
EC-CouncilCertified Responsible AI Governance and Ethics
Domain 4Objective 3
Third-Party AI Risk Management and Supply Chain Security CRAGE Practice Questions (Page 5)
Part of the AI Risk and Third-Party Supply Chain Management domain, which makes up ~15% of our current practice bank.
50questions here
10free pages
7concepts
Questions 21–25
- 21
A healthcare organization uses a third-party AI diagnostic tool. The tool is updated regularly by the vendor. The organization's risk team wants to implement ongoing monitoring to ensure the tool remains safe and effective. Which practices are appropriate for ongoing third-party AI risk monitoring? (Select all that apply.)
Select an answer first - 22
Which regulation directly addresses the security of network and information systems and is relevant to AI supply chain risk management in the European Union?
Select an answer first - 23
In the context of AI supply chain security, which of the following is a primary security challenge specific to the data component?
Select an answer first - 24
Which of the following is a unique attack surface in an AI supply chain that is not typically present in traditional software supply chains?
Select an answer first - 25
A company is evaluating two vendors for an AI-based customer service system. Vendor A has strong security certifications but a history of ethical controversies. Vendor B has no formal certifications but has a clean ethical record and a robust internal testing process. The company's board requires both security and ethical rigor. What should the company do?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CRAGE” is a trademark of its owner, used for identification only.