approval by all teams<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Establish risk-based delegated authority with defined thresholds and escalation requirements**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Establish risk-based delegated authority with defined thresholds and escalation requirements<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Risk-based delegation allows governance to remain efficient while preserving appropriate oversight. Low-risk AI use cases may be approved within business units if predefined criteria are met, while high-impact, autonomous, regulated, or sensitive-data use cases can be escalated to central governance. Thresholds should be documented and applied consistently. This avoids unnecessary bottlenecks while maintaining enterprise accountability. Requiring central approval for every minor AI activity can slow innovation, while unrestricted self-approval can create inconsistent risk treatment. Delegated authority works best when roles, limits, evidence requirements, and exception processes are clearly defined.<\/span><\/p>\n<p><b>Q383. A company discovers that AI policy requirements differ from an existing enterprise privacy policy. What should happen FIRST?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Reconcile the conflicting requirements through the appropriate governance and policy-management process<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Apply only the AI policy<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Apply whichever policy was written most recently<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Allow project teams to choose independently<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Reconcile the conflicting requirements through the appropriate governance and policy-management process<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Conflicting policies can create inconsistent implementation and unclear accountability. The organization should determine the intended requirements, applicable legal obligations, policy hierarchy, and whether one policy must be revised. Relevant stakeholders such as privacy, legal, risk, security, and AI governance should participate in the reconciliation. Simply choosing the newer document does not guarantee the correct outcome. Once resolved, the organization should communicate the interpretation and update related procedures and controls. AI governance should integrate with existing enterprise policies rather than creating parallel requirements that contradict established programs.<\/span><\/p>\n<p><b>Q384. A high-impact AI system affects individuals who may not understand how to challenge its decisions. Which governance capability is MOST important?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Larger model capacity<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> More automated decisions<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Accessible transparency, challenge, and redress mechanisms<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Fewer records of AI-supported decisions<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Accessible transparency, challenge, and redress mechanisms<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Individuals affected by consequential AI decisions may need a meaningful way to understand the AI&#8217;s role, challenge an outcome, provide additional information, and seek human review or remediation. Such mechanisms support accountability, fairness, and trustworthiness and may also be required under applicable laws or policies. A challenge process should be accessible and understandable rather than purely technical. Increasing automation does not solve concerns about rights or unfair outcomes. Appropriate records should also be retained so the organization can reconstruct and review disputed decisions.<\/span><\/p>\n<p><b>Q385. An organization trains an AI model on data collected from several business processes. Before reusing those records, what should the data governance team verify?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only that storage capacity is sufficient<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Only that the dataset is large<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Whether every record has the same file type<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Whether the proposed reuse is permitted, appropriate, and consistent with data-governance obligations**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Whether the proposed reuse is permitted, appropriate, and consistent with data-governance obligations<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Data gathered for one business purpose cannot automatically be reused for AI training. The organization should evaluate legal basis, purpose limitation, consent where applicable, contractual restrictions, classification, retention, confidentiality, and any commitments made to data subjects or customers. Data lineage should identify where the records originated and how they have been transformed. A large or technically clean dataset can still be unsuitable for AI use if the organization lacks appropriate rights or if reuse conflicts with privacy expectations. Responsible AI development therefore begins with lawful and governed data use.<\/span><\/p>\n<p><b>Q386. A machine-learning model uses hundreds of features, but many are unnecessary for achieving acceptable performance. Which risk-management principle should the team consider?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Minimize unnecessary data and features to reduce exposure and complexity<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Add more features regardless of need<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Retain all available data indefinitely<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Avoid documenting feature selection<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Minimize unnecessary data and features to reduce exposure and complexity<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Using unnecessary features can increase privacy exposure, security risk, model complexity, bias pathways, and maintenance burden without meaningful performance benefit. Feature minimization extends the broader principle of data minimization into model design. The development team should evaluate whether each feature contributes sufficient value and whether sensitive attributes or proxy variables are necessary. Reducing unnecessary inputs can also improve explainability and reduce attack surface. This does not mean automatically selecting the smallest possible feature set; the objective is to retain what is reasonably needed for the approved purpose and performance requirements.<\/span><\/p>\n<p><b>Q387. A model performs well on average but fails badly on unusual combinations of valid input values. Which testing approach is MOST appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Test only the most common inputs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Remove unusual cases from monitoring<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Perform edge-case and boundary-condition testing<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Increase model autonomy<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Perform edge-case and boundary-condition testing<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Average performance can hide serious weaknesses in rare but valid situations. Edge-case and boundary testing examines conditions near decision thresholds, unusual feature combinations, extreme values, incomplete inputs, and other scenarios that may occur less frequently but still matter. This is particularly important when the consequences of an incorrect output are significant. Findings may lead to model improvements, human escalation, input restrictions, or safer failure behavior. High-impact AI validation should therefore include more than routine samples and should reflect plausible adverse or unusual operating conditions.<\/span><\/p>\n<p><b>Q388. A high-risk AI system uses a newly updated model, but the previous approved version is still available. What capability does retaining the earlier version primarily support?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Permanent avoidance of future validation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Controlled rollback if the new model behaves unexpectedly<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Elimination of all change-management requirements<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Automatic risk acceptance<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Controlled rollback if the new model behaves unexpectedly<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Retaining a previous known-good model supports recovery if the new deployment produces unacceptable errors, fairness issues, security problems, or operational degradation. Effective rollback requires more than keeping the model file; dependencies, configuration, data compatibility, and deployment procedures should also support restoration. Rollback is a corrective capability and complements predeployment validation and postdeployment monitoring. It does not eliminate the need for change management or approval. Organizations should define objective rollback triggers and test the procedure so restoration can occur quickly when production behavior falls outside approved tolerances.<\/span><\/p>\n<p><b>Q389. A risk team wants to prioritize an AI scenario that could persist undetected for months and accumulate harm gradually. Which additional risk characteristic is MOST relevant?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Persistence or duration of exposure<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Model name length<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Development-team size<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Vendor headquarters location only<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Persistence or duration of exposure<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Some AI failures create immediate harm, while others can remain undetected and accumulate consequences over long periods. Persistence helps management understand whether exposure can compound before discovery. For example, a subtle discriminatory model may affect many decisions over months without triggering an obvious operational incident. This characteristic can influence monitoring intensity, detection controls, review frequency, and remediation urgency. Risk methodologies commonly focus on likelihood and impact, but additional dimensions such as velocity, detectability, reversibility, and persistence can improve prioritization for complex AI scenarios.<\/span><\/p>\n<p><b>Q390. An organization identifies a significant AI risk for which no feasible mitigation currently exists, but the business activity is optional. What treatment is MOST appropriate if exposure exceeds tolerance?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Accept the risk automatically<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Hide the risk from reporting<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Transfer it to the development team<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Avoid the risk by not proceeding with the activity**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Avoid the risk by not proceeding with the activity<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Risk avoidance removes the activity creating the exposure when residual risk cannot be reduced within acceptable tolerance and the activity is not mandatory. This may mean not deploying the AI system, disabling an autonomous capability, or selecting a different process. Acceptance would be inappropriate if exposure remains outside authorized appetite. Transfer may shift certain financial consequences but does not necessarily remove operational, legal, or reputational risk. Treatment decisions should reflect business value, feasibility, legal obligations, risk appetite, and whether alternative approaches can accomplish the underlying objective more safely.<\/span><\/p>\n<p><b>Q391. A control is designed to detect unauthorized changes to AI system prompts. What evidence BEST shows the control is functioning?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Logs and test results showing prompt changes are detected and appropriately escalated<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> The prompt document exists<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> The model owner states that prompts rarely change<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> The system has a high accuracy score<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Logs and test results showing prompt changes are detected and appropriately escalated<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Detective control effectiveness requires evidence that relevant events are actually identified and lead to appropriate response. Testing can introduce controlled prompt changes and confirm that the monitoring system detects them, records sufficient context, and alerts the responsible team. Production logs can provide additional evidence that the process continues operating over time. A written prompt or verbal assurance does not demonstrate control effectiveness. Model accuracy is unrelated to whether unauthorized configuration changes are detected. Material AI prompt changes can alter behavior significantly and therefore may require strong change-monitoring controls.<\/span><\/p>\n<p><b>Q392. An organization uses the same individual to develop, approve, and validate a high-risk AI control. What is the PRIMARY concern?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The control will automatically fail<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> The control will become too expensive<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Independence of control validation may be insufficient<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> AI models cannot use the control<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Independence of control validation may be insufficient<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> High-risk controls benefit from sufficient independent challenge. When one person designs, approves, and validates the same control, confirmation bias or unrecognized weaknesses may reduce assurance quality. Organizational size and practicality influence the degree of separation possible, so complete independence is not always required. Compensating measures can include peer review, second-line risk validation, independent testing, or periodic assurance. The objective is to ensure that control effectiveness is not based solely on self-assessment by the person responsible for creating and operating it.<\/span><\/p>\n<p><b>Q393. A model&#8217;s KRI remains within tolerance, but a related KCI shows that a critical safeguard is failing frequently. What should management do?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Ignore the KCI until the KRI breaches tolerance<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Investigate whether residual risk is increasing despite the current KRI level<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Remove the KCI from reporting<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Automatically classify the risk as low<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Investigate whether residual risk is increasing despite the current KRI level<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> KRIs and KCIs provide different but complementary information. A KRI may not immediately reflect deterioration in the control environment, particularly if it is a lagging measure. A failing critical control can signal that exposure is increasing before incidents or other risk outcomes become visible. Management should evaluate the control failure, reassess residual risk, and determine whether compensating controls or remediation are needed. Waiting for the risk indicator itself to breach tolerance may allow preventable exposure to persist. Leading control information is valuable precisely because it can provide earlier warning.<\/span><\/p>\n<p><b>Q394. Senior management receives monthly AI risk reports, but each month uses a different scoring scale. What is the MOST important improvement?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Add additional scoring scales<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Standardize the rating methodology so trends are comparable over time<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Remove historical comparisons<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Report only qualitative narratives<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Standardize the rating methodology so trends are comparable over time<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Trend analysis requires consistency. If risk-rating scales change frequently, movement may reflect methodology differences rather than actual changes in exposure. The organization should establish a stable methodology with documented definitions, thresholds, and data sources and use formal change control when modifications are necessary. If the methodology must change, management should explain the effect and recalculate prior periods where practical. Reliable reporting allows decision-makers to identify genuine deterioration or improvement and prevents misleading comparisons caused by measurement changes.<\/span><\/p>\n<p><b>Q395. A critical AI supplier begins outsourcing more of its service to subcontractors. What should the customer reassess?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only the supplier&#8217;s marketing position<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Whether outsourcing automatically improves risk<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Supply-chain exposure, control reliance, data handling, and concentration across new subcontractors<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Only the supplier&#8217;s pricing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Supply-chain exposure, control reliance, data handling, and concentration across new subcontractors<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Increased subcontracting can materially alter the supplier&#8217;s risk profile. New parties may process customer data, host critical components, provide foundation models, or introduce geographic and concentration dependencies. The customer should determine whether contractual notification requirements apply and whether new assurance is needed. The assessment should focus on material upstream dependencies rather than every minor supplier. A provider can remain contractually responsible while still creating increased operational or compliance exposure through its subcontractors. Ongoing supplier monitoring should capture such changes rather than relying only on initial due diligence.<\/span><\/p>\n<p><b>Q396. A vendor&#8217;s AI service is critical, but the contract contains no requirement to return customer data in a usable format at termination. What risk is MOST directly increased?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Exit and portability risk<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Model calibration risk<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Employee awareness risk<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Physical-security risk<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Exit and portability risk<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> If data cannot be returned in a usable format, migration to another provider can become difficult, expensive, or impossible. Exit planning should define data export formats, metadata, timing, deletion, assistance, and other transition obligations. Portability is particularly important when AI services rely on prompts, configuration, embeddings, logs, model outputs, or specialized datasets that another platform may need. A technically strong provider can still create high lock-in risk when contracts do not support transition. Exit requirements should therefore be negotiated before the organization becomes operationally dependent.<\/span><\/p>\n<p><b>Q397. An AI incident involves corrupted outputs, but it is unclear whether the cause was an attack or an ordinary model failure. What should incident responders do?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Assume malicious activity immediately<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Preserve evidence and investigate both security and nonsecurity failure hypotheses<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Close the incident because cause is uncertain<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Delete the affected model before collecting evidence<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Preserve evidence and investigate both security and nonsecurity failure hypotheses<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Similar AI symptoms can result from attacks, software defects, bad data, configuration errors, drift, or infrastructure problems. Responders should avoid prematurely deciding on one cause. Evidence such as logs, model versions, data changes, access records, configuration, and external dependencies should be preserved and analyzed systematically. Containment should proceed when ongoing harm is possible, but investigation should remain broad enough to identify the true cause. This improves remediation because security controls will not fix an ordinary data pipeline defect, and model retraining will not resolve a compromised system.<\/span><\/p>\n<p><b>Q398. An AI service is considered critical, but the organization&#8217;s business continuity plan assumes its third-party provider will recover within four hours without supporting evidence. What is the BEST action?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Treat the assumption as sufficient<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Remove the provider from the BIA<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Validate the provider&#8217;s recovery capability against the organization&#8217;s continuity requirements<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Increase the RTO automatically<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Validate the provider&#8217;s recovery capability against the organization&#8217;s continuity requirements<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Continuity assumptions about third parties should be supported by evidence. The organization can review contractual commitments, independent assurance, provider testing, architectural information, or joint exercises to determine whether supplier recovery capability aligns with business requirements. If the provider cannot meet the required recovery time, management may need fallback processes, alternate providers, additional redundancy, or formal risk acceptance. Adjusting the organization&#8217;s RTO merely to match the supplier would undermine the purpose of business impact analysis unless decision-makers explicitly determine that the business can tolerate the longer disruption.<\/span><\/p>\n<p><b>Q399. A recovery test restores an AI application correctly, but the restored environment lacks historical logs required for audit and investigation. What should be improved?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only model training procedures<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> The AI risk appetite statement<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Employee prompt-writing skills<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Backup and recovery requirements for required operational and audit evidence**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Backup and recovery requirements for required operational and audit evidence<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Recovery requirements may include more than the application, model, and production data. Logs and decision records can be necessary for audit, compliance, security investigation, customer disputes, and model-performance analysis. The organization should determine which evidence must remain available after a disaster and ensure backup, retention, and recovery procedures support those requirements. Not every log needs identical recovery objectives, so prioritization should reflect legal, business, and investigative needs. Recovery testing is valuable because it reveals whether required evidence actually survives a disruption.<\/span><\/p>\n<p><b>Q400. An organization wants to use AI to estimate emerging risk scenarios from internal and external data. What is the BEST way to govern the model&#8217;s output?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Treat all AI-generated estimates as official enterprise risk ratings<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Remove expert review to avoid subjective judgment<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Validate assumptions, evidence, and methodology before incorporating estimates into formal risk decisions<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Allow the AI model to accept the risks it identifies<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Validate assumptions, evidence, and methodology before incorporating estimates into formal risk decisions<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> AI can help identify patterns and emerging scenarios that risk teams might otherwise miss, but generated estimates may rely on incomplete data, hidden assumptions, or unreliable relationships. Qualified risk professionals should validate the underlying evidence, methodology, relevance, and uncertainty before using the output in formal risk ratings or treatment decisions. The AI system itself should also be monitored for performance and limitations. This approach captures the analytical benefits of AI while preserving human accountability for official enterprise risk management decisions.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Isaca AAIR Exam Dumps and Practice Test Dumps. Q381. An organization plans to introduce AI into a process that directly supports a strategic corporate objective. What should the AI risk professional establish FIRST? Which AI vendor offers the most features 2. How the proposed AI use case supports the objective and what risks [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18363"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=18363"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18363\/revisions"}],"predecessor-version":[{"id":18364,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18363\/revisions\/18364"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=18363"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=18363"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=18363"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}