
EC-CouncilCertified Responsible AI Governance and Ethics
Domain 5Objective 2
Building Privacy, Trust, and Safety in AI Systems CRAGE Practice Questions (Page 3)
Part of the AI Security Architecture, Privacy, and Trust domain, which makes up ~19% of our current practice bank.
45questions here
9free pages
8concepts
Questions 11–15
- 11
A technology company is developing a new AI-powered personal assistant that will be used in homes. The assistant will record audio to respond to voice commands. The company wants to apply Privacy by Design, but there is a conflict: the assistant's functionality improves with more audio data, but privacy principles require data minimization. The product team must decide how to handle audio data. Which approach best resolves the conflict between functionality and privacy?
Select an answer first - 12
A bank is using an AI system to detect fraudulent transactions. The system has a high detection rate but also produces false positives, which can inconvenience customers. The bank wants to maintain customer trust while minimizing fraud losses. Which approach best balances these competing needs?
Select an answer first - 13
A tech company is developing an AI assistant for elderly care. The assistant can remind users to take medication, detect falls, and alert emergency services. The company wants to build trust with users and their families. However, there is a trade-off between the assistant's autonomy (e.g., automatically calling emergency services) and user control (e.g., requiring user confirmation before calling). Which approach best balances autonomy and user control to build trust?
Select an answer first - 14
A hospital is implementing an AI system that predicts patient deterioration. The system will use patient vital signs and medical history. The hospital must conduct a Data Protection Impact Assessment (DPIA) because the processing is likely to result in a high risk to individuals' rights and freedoms. Which step is essential in the DPIA process?
Select an answer first - 15
A financial services company is deploying an AI system that analyzes customer transaction data to detect fraudulent activity. The system will process personal financial data, and the company must comply with data protection regulations. As part of the Data Protection Impact Assessment (DPIA), the team identifies that the system collects more customer data than necessary for fraud detection. The team also notes that the data is retained for longer than needed. Which combination of actions best addresses the DPIA findings and aligns with the principles of data minimization and purpose limitation?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CRAGE” is a trademark of its owner, used for identification only.