Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free ISACA Advanced in AI Security Management Exam AAISM Exam Questions

Page: 1 / 17 Total 255 questions

Want more questions? Get Premium Access.

Question 1

An attack has occurred on an AI system that has been in use for two years. Which of the following would BEST mitigate the impact of the attack?

Correct Answer: B. Updating deployed training data with new adversarial data
Explanation:

When an AI system experiences an attack after being in production for an extended period, the most effective mitigation strategy is to update the deployed training data with new adversarial data. This process strengthens the model's resilience by retraining it to recognize and resist attack vectors that were previously unknown or unaccounted for. According to the AI Security Management (AAISM) framework, risk mitigation for AI systems must address model robustness through adversarial retraining, data quality improvement, and model lifecycle hardening rather than relying solely on reactive measures.

Why Option B is Correct:

Incorporating adversarial examples into the training set enhances the system's ability to correctly classify and withstand malicious inputs.

This approach directly mitigates the vulnerability exploited in the attack and supports a proactive, continuous risk management cycle.

Why Other Options Are Incorrect:

Option A: Monitoring helps detect suspicious activity but does not resolve the underlying vulnerability.

Option C: Concealing confidence scores may reduce model transparency but does not address the attack mechanism or its root cause.

Option D: Implementing access controls protects the model's architecture but does not improve model robustness against input manipulation attacks.

Exact Extract from Official AAISM Study Guide:

''AI risk management requires continuous improvement following incidents. After an adversarial or data poisoning event, the preferred risk treatment involves retraining the model using adversarial data and updated datasets to enhance robustness. This ensures the AI model adapts to evolving threat landscapes rather than merely restricting access or obscuring outputs.''


AI Security Management (AAISM) Body of Knowledge: AI Risk Treatment and Mitigation Strategies, Adversarial Robustness and Resilience Engineering.

AI Security Management Study Guide: Model Lifecycle Security, Continuous Risk Treatment through Adversarial Retraining.

ISO/IEC 23894:2023, Clause 8.3.2 --- Risk treatment through robustness improvement and adversarial data inclusion.

Question 2

Which of the following AI-driven systems should have the MOST stringent recovery time objective (RTO)?

Correct Answer: D. Industrial control system
Explanation:

AAISM risk guidance notes that the most stringent recovery objectives apply to industrial control systems, as downtime can directly disrupt critical infrastructure, manufacturing, or safety operations. Health support systems also require high availability, but industrial control often underpins safety-critical and real-time environments where delays can result in catastrophic outcomes. Credit risk models and navigation systems are important but less critical in terms of immediate physical and operational impact. Thus, industrial control systems require the tightest RTO.


AAISM Study Guide -- AI Risk Management (Business Continuity in AI)

ISACA AI Security Management -- RTO Priorities for AI Systems

Question 3

When robust input controls are not practical on a large language model (LLM) to prevent prompt injection attacks from external threats, which of the following would be the BEST compensating control to address the risk?

Correct Answer: A. Review and annotate the AI system's outputs
Explanation:

When preventive input hardening isn't feasible for LLMs, AAISM prescribes compensating detective and corrective controls---notably human review and annotation of outputs prior to downstream action---to reduce harm from prompt injection. Output-side review gates prevent untrusted instructions from propagating, enable rapid suppression/feedback loops, and provide labeled examples for subsequent model hardening. IAM (B) is necessary but does not mitigate injection in content; reviewing inputs (C) is less effective than auditing what the model is about to act on; fine-tuning for validation (D) is helpful long-term but is not an immediate compensating control when robust input validation is impractical.


Question 4

An organization utilizes AI-enabled mapping software to plan routes for delivery drivers. A driver following the AI route drives the wrong way down a one-way street, despite numerous signs. Which of the following biases does this scenario demonstrate?

Correct Answer: D. Automation
Explanation:

AAISM defines automation bias as the tendency of individuals to over-rely on AI-generated outputs even when contradictory real-world evidence is available. In this scenario, the driver ignores traffic signs and follows the AI's instructions, showing blind reliance on automation. Selection bias relates to data sampling, reporting bias refers to misrepresentation of results, and confirmation bias involves interpreting information to fit pre-existing beliefs. The most accurate description is automation bias.


AAISM Exam Content Outline -- AI Risk Management (Bias Types in AI)

AI Security Management Study Guide -- Automation Bias in AI Use

Question 5

An organization decides to use an anomaly-based intrusion detection system (IDS) integrated with a generative adversarial network (GAN)--enabled AI tool. The integrated tool would MOST effectively detect intrusions by leveraging:

Correct Answer: D. Synthetic intrusion data to train the tool's components
Explanation:

AAISM materials describe that GAN-based systems excel at generating synthetic data---including simulated attack traffic---which can significantly enhance anomaly-based intrusion detection capabilities. The guidance emphasizes that synthetic attack samples help strengthen the model's ability to detect rare or emerging intrusion types. This aligns with the principle that AI security controls should leverage adversarially generated data during training to improve resilience.

Options A and C describe generic ML enhancements, but not GAN-specific advantages. Option B is useful but insufficient for anomaly detection, which relies heavily on recognizing atypical, previously unseen patterns.


Question 6

An aerospace manufacturer prioritizing accuracy and security wants to use generative AI. Which LLM adoption plan BEST aligns with its risk appetite?

Correct Answer: A. Developing a private LLM to automate non-critical functions
Explanation:

AAISM notes that high-security industries (e.g., aerospace) should prefer private, controlled environments with restricted data exposure. Developing a private LLM for non-critical workloads minimizes operational and security risk while enabling innovation.

Public LLMs for critical functions (C) violate safety expectations. Purchased datasets (D) introduce unknown provenance. Outsourcing (B) increases third-party risk.


Question 7

An organization is designing an AI-based credit risk assessment system integrating sensitive financial data. Which option BEST supports security-by-design?

Correct Answer: B. Applying threat modeling specific to AI components before deployment
Explanation:

AAISM identifies AI-specific threat modeling as an essential early-stage control in security-by-design, particularly for high-risk systems like credit scoring. It systematically identifies:

* data poisoning

* bias vulnerabilities

* model evasion

* model extraction

* misuse scenarios

Differential privacy (A) is powerful but is a mitigation, not the overarching design control. Segmentation (C) and IP allow lists (D) are supporting controls but not the foundational step in secure design.


Question 8

Which of the following is the MOST serious consequence of an AI system correctly guessing the personal information of individuals and drawing conclusions based on that information?

Correct Answer: C. The output may reveal information about individuals or groups without their knowledge
Explanation:

The AAISM curriculum states that the most serious privacy concern occurs when AI systems infer and disclose sensitive personal or group information without the knowledge or consent of the individuals. This constitutes a direct breach of privacy rights and data protection principles, including those enshrined in GDPR and other global regulations. While litigation, reputational damage, or loss of trust are significant consequences, the unauthorized revelation of personal information through inference is classified as the most severe, because it directly undermines individual autonomy and confidentiality.


AAISM Exam Content Outline -- AI Risk Management

AI Security Management Study Guide -- Privacy and Confidentiality Risks

Question 9

A financial organization is concerned about the risk of prompt injection attacks on its customer service chatbot. Which of the following controls BEST addresses this concern?

Correct Answer: B. Input validation
Explanation:

AAISM describes prompt injection as an attack where adversaries craft inputs that manipulate model behavior or override system instructions. The recommended control pattern is to implement robust input validation and constraint mechanisms that sanitize and structure user inputs before they are processed by the model. The guidance includes techniques such as template-based prompts, restricted instruction sets, and validation rules to filter malicious or out-of-scope content. Human-in-the-loop (A) provides oversight but may not scale and is not a primary technical protection. Increasing model parameters (C) relates to capacity and performance, not security. Continuous monitoring (D) is important for detection but does not prevent prompt injection at the point of entry. Therefore, input validation, combined with controlled prompt construction, is identified as the best direct control against prompt injection attacks in customer-facing chatbots.


Question 10

A school district contracts a third-party provider for AI-based curriculum recommendations. Which of the following is the BEST way to ensure the vendor uses AI responsibly?

Correct Answer: C. Requiring the vendor to provide the model card
Explanation:

AAISM emphasizes transparency artifacts from vendors to enable due diligence and assurance. A model card documents intended use, data sources, limitations, performance across subgroups, known risks, and evaluation procedures---information necessary to assess safety, fairness, and compliance for sensitive contexts like education. SSO and support are useful operational features; generic ToS updates are insufficient without model-specific disclosures.


Question 11

Which BEST describes the role of model cards in AI solutions?

Correct Answer: B. They document training data and AI model use cases
Explanation:

AAISM explains that model cards provide structured documentation about AI models, including:

* intended use cases

* training data characteristics

* ethical considerations

* known limitations

* risk factors

* performance benchmarks

They are not visualization tools (A), do not create synthetic data (C), and do not tune models (D).


Question 12

Which of the following key risk indicators (KRIs) is MOST relevant when evaluating the effectiveness of an organization's AI risk management program?

Correct Answer: C. Percentage of AI projects in compliance
Explanation:

AAISM identifies percentage of AI projects in compliance as the most relevant KRI for evaluating AI risk management effectiveness. This metric directly reflects adherence to governance, regulatory, and security requirements. The number of models deployed (A) or systems with AI components (B) indicate scale, not risk management quality. Training requests (D) show awareness levels but do not measure effectiveness of risk management. Compliance percentage provides a direct, measurable indication of how well risks are being governed and mitigated.


AAISM Exam Content Outline -- AI Risk Management (Risk Metrics and Compliance)

AI Security Management Study Guide -- Key Risk Indicators in AI Programs

Question 13

Which of the following is MOST important to consider when validating a third-party AI tool?

Correct Answer: B. Right to audit
Explanation:

The AAISM framework specifies that when adopting third-party AI tools, the right to audit is the most critical contractual and governance safeguard. This ensures that the organization can independently verify compliance with security, privacy, and ethical requirements throughout the lifecycle of the tool. Terms and conditions provide general usage guidance but often limit liability rather than ensuring transparency. Industry certifications may indicate good practice but do not substitute for direct verification. Roundtable testing is useful for evaluation but lacks enforceability. Only the contractual right to audit provides formal assurance that the tool operates in accordance with organizational policies and external regulations.


AAISM Exam Content Outline -- AI Governance and Program Management (Third-Party Governance)

AI Security Management Study Guide -- Vendor Oversight and Audit Rights

Question 14

To ensure AI tools do not jeopardize ethical principles, it is MOST important to validate that:

Correct Answer: B. Outputs of AI tools do not perpetuate adverse biases
Explanation:

AAISM highlights that the core ethical risk in AI is the perpetuation of bias that results in unfair or discriminatory outcomes. Therefore, the most important validation step is ensuring that outputs of AI systems are free from adverse biases. A responsible development policy, stakeholder approvals, and privacy reviews all contribute to governance, but they do not directly ensure ethical outcomes. Validation of output fairness is the critical safeguard for ensuring AI does not violate ethical principles.


AAISM Study Guide -- AI Risk Management (Bias and Ethics Validation)

ISACA AI Security Management -- Ethical AI Practices

Question 15

A programmer suspects an AI system is inferring sensitive user information. What is the BEST action?

Correct Answer: A. Inform the governance panel
Explanation:

AAISM directs that potential privacy, ethical, or compliance risks must be escalated to the AI Governance Panel, the body responsible for oversight, risk approval, and corrective action.

Fine-tuning (B) is premature and may worsen risk. Code review (C) does not address model-level inference issues. Escalating directly to the CIO (D) bypasses the required governance process.