Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISACA logo

ISACAAdvanced in AI Security Management

Domain 3Objective 1

AI Security Architecture and Design AAISM Practice Questions (Page 3)

Part of the AI Technologies and Controls domain, which accounts for 38% of the AAISM exam.

31questions here
7free pages
7concepts
38%of the exam

Questions 11–15

  1. 11expert · hard

    A multinational corporation is building a global AI system for supply chain optimization. The system ingests data from various regional offices, some of which are in countries with strict data localization laws. The data must be aggregated for training, but the company wants to minimize compliance risk. Which architecture best addresses this constraint?

    Select an answer first
  2. 12foundation · medium

    Which infrastructure security control is specifically used to protect the confidentiality of AI models and training data stored on disk?

    Select an answer first
  3. 13expert · hard

    A government agency is deploying an AI system for border control. The system uses facial recognition and must operate in real-time. The threat model identifies a risk that an attacker could craft physical perturbations (e.g., special glasses) to evade detection. The agency also has a strict requirement that the system must not be taken offline for maintenance during peak hours. Which mitigation strategy best balances the threat and the operational constraint?

    Select an answer first
  4. 14application · medium

    A company has deployed a machine learning model as a service that predicts equipment failure. The model is accessed via a REST API. The security team wants to prevent unauthorized users from querying the model and to detect if the model is being used in a way that could indicate an attack. Which set of controls should be implemented?

    Select an answer first
  5. 15expert · hard

    A company is conducting a security architecture review of its AI system. The review finds that the system uses a shared model for multiple clients, and each client's data is stored in the same database with a client ID field. The review also notes that the system does not have a mechanism to prevent a client from accessing another client's data if the client ID is manipulated. Which gap is most critical to address?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “AAISM” is a trademark of its owner, used for identification only.