ISACA AAISM Test Engine Practice Test Questions, Exam Dumps [Q31-Q50]

Share

ISACA AAISM Test Engine Practice Test Questions, Exam Dumps

100% Free AAISM Daily Practice Exam With 257 Questions

NEW QUESTION # 31
An organization is looking to purchase an AI application from a vendor but is concerned about the security of its data. Which of the following is the MOST effective way to address this concern?

  • A. Ensure vendors disclose how the application uses the organization's data
  • B. Mandate an AI security audit by an external auditor before procurement
  • C. Initiate discussions between the organization's and the vendor's legal teams
  • D. Assess the vendor's publicly available AI usage policy

Answer: A

Explanation:
The priority control in AI vendor due diligence is ensuring explicit disclosure of data handling: data flows, purpose limitation, retention/deletion, training vs. inference use, isolation controls, access paths, subcontractors, and storage/transfer boundaries. This disclosure is then tied to contractual commitments and measurable controls. A public policy (Option A) may be incomplete; a pre-procurement external audit (Option C) can be valuable but is not always feasible or targeted to your data use; legal discussions (Option D) are necessary for terms but must be grounded in clear, detailed data-use disclosures to be effective.
References:
AAISM Body of Knowledge: Third-Party AI Risk Management; Data Governance and Usage Controls; Contractual and Technical Safeguards for Vendor AI.
AAISM Study Guide: AI Procurement Due Diligence; Data-Use Transparency (Training vs. Fine-tuning vs.
Inference); Retention, Purpose Limitation, and Cross-Border Controls.


NEW QUESTION # 32
When evaluating a new AI tool for intrusion prevention, which is MOST important to ensure fit within the existing program architecture?

  • A. Prioritize real-time anomaly detection
  • B. Confirm tool capabilities align with control objectives
  • C. Select a tool that integrates with the SIEM
  • D. Ensure automated response orchestration

Answer: B

Explanation:
AAISM stresses that AI tools must align with the organization's existing control objectives and governance requirements, ensuring consistency with risk management, detection philosophy, and operational processes.
Integration with SIEM (D) is important but secondary. Anomaly detection (B) is a feature, not an architectural requirement. Automated orchestration (A) is optional.
References: AAISM Study Guide - AI Security Architecture & Control Alignment.


NEW QUESTION # 33
When robust input controls cannot prevent prompt injections in an LLM, what is the BEST compensating control?

  • A. Conduct human reviews of AI system inputs
  • B. Implement identity and access management (IAM)
  • C. Review and annotate the AI system's outputs
  • D. Fine-tune the system to validate inputs

Answer: C

Explanation:
AAISM identifies output review and annotation as the most practical compensating control when robust input validation cannot be applied.
Output moderation detects:
* maliciously influenced responses
* unsafe outputs
* security-policy violations
IAM (B) does not mitigate prompt injection itself. Human review of inputs (C) is unrealistic at scale. Fine- tuning (A) cannot guarantee full prevention.
References: AAISM Study Guide - Generative AI Safeguards; Output Moderation Controls.


NEW QUESTION # 34
An organization is updating its vendor arrangements to facilitate the safe adoption of AI technologies. Which of the following would be the PRIMARY challenge in delivering this initiative?

  • A. Unwillingness of large AI companies to accept updated terms
  • B. Failure to adequately assess AI risk
  • C. Insufficient legal team experience with AI
  • D. Inability to sufficiently identify shadow AI within the organization

Answer: A

Explanation:
In the AAISM guidance, vendor management for AI adoption highlights that large AI providers often resist contractual changes, particularly when customers seek to impose stricter security, transparency, or ethical obligations. The official study materials emphasize that while organizations must evaluate AI risk and build internal expertise, the primary challenge lies in negotiating acceptable contractual terms with dominant AI vendors who may not be willing to adjust their standardized agreements. This resistance limits the ability of organizations to enforce oversight, bias controls, and compliance requirements contractually.
References:
AAISM Exam Content Outline - AI Risk Management
AI Security Management Study Guide - Third-Party and Vendor Risk


NEW QUESTION # 35
Which of the following BEST addresses risk associated with hallucinations in AI systems?

  • A. Content enrichment
  • B. Automated output validation
  • C. Human oversight
  • D. Recursive chunking

Answer: C

Explanation:
AAISM prescribes human-in-the-loop (HITL) controls as the primary safeguard for high-impact generative AI use cases to mitigate hallucination risk. Human oversight ensures critical outputs are reviewed, corrected, and approved before use, with accountability, escalation, and documented decision trails. Automated validators and enrichment help reduce errors but are secondary; recursive chunking is a prompting tactic, not a governance control.
References: AI Security Management (AAISM) Body of Knowledge: Responsible AI & Human Oversight; Generative AI Risk Controls-Approval Workflows and Human Review; AAISM Study Guide: Hallucination Risk Treatment with HITL and Approval Gates.


NEW QUESTION # 36
An organization uses an AI tool to scan social media for product reviews. Fraudulent social media accounts begin posting negative reviews attacking the organization's product. Which type of AI attack is MOST likely to have occurred?

  • A. Availability attack
  • B. Model inversion
  • C. Deepfake
  • D. Data poisoning

Answer: A

Explanation:
The AAISM materials classify availability attacks as attempts to disrupt or degrade the functioning of an AI system so that its outputs become unreliable or unusable. In this scenario, the fraudulent social media accounts are deliberately overwhelming the AI tool with misleading negative reviews, undermining its ability to deliver accurate sentiment analysis. This aligns directly with the concept of an availability attack. Model inversion relates to reconstructing training data from outputs, deepfakes involve synthetic content generation, and data poisoning corrupts the training set rather than manipulating inputs at runtime. Therefore, the fraudulent review campaign is most accurately identified as an availability attack.
References:
AAISM Study Guide - AI Risk Management (Adversarial Threats and Availability Risks) ISACA AI Security Management - Attack Classifications


NEW QUESTION # 37
A data scientist creating categories and training the algorithm on large data sets is an example of which type of AI model learning technique?

  • A. Reinforcement
  • B. Machine learning (ML)
  • C. Supervised
  • D. Unsupervised

Answer: C

Explanation:
AAISM classifies learning paradigms by the presence of labeled targets. Creating categories (labels) and training on them is supervised learning, where input features are mapped to known outputs and optimization minimizes prediction error against ground truth. Unsupervised (B) discovers structure without labels; reinforcement (A) optimizes behavior via rewards; "machine learning" (C) is the broad field, not the specific technique.
References: AI Security Management (AAISM) Body of Knowledge - AI/ML Foundations; Learning Paradigms and Data Requirements. AAISM Study Guide - Supervised vs. Unsupervised vs. Reinforcement Learning; Label Quality and Model Performance Dependencies.


NEW QUESTION # 38
Which of the following involves documenting and monitoring the complete journey of data as it flows through an AI system?

  • A. Lineage
  • B. Processing
  • C. Origin
  • D. Transformation

Answer: A

Explanation:
Data lineage records and monitors the end-to-end journey of data-sources, movements, transformations, storage locations, uses, and dependencies-providing traceability, auditability, and accountability across the AI lifecycle. "Origin" is a single point (provenance), "transformation" is one step within the flow, and
"processing" is a general activity rather than a governance record of the entire path.
References: AI Security Management (AAISM) Body of Knowledge: Data Governance-Provenance and Lineage; AAISM Study Guide: Lineage Documentation, Traceability, and Audit Evidence.


NEW QUESTION # 39
Which of the following is the GREATEST concern when a vendor enables generative AI features for an organization's critical system?

  • A. Bias and ethical practices
  • B. Security monitoring and alerting
  • C. Proposed regulatory enhancements
  • D. Access to the model

Answer: D

Explanation:
When enabling genAI capabilities in a critical system, AAISM prioritizes controlling access to the model and its interfaces (prompt surfaces, context windows, tools/functions, and connected data) because exposure expands the attack surface for prompt injection, data exfiltration, jailbreaks, and misuse. Monitoring (C) is necessary but detective; ethics and bias (D) are vital but secondary to immediate safety and security of a mission-critical environment; proposed regulations (B) are not an immediate operational risk.
References: AAISM Body of Knowledge: GenAI Security-Access Governance, Interface Hardening, and Prompt Surface Controls; AAISM Study Guide: Critical System Safeguards-Least Privilege, Guardrails, and Abuse Prevention.


NEW QUESTION # 40
Which of the following is the MOST critical success factor for an AI implementation project?

  • A. Ensuring AI risk is captured in the risk register
  • B. Mapping data throughout the life cycle
  • C. Developing and using model cards
  • D. Obtaining senior management buy-in

Answer: D

Explanation:
AAISM identifies executive sponsorship and senior management buy-in as the foremost success factor for AI initiatives. It secures resources, resolves cross-functional conflicts, sets risk appetite, and enforces adherence to governance and controls. Model cards (A), risk registers (B), and lifecycle data mapping (C) are vital practices within the program, but without top-level commitment, adoption, funding, and accountability often fail.
References: AI Security Managementâ„¢ (AAISM) Body of Knowledge - AI Program Governance; Executive Sponsorship & Accountability; Strategy-to-Control Alignment for Successful AI Delivery.


NEW QUESTION # 41
A large pharmaceutical company using a new AI solution to develop treatment regimens is concerned about potential hallucinations with the introduction of real-world data. Which of the following is MOST likely to reduce this risk?

  • A. Penetration testing
  • B. AI impact analysis
  • C. Human-in-the-loop
  • D. Data asset validation

Answer: C

Explanation:
AAISM materials identify human-in-the-loop governance as the most effective safeguard against risks such as hallucinations in AI systems used in high-stakes domains like healthcare. By ensuring that human experts validate outputs before they influence patient treatment decisions, organizations preserve accountability, safety, and accuracy. Penetration testing is a cybersecurity measure, not relevant to hallucination risk. AI impact analysis helps evaluate systemic effects but does not directly prevent faulty outputs. Data validation improves input quality but cannot fully prevent generative hallucinations. The key safeguard is human-in-the- loop oversight.
References:
AAISM Study Guide - AI Governance and Program Management (Human Oversight in High-Risk AI) ISACA AI Security Management - Mitigating Hallucinations in Generative AI


NEW QUESTION # 42
Which of the following is the GREATEST risk inherent to implementing generative AI?

  • A. Inadequate return on investment (ROI)
  • B. Potential intellectual property violations
  • C. Lack of employee training
  • D. Unidentified asset vulnerabilities

Answer: B

Explanation:
The AAISM framework identifies intellectual property (IP) violations as the most significant inherent risk in deploying generative AI. These systems often rely on large-scale internet data for training, which may inadvertently contain copyrighted or proprietary material. This creates legal and reputational exposure when outputs reproduce or reference protected content. While employee training gaps, asset vulnerabilities, and ROI concerns are relevant risks, they are not inherent to generative models themselves. The greatest inherent risk tied directly to generative AI adoption is the possibility of violating intellectual property rights.
References:
AAISM Study Guide - AI Risk Management (Generative AI Risks and Legal Exposure) ISACA AI Security Management - Copyright and IP Concerns in Generative AI


NEW QUESTION # 43
Which of the following should be a PRIMARY consideration when defining recovery point objectives (RPOs) and recovery time objectives (RTOs) for generative AI solutions?

  • A. Maintaining consistent hardware configurations to prevent discrepancies during model restoration
  • B. Prioritizing computational efficiency over data integrity to minimize downtime
  • C. Ensuring the backup system can restore training data sets within the defined RTO window
  • D. Preserving the most recent versions of data models to avoid inaccuracies in functionality

Answer: C

Explanation:
When setting RPOs and RTOs for AI systems, especiallygenerative AI, thecritical factor is the restoration of training data and model artifacts within the recovery window. Without this, restored systems may function inaccurately or incompletely, undermining business continuity.
AAISM risk management principles emphasize:
* Recovery objectives must align withdata protection requirementsfor both training and inference data.
* The ability to restorelarge-scale training datasetsis primary, since downtime without them leads to operational and compliance risks.
* Computational efficiency and hardware consistency are secondary considerations, but not the primary drivers of RPO/RTO definitions.
Thus, ensuring backup and restore capabilities of training datasets directly within RTO is theprimary requirement.


NEW QUESTION # 44
An organization utilizes AI-enabled mapping software to plan routes for delivery drivers. A driver following the AI route drives the wrong way down a one-way street, despite numerous signs. Which of the following biases does this scenario demonstrate?

  • A. Confirmation
  • B. Automation
  • C. Reporting
  • D. Selection

Answer: B

Explanation:
AAISM defines automation bias as the tendency of individuals to over-rely on AI-generated outputs even when contradictory real-world evidence is available. In this scenario, the driver ignores traffic signs and follows the AI's instructions, showing blind reliance on automation. Selection bias relates to data sampling, reporting bias refers to misrepresentation of results, and confirmation bias involves interpreting information to fit pre-existing beliefs. The most accurate description is automation bias.
References:
AAISM Exam Content Outline - AI Risk Management (Bias Types in AI)
AI Security Management Study Guide - Automation Bias in AI Use


NEW QUESTION # 45
During the deployment of a generative AI platform, a risk assessment highlighted threats such as data leakage and prompt manipulation. Which of the following is the BEST way to ensure appropriate control selection?

  • A. Map identified AI threats to enterprise control catalogs and integrate AI-specific safeguards where gaps exist
  • B. Postpone control selection until deployment and address risk through enhanced monitoring
  • C. Apply AI-specific controls from external frameworks without customization and initiate monitoring to expedite compliance
  • D. Rely primarily on vendor-provided security features and seek third-party certifications

Answer: A

Explanation:
AAISM requires that control selection be threat-led and context-specific, aligning AI threats to the organization's existing enterprise control catalogs (security, privacy, resilience) and augmenting them with AI- specific safeguards where coverage is insufficient. This ensures consistency with the risk appetite, removes duplication, and closes AI-unique gaps (e.g., prompt injection, data leakage from context windows, model misuse). Generic reliance on vendors or uncustomized external frameworks does not ensure fit-for-purpose coverage, and deferring control selection to post-deployment contradicts proactive risk treatment.
References: AI Security Managementâ„¢ (AAISM) Body of Knowledge - Governance & Program Controls; Control Selection and Tailoring; Threat-to-Control Mapping for AI Systems; Risk Appetite & Control Assurance Alignment.


NEW QUESTION # 46
What is the GREATEST concern when a vendor enables generative AI features for an organization's critical system?

  • A. Bias and ethical practices
  • B. Security monitoring and alerting
  • C. Proposed regulatory enhancements
  • D. Access to the model

Answer: D

Explanation:
AAISM highlights that uncontrolled access to generative AI in critical systems introduces the highest level of risk, as such models can:
* expose sensitive data
* execute unintended actions
* be manipulated through injected prompts
* cause operational instability
Monitoring (A) is important but not the core risk. Bias (B) is significant but secondary in critical systems.
Regulatory enhancements (C) are indirect.
References: AAISM Study Guide - Generative AI Operational Risk; Access Control Priority.


NEW QUESTION # 47
A health services organization is developing a proprietary generative AI chatbot to assist patients with medical devices. Which of the following should be the organization's HIGHEST priority?

  • A. Maximizing neural network size
  • B. Tuning algorithms used in the AI model
  • C. Maximizing the amount of training data
  • D. Selecting the appropriate training data

Answer: D

Explanation:
AAISM prioritizes training data suitability-lawful sourcing, provenance, quality, representativeness, and safety-especially in health-related applications. The correctness and appropriateness of training data determine clinical safety, reduction of harmful outputs, and compliance with data protection/sector obligations. Larger models or more data do not compensate for inappropriate or low-quality datasets; tuning is secondary to ensuring the right data with rigorous curation, labeling quality, and guardrails aligned to patient safety requirements.
References:* AI Security Managementâ„¢ (AAISM) Body of Knowledge: Data Governance & Quality; High- Risk/Health Context Controls; Safety & Harm Minimization* AAISM Study Guide: Data Provenance & Suitability, Domain-Specific Dataset Controls; Compliance-by-Design for Sensitive Sectors


NEW QUESTION # 48
Which of the following approaches BEST helps reduce model bias?

  • A. Increasing the number of labels per instance
  • B. Ensuring diversity in training data sources
  • C. Decreasing frequency of model updates
  • D. Utilizing a more complex architecture

Answer: B

Explanation:
AAISM states that the strongest control against bias is ensuring representative, diverse, and inclusive training data. This directly minimizes skew and systemic underrepresentation.
Complex architectures (B) do not reduce bias and may exacerbate it. Reducing updates (C) increases drift.
More labels (D) improves supervision quality but does not inherently solve bias if the data itself is skewed.
References: AAISM Study Guide - Bias Mitigation and Data Quality Requirements.


NEW QUESTION # 49
Which of the following AI data management techniques involves creating validation and test data?

  • A. Learning
  • B. Training
  • C. Splitting
  • D. Annotating

Answer: C

Explanation:
Data splitting partitions a labeled dataset into training, validation, and test subsets to enable unbiased model tuning and evaluation. Training (A) consumes the training split; annotating (B) adds labels; learning (D) is a general term for model optimization, not a data management step.
References: AI Security Management (AAISM) Body of Knowledge - Data Lifecycle Controls; Dataset Partitioning for Validation and Testing. AAISM Study Guide - Train/Validation/Test Splits and Evaluation Integrity.


NEW QUESTION # 50
......


ISACA AAISM Exam Syllabus Topics:

TopicDetails
Topic 1
  • AI Governance and Program Management: This section of the exam measures the abilities of AI Security Governance Professionals and focuses on advising stakeholders in implementing AI security through governance frameworks, policy creation, data lifecycle management, program development, and incident response protocols.
Topic 2
  • AI Technologies and Controls: This section of the exam measures the expertise of AI Security Architects and assesses knowledge in designing secure AI architecture and controls. It addresses privacy, ethical, and trust concerns, data management controls, monitoring mechanisms, and security control implementation tailored to AI systems.
Topic 3
  • AI Risk Management: This section of the exam measures the skills of AI Risk Managers and covers assessing enterprise threats, vulnerabilities, and supply chain risk associated with AI adoption, including risk treatment plans and vendor oversight.

 

Use Valid New AAISM Test Notes & AAISM Valid Exam Guide: https://www.passcollection.com/AAISM_real-exams.html

AAISM exam torrent ISACA study guide: https://drive.google.com/open?id=1U9g90VWkR3RvhbegHV0n62DnR0g7A2C2