
EC-CouncilCertified Responsible AI Governance and Ethics
Domain 4Objective 2
Risk Assessment CRAGE Practice Questions (Page 2)
Part of the AI Risk and Third-Party Supply Chain Management domain, which makes up ~15% of our current practice bank.
48questions here
10free pages
7concepts
Questions 6–10
- 6
What is the primary difference between qualitative and quantitative risk analysis?
Select an answer first - 7
A retail company has implemented a risk treatment for an AI supply chain risk by requiring the vendor to provide quarterly security audits. After the first year, the audits show that the vendor's security posture has significantly improved, and the risk level has decreased. However, the company's risk appetite has also become more stringent due to new regulations. What should the company do?
Select an answer first - 8
A hospital uses an AI diagnostic support system from a vendor. The system has a known risk of misdiagnosis for certain demographics. The hospital has a very low risk appetite for patient safety. The vendor offers to update the model, but this would require a 3-month downtime and significant costs. What is the most appropriate risk treatment?
Select an answer first - 9
A telecommunications company has implemented a risk monitoring process for its AI network optimization vendor. The process includes quarterly reviews and real-time alerts for model performance degradation. What is the primary purpose of this monitoring?
Select an answer first - 10
In the context of AI and third-party supply chain management, what is the primary purpose of risk assessment?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CRAGE” is a trademark of its owner, used for identification only.