
ISACAAdvanced in AI Audit
Domain 2Objective 6
Threats and Vulnerabilities Specific to AI AAIA Practice Questions (Page 5)
Part of the AI Operations domain, which accounts for 46% of the AAIA exam.
31questions here
7free pages
8concepts
46%of the exam
Questions 21–25
- 21
An attacker repeatedly queries a machine learning model and uses the responses to build a functional copy of the model. This attack is known as:
Select an answer first - 22
A bank deploys a deep learning model to approve credit card transactions. An attacker discovers that by adding a subtle, imperceptible pattern to a transaction image, the model consistently misclassifies fraudulent transactions as legitimate. The attacker exploits this flaw repeatedly without needing to alter the model's training data. Which type of AI-specific threat is being exploited?
Select an answer first - 23
A backdoor attack on a machine learning model is a type of data poisoning. What is the defining characteristic of a backdoor attack?
Select an answer first - 24
A company deploys an LLM-based customer support system. They want to reduce the risk of prompt injection attacks that trick the model into revealing sensitive data. Which control would be most effective?
Select an answer first - 25
Why is lack of explainability considered a vulnerability in production AI systems?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “AAIA” is a trademark of its owner, used for identification only.