Summer Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: ecus65

Isaca AAISM - ISACA Advanced in AI Security Management (AAISM) Exam

Page: 1 / 3
Total 90 questions

Which of the following should be the PRIMARY consideration for an organization concerned about liabilities associated with unforeseen behavior from agentic AI systems?

A.

Model dependencies

B.

Approved base models

C.

Accountability model

D.

Acceptable risk level

A large pharmaceutical company using a new AI solution to develop treatment regimens is concerned about potential hallucinations with the introduction of real-world data. Which of the following is MOST likely to reduce this risk?

A.

Penetration testing

B.

Human-in-the-loop

C.

AI impact analysis

D.

Data asset validation

An organization utilizes AI-enabled mapping software to plan routes for delivery drivers. A driver following the AI route drives the wrong way down a one-way street, despite numerous signs. Which of the following biases does this scenario demonstrate?

A.

Selection

B.

Reporting

C.

Confirmation

D.

Automation

Which of the following is a key risk indicator (KRI) for an AI system used for threat detection?

A.

Number of training epochs

B.

Training time of the model

C.

Number of layers in the neural network

D.

Number of system overrides by cyber analysts

Which of the following controls BEST mitigates the risk of bias in AI models?

A.

Robust access control techniques

B.

Regular data reconciliation

C.

Cryptographic hash functions

D.

Diverse data sourcing strategies

A financial institution plans to deploy an AI system to provide credit risk assessments for loan applications. Which of the following should be given the HIGHEST priority in the system’s design to ensure ethical decision-making and prevent bias?

A.

Regularly update the model with new customer data to improve prediction accuracy.

B.

Integrate a mechanism for customers to appeal decisions directly within the system.

C.

Train the system to provide advisory outputs with final decisions made by human experts.

D.

Restrict the model’s decision-making criteria to objective financial metrics only.

Which of the following is the MOST important course of action prior to placing an in-house developed AI solution into production?

A.

Perform a privacy, security, and compliance gap analysis

B.

Deploy a prototype of the solution

C.

Obtain senior management sign-off

D.

Perform testing, evaluation, validation, and verification

Which of the following types of testing can MOST effectively mitigate prompt hacking?

A.

Load

B.

Input

C.

Regression

D.

Adversarial

When an attacker uses synthetic data to reverse engineer an organization’s AI model, it is an example of which of the following types of attack?

A.

Distillation

B.

Inversion

C.

Prompt

D.

Poisoning

The PRIMARY reason to conduct a privacy impact assessment (PIA) on an AI system is to:

A.

Identify applicable regulations

B.

Determine whether personal data is poisoned

C.

Build customer confidence

D.

Analyze how personal data is handled