
EC-CouncilCertified Responsible AI Governance and Ethics
Domain 4Objective 3
Third-Party AI Risk Management and Supply Chain Security CRAGE Practice Questions (Page 9)
Part of the AI Risk and Third-Party Supply Chain Management domain, which makes up ~15% of our current practice bank.
50questions here
10free pages
7concepts
Questions 41–45
- 41
A company is considering a vendor that provides an AI-based customer analytics platform. The vendor has a bug bounty program and publishes an annual transparency report. The company's procurement team wants to perform due diligence. What should the team review?
Select an answer first - 42
A comprehensive vendor risk assessment for an AI vendor should include an evaluation of the vendor's compliance posture. Which of the following is a key element of that evaluation?
Select an answer first - 43
An organization has deployed a third-party natural language processing model for customer support. The vendor releases a new version of the model every month. The organization's risk team wants to ensure that the model's performance and ethical behavior remain consistent over time. Which approach best supports ongoing third-party AI risk monitoring?
Select an answer first - 44
Which of the following is a preventive strategy to mitigate supply chain attacks targeting AI components?
Select an answer first - 45
A software company uses an open-source AI library for image recognition in its product. The company discovers that the library's repository was compromised and a malicious version was published. The company has already integrated the malicious version into its product. What is the most effective mitigation strategy?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CRAGE” is a trademark of its owner, used for identification only.