Weekend Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: clap70

AAISM ISACA Advanced in AI Security Management (AAISM) Exam Questions and Answers

Questions 4

Which of the following is the GREATEST risk inherent to implementing generative AI?

Options:

A.

Lack of employee training

B.

Unidentified asset vulnerabilities

C.

Inadequate return on investment (ROI)

D.

Potential intellectual property violations

Buy Now
Questions 5

Which of the following types of testing can MOST effectively mitigate prompt hacking?

Options:

A.

Load

B.

Input

C.

Regression

D.

Adversarial

Buy Now
Questions 6

An organization is reviewing an AI application to determine whether it is still needed. Engineers have been asked to analyze the number of incorrect predictions against the total number of predictions made. Which of the following is this an example of?

Options:

A.

Control self-assessment (CSA)

B.

Model validation

C.

Key performance indicator (KPI)

D.

Explainable decision-making

Buy Now
Questions 7

A financial institution plans to deploy an AI system to provide credit risk assessments for loan applications. Which of the following should be given the HIGHEST priority in the system’s design to ensure ethical decision-making and prevent bias?

Options:

A.

Regularly update the model with new customer data to improve prediction accuracy.

B.

Integrate a mechanism for customers to appeal decisions directly within the system.

C.

Train the system to provide advisory outputs with final decisions made by human experts.

D.

Restrict the model’s decision-making criteria to objective financial metrics only.

Buy Now
Questions 8

Which of the following should be the PRIMARY consideration for an organization concerned about liabilities associated with unforeseen behavior from agentic AI systems?

Options:

A.

Model dependencies

B.

Approved base models

C.

Accountability model

D.

Acceptable risk level

Buy Now
Questions 9

An organization plans to apply an AI system to its business, but developers find it difficult to predict system results due to lack of visibility to the inner workings of the AI model. Which of the following is the GREATEST challenge associated with this situation?

Options:

A.

Gaining the trust of end users through explainability and transparency

B.

Assigning a risk owner who is responsible for system uptime and performance

C.

Determining average turnaround time for AI transaction completion

D.

Continuing operations to meet expected AI security requirements

Buy Now
Questions 10

Which of the following controls BEST mitigates the inherent limitations of generative AI models?

Options:

A.

Ensuring human oversight

B.

Adopting AI-specific regulations

C.

Classifying and labeling AI systems

D.

Reverse engineering the models

Buy Now
Questions 11

An organization plans to implement a new AI system. Which of the following is the MOST important factor in determining the level of risk monitoring activities required?

Options:

A.

The organization’s risk appetite

B.

The organization’s number of AI system users

C.

The organization’s risk tolerance

D.

The organization’s compensating controls

Buy Now
Questions 12

Which of the following is the MOST important consideration for an organization that has decided to adopt AI to leverage its competitive advantage?

Options:

A.

Develop a comprehensive strategic roadmap for AI integration

B.

Develop a comprehensive risk management process to address AI-related issues

C.

Develop internal training programs on AI governance, risk, and compliance (GRC)

D.

Develop a business case for the procurement of AI monitoring tools

Buy Now
Questions 13

To ensure AI tools do not jeopardize ethical principles, it is MOST important to validate that:

Options:

A.

The organization has implemented a responsible development policy

B.

Outputs of AI tools do not perpetuate adverse biases

C.

Stakeholders have approved alignment with company values

D.

AI tools are evaluated by the privacy department before implementation

Buy Now
Questions 14

During the creation of a new large language model (LLM), an organization procured training data from multiple sources. Which of the following is MOST likely to address the CISO's security and privacy concerns?

Options:

A.

Data augmentation

B.

Data minimization

C.

Data classification

D.

Data discovery

Buy Now
Questions 15

Which of the following metrics BEST evaluates the ability of a model to correctly identify all true positive instances?

Options:

A.

F1 score

B.

Recall

C.

Precision

D.

Specificity

Buy Now
Questions 16

Which of the following is MOST important to consider when validating a third-party AI tool?

Options:

A.

Terms and conditions

B.

Right to audit

C.

Industry analysis and certifications

D.

Roundtable testing

Buy Now
Questions 17

Which of the following is the BEST mitigation control for membership inference attacks on AI systems?

Options:

A.

Model ensemble techniques

B.

AI threat modeling

C.

Differential privacy

D.

Cybersecurity-oriented red teaming

Buy Now
Questions 18

Which of the following security framework elements BEST helps to safeguard the integrity of outputs generated by AI algorithms?

Options:

A.

Risk exposure due to bias in AI outputs is kept within an acceptable range

B.

Ethical standards are incorporated into security awareness programs

C.

Management is prepared to disclose AI system architecture to stakeholders

D.

Responsibility is defined for legal actions related to AI regulatory requirements

Buy Now
Questions 19

Personal data used to train AI systems can BEST be protected by:

Options:

A.

Erasing personal data after training

B.

Ensuring the quality of personal data

C.

Anonymizing personal data

D.

Hashing personal data

Buy Now
Questions 20

Which of the following is the MOST effective way to mitigate the risk of deepfake attacks?

Options:

A.

Relying on human judgment for oversight

B.

Limiting employee access to AI tools

C.

Validating the provenance of the data source

D.

Using a general-purpose large language model (LLM) to detect fraud

Buy Now
Questions 21

Which of the following AI-driven systems should have the MOST stringent recovery time objective (RTO)?

Options:

A.

Health support system

B.

Credit risk modeling system

C.

Car navigation system

D.

Industrial control system

Buy Now
Questions 22

An organization has requested a developer to apply AI algorithms to existing modules in order to improve customer service quality. At this stage, which of the following should be considered FIRST?

Options:

A.

The developer may need to be held accountable for business inquiries raised by customers

B.

IT management may need to revise the service agreement if AI behavior cannot be predefined

C.

Project sponsors may need to agree on a phased approach in order to ensure safe release

D.

The organization may need to explain the performance of the applied AI algorithm

Buy Now
Questions 23

Which of the following factors is MOST important for preserving user confidence and trust in generative AI systems?

Options:

A.

Bias minimization

B.

Access controls and secure storage solutions

C.

Transparent disclosure and informed consent

D.

Data anonymization

Buy Now
Questions 24

An organization is facing a deepfake attack intended to manipulate stock prices. The organization’s crisis communication plan has been activated. Which of the following is MOST important to include in the initial response?

Options:

A.

Conduct employee awareness training on recognizing deepfake videos and audio

B.

Provide clarifying information in a pre-approved public statement

C.

Conduct a detailed forensic analysis to identify the source of the deepfake

D.

Engage with brand monitoring services to track social media activity

Buy Now
Questions 25

An organization decides to contract a vendor to implement a new set of AI libraries. Which of the following is MOST important to address in the master service agreement to protect data used during the AI training process?

Options:

A.

Data pseudonymization

B.

Continuous data monitoring

C.

Independent certification

D.

Right to audit

Buy Now
Questions 26

An organization recently introduced a generative AI chatbot that can interact with users and answer their queries. Which of the following would BEST mitigate hallucination risk identified by the risk team?

Options:

A.

Performing model testing and validation

B.

Training the foundational model on large data sets

C.

Ensuring model developers have been trained in AI risk

D.

Fine-tuning the foundational model

Buy Now
Questions 27

Which of the following should be done FIRST when developing an acceptable use policy for generative AI?

Options:

A.

Determine the scope and intended use of AI

B.

Review AI regulatory requirements

C.

Consult with risk management and legal

D.

Review existing company policies

Buy Now
Exam Code: AAISM
Exam Name: ISACA Advanced in AI Security Management (AAISM) Exam
Last Update: Sep 13, 2025
Questions: 90
AAISM pdf

AAISM PDF

$25.5  $84.99
AAISM Engine

AAISM Testing Engine

$30  $99.99
AAISM PDF + Engine

AAISM PDF + Testing Engine

$40.5  $134.99