
ISACAAdvanced in AI Risk
Domain 3Objective 1
AI Risk Scenario Identification and Assessment (e.g., Threats, Vulnerabilities, and Attacks) AAIR Practice Questions (Page 5)
Part of the AI Risk Program Management domain, which accounts for 42% of the AAIR exam.
28questions here
6free pages
8concepts
42%of the exam
Questions 21–25
- 21
Which category of threat to an AI system is primarily concerned with an attacker stealing the model's architecture, parameters, or training data?
Select an answer first - 22
A government agency uses an AI system to screen job applications. The system is publicly accessible and the agency has published detailed documentation about the model's architecture and training data. An activist group with moderate technical skills has expressed interest in disrupting the system. Which factor MOST increases the likelihood of a successful attack on this system?
Select an answer first - 23
A financial institution uses a machine learning model to approve credit card transactions. The model was trained on historical transaction data that was collected from a public dataset. Recently, an attacker has been submitting fraudulent transactions that are designed to look like legitimate ones, causing the model to approve them. Which of the following is the MOST likely threat category for this attack?
Select an answer first - 24
Which of the following is a vulnerability in the deployment environment of an AI system?
Select an answer first - 25
Which factor is most directly considered when estimating the likelihood of an AI risk scenario?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “AAIR” is a trademark of its owner, used for identification only.