Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Responsible AI Governance and Ethics

Domain 4Objective 3

Third-Party AI Risk Management and Supply Chain Security CRAGE Practice Questions (Page 1)

Part of the AI Risk and Third-Party Supply Chain Management domain, which makes up ~15% of our current practice bank.

50questions here
10free pages
7concepts

Questions 1–5

  1. 1application · medium

    A company uses a third-party AI model that is hosted on the vendor's infrastructure. The vendor uses a machine learning operations (MLOps) platform to manage model versions. The company is concerned about the risk of an attacker gaining access to the MLOps platform and modifying the model. What is the primary attack surface?

    Select an answer first
  2. 2application · medium

    A manufacturing company uses a third-party AI vision system to inspect products on an assembly line. The system is updated weekly with new model weights downloaded from the vendor's server. The company's security team is concerned about the integrity of the model weights during download. Which attack surface is most directly relevant?

    Select an answer first
  3. 3application · medium

    A company uses a third-party AI model for fraud detection. The vendor's model is updated monthly, and the company has a monitoring process that tracks the model's false positive rate. After a recent update, the false positive rate increases significantly. What should the company do as part of ongoing third-party AI risk monitoring?

    Select an answer first
  4. 4application · medium · select all that apply

    A university is procuring an AI system for student admissions. The vendor is a large tech company with a strong security reputation. The university's ethics committee is concerned about potential bias in the admissions model. Which actions should the university take as part of a comprehensive vendor risk assessment? (Select all that apply.)

    Select an answer first
  5. 5foundation · easy

    During AI supply chain due diligence, which of the following documents should be reviewed to understand the vendor's liability and data handling obligations?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CRAGE” is a trademark of its owner, used for identification only.