
EC-CouncilCertified Responsible AI Governance and Ethics
Domain 4Objective 3
Third-Party AI Risk Management and Supply Chain Security CRAGE Practice Questions (Page 6)
Part of the AI Risk and Third-Party Supply Chain Management domain, which makes up ~15% of our current practice bank.
50questions here
10free pages
7concepts
Questions 26–30
- 26
A healthcare organization is evaluating a vendor that provides a pre-trained diagnostic imaging model. The vendor hosts the model in its own cloud environment and offers an API for inference. The organization's security team is concerned about the vendor's data handling practices and the model's behavior on diverse patient populations. Which action best addresses the organization's risk identification and assessment needs before signing a contract?
Select an answer first - 27
When managing third-party AI risks, which standard provides a framework for information security management systems (ISMS) that vendors can be certified against?
Select an answer first - 28
A government agency is procuring an AI system for resume screening. The vendor claims to be compliant with the agency's national AI ethics guidelines. The agency's procurement team must conduct a vendor risk assessment. Which combination of actions would provide the most comprehensive assessment?
Select an answer first - 29
A company uses a third-party AI model for real-time fraud detection. The vendor updates the model frequently, and the company has a monitoring system that tracks the model's accuracy and false positive rate. Recently, the monitoring system flagged a significant drop in accuracy. The company's incident response team is unsure whether the drop is due to a vendor update or a change in the input data distribution. What should the company do first?
Select an answer first - 30
A company's AI system uses a third-party pre-trained model that is integrated into a larger application. The company discovers that the model's training data included maliciously crafted examples that cause the model to misclassify certain inputs. This is an example of which type of supply chain attack, and what is the most effective mitigation?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CRAGE” is a trademark of its owner, used for identification only.