
ISACAAdvanced in AI Security Management
Domain 2Objective 2
AI Threat and Vulnerability Management AAISM Practice Questions (Page 5)
Part of the AI Risk Management domain, which accounts for 31% of the AAISM exam.
38questions here
8free pages
11concepts
31%of the exam
Questions 21–25
- 21
What is the goal of a model extraction attack?
Select an answer first - 22
Which attack vector involves inserting a hidden trigger into a model so that it behaves maliciously only when the trigger is present?
Select an answer first - 23
A financial services firm deploys a fraud-detection model that approves or declines transactions in real time. The security team notices a sudden increase in false declines for a specific merchant category, but the model's overall accuracy remains stable. Which action is most appropriate to investigate whether an adversarial attack is occurring?
Select an answer first - 24
A security team is assessing an AI system that uses a pre-trained model from a third-party vendor. The team has limited resources and must decide where to focus its vulnerability assessment. Which approach is most effective?
Select an answer first - 25
A bank's credit-scoring model is suspected of being compromised by a poisoning attack that biases decisions against a specific demographic group. The bank must respond while maintaining regulatory compliance and minimizing customer impact. Which response sequence is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “AAISM” is a trademark of its owner, used for identification only.