
EC-CouncilCertified Responsible AI Governance and Ethics
Domain 4Objective 1
AI Risk and Threat Management CRAGE Practice Questions (Page 1)
Part of the AI Risk and Third-Party Supply Chain Management domain, which makes up ~15% of our current practice bank.
54questions here
11free pages
10concepts
Questions 1–5
- 1
What is a key benefit of regularly communicating AI risk status to executive leadership?
Select an answer first - 2
A company's AI risk team has identified a critical vulnerability in a customer-facing recommendation system. The vulnerability could expose customer preferences. The team needs to communicate this risk to the executive board, which is not technically sophisticated. What is the best way to communicate this risk?
Select an answer first - 3
A government agency uses an AI system to screen benefit applications. The system begins to deny applications at a much higher rate than usual. The agency has an incident response plan for IT systems but not specifically for AI failures. What is the most important first step in responding to this AI-related incident?
Select an answer first - 4
An e-commerce company uses an AI chatbot to handle customer service. The chatbot sometimes generates offensive responses, which the company has identified as a risk. The company also notices that the chatbot's responses are influenced by user inputs in real time. Which additional risk should the company identify and categorize?
Select an answer first - 5
A hospital is deploying an AI system to predict patient deterioration. The risk team has identified two risks: (1) the model may fail to predict deterioration for patients with rare conditions, and (2) the model may produce false alarms that desensitize staff. The hospital has limited resources for risk mitigation. Which risk should be prioritized for mitigation?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CRAGE” is a trademark of its owner, used for identification only.