
ISACAAdvanced in AI Risk
Domain 3Objective 5
AI Supply Chain Risk Management (e.g., Third Party Resources) AAIR Practice Questions (Page 2)
Part of the AI Risk Program Management domain, which accounts for 42% of the AAIR exam.
36questions here
8free pages
10concepts
42%of the exam
Questions 6–10
- 6
A security company uses a third-party AI model for threat detection. The model is proprietary, and the vendor does not disclose its architecture. The company is concerned about adversarial attacks that could fool the model. What is the most effective mitigation strategy?
Select an answer first - 7
A bank uses a third-party AI model for fraud detection. The model was accurate at deployment, but recent performance has declined, and the bank suspects the model's behavior is changing due to shifts in the underlying data. What is the most appropriate action to mitigate this risk?
Select an answer first - 8
Why is data lineage important in AI supply chain risk management?
Select an answer first - 9
Which standard provides requirements for an AI management system, including supply chain considerations?
Select an answer first - 10
A company is evaluating a third-party AI vendor for a critical application. The vendor has a strong security posture but has been criticized for using data without proper consent. The company's legal team is concerned about reputational and regulatory risks. What is the most important factor to consider in the due diligence process?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “AAIR” is a trademark of its owner, used for identification only.