Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Responsible AI Governance and Ethics

Domain 4Objective 1

AI Risk and Threat Management CRAGE Practice Questions (Page 5)

Part of the AI Risk and Third-Party Supply Chain Management domain, which makes up ~15% of our current practice bank.

54questions here
11free pages
10concepts

Questions 21–25

  1. 21expert · hard

    A retail company uses a third-party AI vendor for inventory management. The vendor's model is hosted on the vendor's cloud infrastructure. The company has learned that the vendor had a security breach that may have exposed the model's training data. The company's contract with the vendor does not specify data breach notification procedures. Which action is most appropriate to manage this third-party risk?

    Select an answer first
  2. 22expert · hard

    A financial technology company uses an AI model from a third-party vendor to assess creditworthiness. The model has been found to have a bias against a certain demographic group. The vendor is unwilling to share the training data or allow the company to modify the model. The company must decide how to mitigate the bias risk. Which strategy is most feasible?

    Select an answer first
  3. 23expert · hard

    A global pharmaceutical company is deploying an AI system to assist in drug discovery. The system uses patient data from multiple countries. The company must comply with GDPR in Europe and other local data protection laws. The AI risk team has identified a risk that the model could inadvertently reveal patient identities. The company's legal team insists on strict data minimization, while the research team wants to retain as much data as possible for model accuracy. Which approach best balances compliance and model performance?

    Select an answer first
  4. 24foundation · easy

    Which adversarial attack aims to reconstruct or infer sensitive information about the training data by querying the model?

    Select an answer first
  5. 25application · medium

    A company's AI risk team has identified four risks: a model bias with high impact but low likelihood, a data poisoning attack with medium impact and medium likelihood, a system outage with high impact and high likelihood, and a regulatory fine with low impact and low likelihood. The company has limited resources. Which risk should be addressed first?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CRAGE” is a trademark of its owner, used for identification only.