
EC-CouncilCertified Responsible AI Governance and Ethics
Domain 4Objective 3
Third-Party AI Risk Management and Supply Chain Security CRAGE Practice Questions (Page 10)
Part of the AI Risk and Third-Party Supply Chain Management domain, which makes up ~15% of our current practice bank.
50questions here
10free pages
7concepts
Questions 46–50
- 46
A company uses a third-party AI model that is distributed as a signed package. The company's security team wants to ensure that the package has not been tampered with before deployment. What should the team do?
Select an answer first - 47
An organization uses a third-party AI model for credit scoring. The vendor updates the model using data from a new source that the organization has not reviewed. Which category of third-party AI risk does this scenario primarily illustrate?
Select an answer first - 48
A financial services firm uses a third-party AI model for credit scoring. The vendor releases a new version of the model that the firm deploys after only checking that the API endpoint still responds. Two weeks later, the firm notices that the model's approval rate for a protected demographic group has dropped significantly. What should the firm do first?
Select an answer first - 49
When performing due diligence on a third-party AI provider, which of the following is an important indicator of the provider's reliability and security maturity?
Select an answer first - 50
In the context of third-party AI risk management, what is the purpose of a vendor risk register?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CRAGE
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CRAGE” is a trademark of its owner, used for identification only.