Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Responsible AI Governance and Ethics

Domain 4Objective 3

Third-Party AI Risk Management and Supply Chain Security CRAGE Practice Questions (Page 2)

Part of the AI Risk and Third-Party Supply Chain Management domain, which makes up ~15% of our current practice bank.

50questions here
10free pages
7concepts

Questions 6–10

  1. 6application · medium · select all that apply

    A manufacturing company is selecting a third-party AI vendor for quality control. The vendor has a good reputation but has experienced a minor security incident in the past. The company's procurement team is performing due diligence. Which actions are appropriate for AI supply chain due diligence? (Select all that apply.)

    Select an answer first
  2. 7application · medium

    A company uses a third-party AI model that is distributed as a container image. The company's security team wants to implement a supply chain security control to ensure that only approved images are used in production. What should the team implement?

    Select an answer first
  3. 8application · medium

    A company uses a third-party AI model that is distributed as a container image. The company's security team discovers that the vendor's container registry was compromised and that a malicious image was published. The company has already pulled the image and is running it in production. What is the most immediate and effective response?

    Select an answer first
  4. 9expert · hard

    A company uses a third-party AI model for predictive maintenance. The vendor has a history of releasing updates that sometimes degrade performance. The company has a service-level agreement (SLA) with the vendor that includes penalties for performance degradation. The company's operations team wants to ensure that the model continues to meet performance thresholds. What is the best approach to manage this risk?

    Select an answer first
  5. 10expert · hard

    A telecommunications company uses a third-party AI model for network anomaly detection. The model is updated frequently by the vendor. The company's security team has limited resources and cannot manually review every update. The company wants to maintain effective monitoring without overburdening its team. Which strategy is most effective?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CRAGE” is a trademark of its owner, used for identification only.