
ISACAAdvanced in AI Risk
Domain 3Objective 1
AI Risk Scenario Identification and Assessment (e.g., Threats, Vulnerabilities, and Attacks) AAIR Practice Questions (Page 4)
Part of the AI Risk Program Management domain, which accounts for 42% of the AAIR exam.
28questions here
6free pages
8concepts
42%of the exam
Questions 16–20
- 16
Which attack vector is primarily used to determine whether a specific data record was part of the model's training dataset?
Select an answer first - 17
An AI risk manager needs to document a risk scenario involving a data poisoning attack on a fraud detection model. The documentation will be used to communicate the risk to senior management and to support decision-making. Which of the following is the MOST important element to include in the documentation?
Select an answer first - 18
Which combination of factors is typically used to prioritize AI risk scenarios?
Select an answer first - 19
A security team is estimating the likelihood of a data poisoning attack on a model that is retrained weekly using user-generated content. The model is used to recommend content on a social media platform. The team has observed a small number of coordinated accounts attempting to submit malicious content. Which factor MOST increases the likelihood of a successful data poisoning attack?
Select an answer first - 20
A social media platform uses an AI content moderation system to identify hate speech. An attacker has found a way to craft posts that bypass the moderation system, leading to a flood of offensive content on the platform. Which of the following is the MOST significant impact of this risk scenario?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “AAIR” is a trademark of its owner, used for identification only.