
ISACAAdvanced in AI Security Management
Domain 2Objective 2
AI Threat and Vulnerability Management AAISM Practice Questions (Page 6)
Part of the AI Risk Management domain, which accounts for 31% of the AAISM exam.
38questions here
8free pages
11concepts
31%of the exam
Questions 26–30
- 26
A security team is prioritizing vulnerabilities for an AI system that is used for medical diagnosis. The team has identified the following vulnerabilities: (1) a model inversion attack that could expose patient data, (2) a data poisoning vulnerability in the training pipeline, and (3) a prompt injection vulnerability in the system's natural language interface. The system is subject to HIPAA and must maintain high accuracy. Which vulnerability should be prioritized?
Select an answer first - 27
Which of the following is an example of a supply chain risk specific to AI systems?
Select an answer first - 28
A security analyst is categorizing threats to an AI system that uses a public cloud-based machine learning service. The analyst is concerned about an attacker who could steal the model by querying it repeatedly. Which threat category does this attack belong to?
Select an answer first - 29
Which regulatory requirement might affect how AI vulnerabilities are managed?
Select an answer first - 30
A company has implemented a vulnerability management lifecycle for its AI systems. The security team has identified a vulnerability in a model's inference API that allows an attacker to cause a denial of service. The team has patched the API and wants to verify that the vulnerability is resolved. Which action is most appropriate for verification?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “AAISM” is a trademark of its owner, used for identification only.