The CEO of a large, multi-sector organization has discovered that, without formal guidance, business units have developed shadow IT by incorporating AI into their daily operations. In response, an AI governance group has been established to address this issue. Which of the following is MOST important for the group to gather from each business unit?
AInventory of models in use
BBusiness continuity plan (BCP)
CAPI key management practices
DSoftware bill of materials
Which option BEST characterizes the role of risk documentation within an AI governance program?
AOffering detailed analyses of technical risk and vulnerabilities
BDemonstrating governance, risk, and compliance (GRC) for external stakeholders
COutlining the acceptable levels of risk for AI-related initiatives
DProviding a record of past AI-related incidents for audits
Which key risk indicator (KRI) is MOST relevant for assessing the effectiveness of an organization’s AI risk management program?
APercentage of critical business systems with AI components
BNumber of AI-related training requests submitted
CNumber of AI models deployed into production
DPercentage of AI project in compliance
When preparing for an AI incident, which of the following should be completed FIRST?
AImplement a clear communication channel to report AI incidents.
BEstablish a cross-functional incident response team with AI knowledge.
CEstablish recovery processes for AI system models and data sets.
DCreate containment and eradication procedures for AI-related incidents.
QuestionQ6
AI Risk Management
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ7
AI Technologies and Controls
QuestionQ8
AI Governance and Program Management
QuestionQ9
AI Risk Management
QuestionQ10
AI Technologies and Controls
QuestionQ11
AI Risk Management
QuestionQ12
AI Risk Management
QuestionQ13
AI Risk Management
QuestionQ14
AI Technologies and Controls
QuestionQ15
AI Risk Management
QuestionQ16
AI Risk Management
QuestionQ17
AI Technologies and Controls
QuestionQ18
AI Risk Management
QuestionQ19
AI Risk Management
QuestionQ20
AI Technologies and Controls
QuestionQ21
AI Governance and Program Management
QuestionQ22
AI Risk Management
QuestionQ23
AI Technologies and Controls
QuestionQ24
AI Technologies and Controls
QuestionQ25
AI Governance and Program Management
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Ad
Want a break from the ads?
Go ad-free and unlock Learn Mode, Exam Mode, AstroTutor AI and every premium tool — everything you need to walk in prepared, and confident.
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Which of the following is a PRIMARY consideration when defining recovery point objectives (RPOs) and recovery time objectives (RTOs) for generative AI solutions?
APrioritizing computational efficiency over data integrity to minimize downtime
BMaintaining consistent hardware configurations to prevent discrepancies during model restoration
CPreserving the most recent versions of data models to avoid inaccuracies in functionality
DEnsuring the backup system can restore training data sets within the defined RTO window
Which of the following would BEST help mitigate vulnerabilities related to hidden triggers in generative AI models?
AMonitoring model outputs and suspicious patterns to detect trigger activations
BRegularly retraining the model using a diverse data set
CApplying differential privacy and masking sensitive patterns in the training data
DIncorporating adversarial training to expose and neutralize potential triggers
Which of the following belongs in an AI acceptable-use policy?
AEthical and legal compliance standards
BAI training data requirements
CData collection and storage processes
DAI monitoring requirements
An organization plans to commission a third-party AI system to make decisions using sensitive data. Which of the following metrics is MOST important for the organization to consider?
AAccessibility rating
BModel response time
CAccuracy thresholds
DService availability
During which phase of the AI life cycle are models evaluated for security and confirmed to be free from malicious manipulation?
AVerification
BValidation
CEvaluation
DTesting
An organization is deploying AI agents that have tools and data access. Which of the following is MOST important to include in end-user acceptable-use policies to reduce misuse?
AValidate agent compliance with output restrictions.
BAllow users to configure agent autonomy to optimize productivity.
CRestrict prompts intended to manipulate agent behavior.
DPromote agent independence by limiting human review of AI decisions.
While deploying a generative AI platform, a risk assessment identifies threats including data leakage and prompt manipulation. Which option is the BEST approach to ensure suitable controls are selected?
AMap identified AI threats to enterprise control catalogs and integrate AI-specific safeguards where gaps exist.
BRely primarily on vendor-provided security features and seek third-party certifications.
CPostpone control selection until deployment and address risk through enhanced monitoring.
DApply AI-specific controls from external frameworks without customization and initiate monitoring to expedite compliance.
Which option BEST ensures that AI components are validated during disaster recovery testing?
ARunning simulated data loss scenarios by erasing test records from the AI system's feature store
BDisconnecting primary model training clusters to test retraining workflow during extended outages
CSimulating denial of service (DoS) attacks against AI APIs to evaluate detection capabilities
DMonitoring model performance metrics during failover and recovery to assess system stability
An organization requires large datasets for application testing. Which of the following would BEST meet this need?
AUsing open-source data repositories
BReviewing AI model cards
CPerforming AI data augmentation
DIncorporating data from search content
Which of the following would be of the GREATEST concern to an information security manager when a small startup organization proposes using a pre-trained, open-source AI solution?
AThe organization has limited visibility to how data is being used.
BThere may be a lack of support if the project is abandoned.
CThe model is not compatible with enterprise architecture (EA).
DThe open-source model includes a hidden backdoor.
When integrating AI to drive innovation, which of the following can BEST help an organization manage security risk?
AEvaluating compliance requirements
BRe-evaluating the risk appetite
CAdopting a phased approach
DSeeking third-party advice
Which of the following is the MOST effective defense against cyberattacks that modify input data to evade detection by the model?
AEnhancing model robustness through adversarial training
BImplementing restricted access to model's internal parameters
CConducting periodic monitoring activities on model's decisions
DApplying differential privacy controls on training datasets
Which of the following is the MOST critical key risk indicator (KRI) for an AI system?
AThe amount of data in the model
BThe rate of drift in the model
CThe accuracy rate of the model
DThe response time of the model
A healthcare organization has begun designing an AI-supported advisory system. Which option BEST reduces the risk that AI-generated recommendations could negatively affect patients?
AAdvise patients in advance that AI is utilized to provide services at an optimal level.
BReview outputs and compare against thresholds to ensure volatility remains within the acceptable range.
CIntroduce a means by which patients can opt out of AI-based services and recommendations.
DEnsure the AI framework fulfills compliance requirements mandated by regulatory authorities.
Which approach BEST supports separating sensitive data from shareable data to help prevent an AI chatbot from unintentionally revealing confidential information?
AZero Trust
BSandboxing
CSiloing
DContainerization
Who is accountable for implementing the recommendations in a final report following an external AI compliance audit?
ASystem architects
BInternal auditors
CEnd users
DModel owners
Which of the following employee-awareness topics would MOST likely be updated to address AI-enabled cyber risk?
AMalicious insider threats
BClean desk policy
CAuthentication controls
DSocial engineering
A chatbot was identified as producing low-quality and inaccurate output, and a subsequent investigation found that insecure third-party libraries were in use. Which of the following is the BEST approach to prevent this incident from happening again?
APerform automated data validation and access control review.
BEstablish secure coding practices and perform testing, evaluation, verification, and validation (TEVV).
CSanitize input and implement rate limiting.
DEmploy strict content security policies (CSPs) and document asset listing.
Personal data used for training AI systems can BEST be protected by:
Aanonymizing personal data.
Bhashing personal data.
Cerasing personal data after training.
Densuring the quality of personal data.
The PRIMARY purpose of adopting and implementing AI architecture as part of an organizational AI program is to:
Adeploy fast and cost-efficient AI systems for rapidly changing environments.
Bprovide a basis for identification of threats and vulnerabilities.
Calign the system components of AI with the business goals of the organization.
Densure the development of powerful, efficient, and scalable AI systems.
Community Discussion