New Year Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70percent

IAPP AIGP Artificial Intelligence Governance Professional Exam Practice Test

Demo: 49 questions
Total 165 questions

Artificial Intelligence Governance Professional Questions and Answers

Question 1

What is the main purpose of accountability structures under the Govern function of the NIST Al Risk Management Framework?

Options:

A.

To empower and train appropriate cross-functional teams.

B.

To establish diverse, equitable and inclusive processes.

C.

To determine responsibility for allocating budgetary resources.

D.

To enable and encourage participation by external stakeholders.

Question 2

You are a privacy program manager at a large e-commerce company that uses an Al tool to deliver personalized product recommendations based on visitors' personal information that has been collected from the company website, the chatbot and public data the company has scraped from social media.

A user submits a data access request under an applicable U.S. state privacy law, specifically seeking a copy of their personal data, including information used to create their profile for productrecommendations.

What is the most challenging aspect of managing this request?

Options:

A.

Some of the visitor's data is synthetic data that the company does not have to provide to the data subject.

B.

The data subject's data is structured data that can be searched, compiled and reviewed only by an automated tool.

C.

The data subject is not entitled to receive a copy of their data because some of it was scraped from public sources.

D.

Some of the data subject's data is unstructured data and you cannot untangle it from the other data, including information about other individuals.

Question 3

All of the following are included within the scope of post-deployment Al maintenance EXCEPT?

Options:

A.

Ensuring that all model components are subject a control framework.

B.

Dedicating experts to continually monitor the model output.

C.

Evaluating the need for an audit under certain standards.

D.

Defining thresholds to conduct new impact assessments.

Question 4

The best practice to manage third-party risk associated with AI systems is to create and implement policies that?

Options:

A.

Focus on the financial stability of third-party vendors as the primary criterion for risk assessment.

B.

Provide for an appropriate level of due diligence and ongoing monitoring based on the defined risk.

C.

Require third-party AI systems to undergo a comprehensive audit by an external cybersecurity firm every six months.

D.

Focus on the technical aspects of AI systems, such as data security, while ethical risks are addressed through suitable contracts.

Question 5

You are part of your organization’s ML engineering team and notice that the accuracy of a model that was recently deployed into production is deteriorating.

What is the best first step address this?

Options:

A.

Replace the model with a previous version.

B.

Conduct champion/challenger testing.

C.

Perform an audit of the model.

D.

Run red-teaming exercises.

Question 6

Please select 3 of the 5 options below. No partial credit will be given.

All of the following are unique characteristics of AI that require a comprehensive approach to governance EXCEPT?

Options:

A.

Autonomy.

B.

Automation.

C.

Adaptability.

D.

Speed and scale.

E.

Superintelligence.

Question 7

Pursuant to the White House Executive Order of November 2023, who is responsible for creating guidelines to conduct red-teaming tests of Al systems?

Options:

A.

National Institute of Standards and Technology (NIST).

B.

National Science and Technology Council (NSTC).

C.

Office of Science and Technology Policy (OSTP).

D.

Department of Homeland Security (DHS).

Question 8

The best method to ensure a comprehensive identification of risks for a new AI model is?

Options:

A.

An environmental scan.

B.

Red teaming.

C.

Integration testing.

D.

An impact assessment.

Question 9

What is the best method to proactively train an LLM so that there is mathematical proof that no specific piece of training data has more than a negligible effect on the model or its output?

Options:

A.

Clustering.

B.

Transfer learning.

C.

Differential privacy.

D.

Data compartmentalization.

Question 10

Which of the following is an obligation of an importer of high-risk AI systems under the EU AI Act?

Options:

A.

Provide technical documentation.

B.

Affix the CE marking.

C.

Verify the Declaration of Conformity.

D.

Conduct a data protection impact assessment.

Question 11

What is the most important reason for documenting risks when developing an AI system?

Options:

A.

To provide transparency to stakeholders.

B.

To align with industry standards.

C.

To promote knowledge sharing.

D.

To mitigate potential liability.

Question 12

A US-based mortgage lender has purchased a chatbot. They plan to have the chatbot collect information from consumers who are interested in loans and offer the consumers 2-3 different options based on its current pricing and product offerings, which change frequently. This chatbot was initially developed and previously deployed by a Russian airline for booking flights.

The best option for the part of the process that generates the loan offers is?

Options:

A.

Retrieval-Augmented Generation.

B.

Multimodal Generative AI.

C.

Expert System.

D.

Quantum computing

Question 13

A company has trained an ML model primarily using synthetic data, and now intends to use live personal data to test the model.

Which of the following is NOT a best practice apply during the testing?

Options:

A.

The test data should be representative of the expected operational data.

B.

Testing should minimize human involvement to the extent practicable.

C.

The test data should be anonymized to the extent practicable.

D.

Testing should be performed specific to the intended uses.

Question 14

The planning phase of the Al life cycle articulates all of the following EXCEPT the?

Options:

A.

Objective of the model.

B.

Approach to governance.

C.

Choice of the architecture.

D.

Context in which the model will operate.

Question 15

Which of the following is the least relevant consideration in assessing whether users should be given the right to opt out from an Al system?

Options:

A.

Feasibility.

B.

Risk to users.

C.

Industry practice.

D.

Cost of alternative mechanisms.

Question 16

All of the following are elements of establishing a global Al governance infrastructure EXCEPT?

Options:

A.

Providing training to foster a culture that promotes ethical behavior.

B.

Creating policies and procedures to manage third-partyrisk.

C.

Understanding differences in norms across countries.

D.

Publicly disclosing ethical principles.

Question 17

What is the most significant risk of deploying an AI model that can create realistic images and videos?

Options:

A.

Copyright infringement.

B.

Security breaches.

C.

Downstream harms.

D.

Output cannot be protected.

Question 18

During the planning and design phases of the Al development life cycle, bias can be reduced by all of the following EXCEPT?

Options:

A.

Stakeholder involvement.

B.

Feature selection.

C.

Human oversight.

D.

Data collection.

Question 19

Your organization is searching for a new way to help accurately forecast sales predictions by various types of customers.

Which of the following is the best type of model to choose if your organization wants to customize the model and avoid lock-in?

Options:

A.

A free large language model.

B.

A classic machine learning model.

C.

A proprietary generative AI model.

D.

A subscription-based, multimodal model.

Question 20

Retraining an LLM can be necessary for all of the following reasons EXCEPT?

Options:

A.

To minimize degradation in prediction accuracy due tochanges in data.

B.

Adjust the model's hyper parameters to a specific use case.

C.

Account for new interpretations of the same data.

D.

To ensure interpretability of the model's predictions.

Question 21

An AI system's function, the industry and the location in which it operates are important factors in considering which of the following?

Options:

A.

Organizational accountability.

B.

Internal governance needs.

C.

Diversity of data sources.

D.

Explainability of results.

Question 22

MULTI-SELECT

Please select 3 of the 5 options below. No partial credit will be given.

Training an AI model is time-consuming because of?

Options:

A.

The complexity of the AI model.

B.

The maturity of AI governance.

C.

The volume of training data.

D.

The number of stakeholders.

E.

The quality of the training data.

Question 23

During the first month when the company monitors the model for bias, it is most important to?

Options:

A.

Continue disparity testing.

B.

Provide regular awareness training.

C.

Analyze the quality of the training and testing data.

D.

Document the results of final decisions made by the human underwriter.

Question 24

CASE STUDY

Please use the following answer the next question:

A local police department in the United States procured an Al system to monitor and analyze social media feeds, online marketplaces and other sources of public information to detect evidence of illegal activities (e.g., sale of drugs or stolen goods). The Al system works by surveilling the public sites in order to identify individuals that are likely to have committed a crime. It cross-references the individuals against data maintained by law enforcement and then assigns a percentage score of the likelihood of criminal activity based on certain factors like previous criminal history, location, time, race and gender.

The police department retained a third-party consultant assist in the procurement process, specifically to evaluate two finalists. Each of the vendors provided information about their system's accuracy rates, the diversity of their training data and how their system works. The consultant determined that the first vendor’s system has a higher accuracy rate and based on this information, recommended this vendor to the police department.

The police department chose the first vendor and implemented its Al system. As part of the implementation, the department and consultant created a usage policy for the system, whichincludes training police officers on how the system works and how to incorporate it into their investigation process.

The police department has now been using the Al system for a year. An internal review has found that every time the system scored a likelihood of criminal activity at or above 90%, the police investigation subsequently confirmed that the individual had, in fact, committed a crime. Based on these results, the police department wants to forego investigations for cases where the Al system gives a score of at least 90% and proceed directly with an arrest.

What is the best reason the police department should continue to perform investigations even if the Al system scores an individual's likelihood of criminal activity at or above 90%?

Options:

A.

Because the department did not perform an impact assessment for this intended use.

B.

Because Al systems that affect fundamental civil rights should not be fully automated.

C.

Because investigations may identify additional individuals involved in the crime.

D.

Because investigations may uncover information relevant to sentencing.

Question 25

A deployer discovers that a high-risk AI recruiting system has been making widespread errors, resulting in harms to the rights of a considerable number of EU residents who are denied consideration for jobs for improper reasons such as ethnicity, gender and age.

According to the EU AI Act, what should the company do first?

Options:

A.

Notify the provider, the distributor, and finally the relevant market authority of the serious incident.

B.

Identify any decisions that may have been improperly made and re-open them for human review.

C.

Submit an incomplete report to the relevant market authority immediately and follow up with a complete report as soon as possible.

D.

Conduct a thorough investigation of the serious incident within the 15 day timeline and present the completed report to the relevant market authority.

Question 26

According to the EU Al Act, providers of what kind of machine learning systems will be required to register with an EU oversight agency before placing their systems in the EU market?

Options:

A.

Al systems that are harmful based on a legal risk-utility calculation.

B.

Al systems that are "strong" general intelligence.

C.

Al systems trained on sensitive personal data.

D.

Al systems that are high-risk.

Question 27

Which of the following arenotconsidered biometric data under U.S. privacy laws?

Options:

A.

Iris scans

B.

Walking gait

C.

Keystroke dynamics

D.

GPS location of a user’s fitness watch

Question 28

CASE STUDY

A global marketing agency is adapting a large language model ("LLM") to generate content for an upcoming marketing campaign for a client's new product: a hard hat designed for construction workers of any gender to better protect them from head injuries.

The marketing agency is accessing the LLM through an application programming interface ("API") developed by a third-party technology company. They want to generate text to be used for targeted advertising communications that highlight the benefits of the hard hat to potential purchasers. Both the marketing agency and the technology company have taken reasonable steps to address Al governance.

The marketing company has:

•           Entered into a contract with the technology company with suitable representations and warranties.

•           Completed an impact assessment on the LLM for this intended use.

•           Built technical guidance on how to measure and mitigate bias in the LLM.

•           Enabled technical aspects of transparency, explainability, robustness and privacy.

•           Followed applicable regulatory requirements.

•           Created specific legal statements and disclosures regarding the use of the Al on its client's advertising.

The technology company has:

•           Provided guidance and resources to developers to address environmental concerns.

•           Build technical guidance on how to measure and mitigate bias in the LLM.

•           Provided tools and resources to measure bias specific to the LLM.

•           Enabled technical aspects of transparency, explainability, robustness and privacy.

•           Mapped and mitigated potential societal harms and large-scale impacts.

•           Followed applicable regulatory requirements and industry standards.

•           Created specific legal statements and disclosures regarding the LLM. including with respect to IP and rights to data.

The marketing company and its tech provider have taken reasonable steps to govern the AI’s use, including legal disclosures, impact assessments, and bias mitigation. However, the company wants to takeone more stepto improve governance and reduce risks related to ongoing oversight and accountability.

While the marketing agency took steps to mitigate its risks, the best additional step would be to:

Options:

A.

Negotiate an intellectual property indemnity from the technology company

B.

Evaluate the use of AI in the marketing industry to identify best practices

C.

Engage a third party to lead the procurement selection process

D.

Establish a governance committee to oversee the project

Question 29

Under the NIST Al Risk Management Framework, all of the following are defined as characteristics of trustworthy Al EXCEPT?

Options:

A.

Tested and Effective.

B.

Secure and Resilient.

C.

Explainable and Interpretable.

D.

Accountable and Transparent.

Question 30

Scenario:

A distributor operating in the EU is responsible for selling imported high-risk AI systems to businesses. The distributor wants to ensure they fulfill all applicable obligations under the EU AI Act.

All of the following are obligations of a distributor of high-risk AI systems under the EU AI Act EXCEPT?

Options:

A.

Corrective actions

B.

Verification of CE marking

C.

Registration in EU Database

D.

Communication with national authorities

Question 31

CASE STUDY

Please use the following answer the next question:

XYZ Corp., a premier payroll services company that employs thousands of people globally, is embarking on a new hiring campaign and wants to implement policies and procedures to identify and retain the best talent. The new talent will help the company's product team expand its payroll offerings to companies in the healthcare and transportation sectors, including in Asia.

It has become time consuming and expensive for HR to review all resumes, and they are concerned that human reviewers might be susceptible to bias.

Address these concerns, the company is considering using a third-party Al tool to screen resumes and assist with hiring. They have been talking to several vendors about possibly obtaining a third-party Al-enabled hiring solution, as long as it would achieve its goals and comply with all applicable laws.

The organization has a large procurement team that is responsible for the contracting of technology solutions. One of the procurement team's goals is to reduce costs, and it often prefers lower-cost solutions. Others within the company are responsible for integrating and deploying technology solutions into the organization's operations in a responsible, cost-effective manner.

The organization is aware of the risks presented by Al hiring tools and wants to mitigate them. It also questions how best to organize and train its existing personnel to use the Al hiring tool responsibly. Their concerns are heightened by the fact that relevant laws vary across jurisdictions and continue to change.

The frameworks that would be most appropriate for XYZ's governance needs would be the NIST Al Risk Management Framework and?

Options:

A.

NIST Information Security Risk (NIST SP 800-39).

B.

NIST Cyber Security Risk Management Framework (CSF 2.0).

C.

IEEE Ethical System Design Risk Management Framework (IEEE 7000-21).

D.

Human Rights, Democracy, and Rule of Law Impact Assessment (HUDERIA).

Question 32

Which of the following is a subcategory of Al and machine learning that uses labeled datasets to train algorithms?

Options:

A.

Segmentation.

B.

Generative Al.

C.

Expert systems.

D.

Supervised learning.

Question 33

CASE STUDY

Please use the following answer the next question:

XYZ Corp., a premier payroll services company that employs thousands of people globally, is embarking on a new hiring campaign and wants to implement policies and procedures to identify and retain the best talent. The new talent will help the company's product team expand its payroll offerings to companies in the healthcare and transportation sectors, including in Asia.

It has become time consuming and expensive for HR to review all resumes, and they are concerned that human reviewers might be susceptible to bias.

Address these concerns, the company is considering using a third-party Al tool to screen resumes and assist with hiring. They have been talking to several vendors about possibly obtaining a third-party Al-enabled hiring solution, as long as it would achieve its goals and comply with all applicable laws.

The organization has a large procurement team that is responsible for the contracting of technology solutions. One of the procurement team's goals is to reduce costs, and it often prefers lower-cost solutions. Others within the company are responsible for integrating and deploying technology solutions into the organization's operations in a responsible, cost-effective manner.

The organization is aware of the risks presented by Al hiring tools and wants to mitigate them. It also questions how best to organize and train its existing personnel to use the Al hiring tool responsibly. Their concerns are heightened by the fact that relevant laws vary across jurisdictions and continue to change.

Which other stakeholder groups should be involved in the selection and implementation of the Al hiring tool?

Options:

A.

Finance and Legal.

B.

Marketing and Compliance.

C.

Supply Chain and Marketing.

D.

Litigation and Product Development.

Question 34

CASE STUDY

A company is considering the procurement of an AI system designed to enhance the security of IT infrastructure. The AI system analyzes how users type on their laptops, including typing speed, rhythm and pressure, to create a unique user profile. This data is then used to authenticate users and ensure that only authorized personnel can access sensitive resources.

When prioritizing the updates to its policies, rules and procedures to include the new AI system for user authentication, the organization should:

Options:

A.

Update third-party data sharing policies

B.

Update security controls for sensitive data

C.

Ensure that any personal data used is only processed for a specific and lawful purpose

D.

Reduce the complexity of the policy to make it easier for non-technical employees to understand

Question 35

Under the Canadian Artificial Intelligence and Data Act, when must the Minister of Innovation, Science and Industry be notified about a high-impact Al system?

Options:

A.

When use of the system causes or is likely to cause material harm.

B.

When the algorithmic impact assessment has been completed.

C.

Upon release of a new version of the system.

D.

Upon initial deployment of the system.

Question 36

Which of the following best defines an "Al model"?

Options:

A.

A system that applies defined rules to execute tasks.

B.

A system of controls that is used to govern an Al algorithm.

C.

A corpus of data which an Al algorithm analyzes to make predictions.

D.

A program that has been trained on a set of data to find patterns within the data.

Question 37

CASE STUDY

Please use the following answer the next question:

XYZ Corp., a premier payroll services company that employs thousands of people globally, is embarking on a new hiring campaign and wants to implement policies and procedures to identify and retain the best talent. The new talent will help the company's product team expand its payroll offerings to companies in the healthcare and transportation sectors, including in Asia.

It has become time consuming and expensive for HR to review all resumes, and they are concerned that human reviewers might be susceptible to bias.

Address these concerns, the company is considering using a third-party Al tool to screen resumes and assist with hiring. They have been talking to several vendors about possibly obtaining a third-party Al-enabled hiring solution, as long as it would achieve its goals and comply with all applicable laws.

The organization has a large procurement team that is responsible for the contracting of technology solutions. One of the procurement team's goals is to reduce costs, and it often prefers lower-cost solutions. Others within the company are responsible for integrating and deploying technology solutions into the organization's operations in a responsible, cost-effective manner.

The organization is aware of the risks presented by Al hiring tools and wants to mitigate them. It also questions how best to organize and train its existing personnel to use the Al hiring tool responsibly. Their concerns are heightened by the fact that relevant laws vary across jurisdictions and continue to change.

All of the following are potential negative consequences created by using the Al tool when making hiring decisions EXCEPT?

Options:

A.

Reputational harm.

B.

Civil rights violations.

C.

Discriminatory treatment.

D.

Intellectual property infringement.

Question 38

CASE STUDY

A premier payroll services company that employs thousands of people globally, is embarking on a new hiring campaign and wants to implement policies and procedures to identify and retain the best talent. The new talent will help the company's product team expand its payroll offerings to companies in the healthcare and transportation sectors, including in Asia.

It has become time consuming and expensive for HR to review all resumes, and they are concerned that human reviewers might be susceptible to bias.

To address these concerns, the company is considering using a third-party Al tool to screen resumes and assist with hiring. They have been talking to several vendors about possibly obtaining a third-party Al-enabled hiring solution, as long as it would achieve its goals and comply with all applicable laws.

The organization has a large procurement team that is responsible for the contracting of technology solutions. One of the procurement team's goals is to reduce costs, and it often prefers lower-cost solutions. Others within the company deploy technology solutions into the organization’s operations in a responsible, cost-effective manner.

The organization is aware of the risks presented by Al hiring tools and wants to mitigate them. It also questions how best to organize and train its existing personnel to use the Al hiring tool responsibly. Their concerns are heightened by the fact that relevant laws vary across jurisdictions and continue to change.

The organization continues planning the adoption of an AI tool to support hiring, but is concerned about potential bias in content generated by AI systems and how that could affect public perception.

Which of the following measures should the company adopt tobest mitigate its risk of reputational harmfrom using the AI tool?

Options:

A.

Test the AI tool pre- and post-deployment

B.

Ensure the vendor provides indemnification for the AI tool

C.

Require the procurement and deployment teams to agree upon the AI tool

D.

Continue to require the company’s hiring personnel to manually screen all applicants

Question 39

What is theprimary purposeof an AI impact assessment?

Options:

A.

To determine whether a conformity assessment is needed

B.

To escalate the findings to the appropriate owner(s)

C.

To identify and measure the benefits of an AI system

D.

To anticipate and manage the potential risks and harms of an AI system

Question 40

If it is possible to provide a rationale for a specific output of an Al system, that system can best be described as?

Options:

A.

Accountable.

B.

Transparent.

C.

Explainable.

D.

Reliable.

Question 41

An EU bank intends to launch a multi-modal Al platform for customer engagement and automated decision-making assist with the opening of bank accounts. The platform has been subject to thorough risk assessments and testing, where it proves to be effective in not discriminating against any individual on the basis of a protected class.

What additional obligations must the bank fulfill prior to deployment?

Options:

A.

The bank must obtain explicit consent from users under the privacy Directive.

B.

The bank must disclose how the Al system works under the Ell Digital Services Act.

C.

The bank must subject the Al system an adequacy decision and publish its appropriate safeguards.

D.

The bank must disclose the use of the Al system and implement suitable measures for users to contest automated decision-making.

Question 42

Scenario:

A financial services company is planning a new AI project to assess creditworthiness. The AI team is mapping out what tasks should be completed during theplanning phaseof the AI lifecycle.

The planning phase of the AI lifecycle includes all of the following EXCEPT:

Options:

A.

Definition of underlying assumptions

B.

Approach to governance

C.

Choice of the architecture

D.

Context in which the model will operate

Question 43

What type of organizational risk is associated with Al's resource-intensive computing demands?

Options:

A.

People risk.

B.

Security risk.

C.

Third-party risk.

D.

Environmental risk.

Question 44

According to the GDPR, what is an effective control to prevent a determination based solely on automated decision-making?

Options:

A.

Provide a just-in-time notice about the automated decision-making logic.

B.

Define suitable measures to safeguard personal data.

C.

Provide a right to review automated decision.

D.

Establish a human-in-the-loop procedure.

Question 45

A U.S. mortgage company developed an Al platform that was trained using anonymized details from mortgage applications, including the applicant’s education, employment and demographic information, as well as from subsequent payment or default information. The Al platform will be used automatically grant or deny new mortgage applications, depending on whether the platform views an applicant as presenting a likely risk of default.

Which of the following laws is NOT relevant to this use case?

Options:

A.

Fair Housing Act.

B.

Fair Credit Reporting Act.

C.

Equal Credit Opportunity Act.

D.

Title VII of the Civil Rights Act of 1964.

Question 46

You asked a generative Al tool to recommend new restaurants to explore in Boston, Massachusetts that have a specialty Italian dish made in a traditional fashion without spinach and wine. The generative Al tool recommended five restaurants for you to visit.

After looking up the restaurants, you discovered one restaurant did not exist and two others did not have the dish.

This information provided by the generative Al tool is an example of what is commonly called?

Options:

A.

Prompt injection.

B.

Model collapse.

C.

Hallucination.

D.

Overfitting.

Question 47

Which of the following disclosures is NOT required for an EU organization that developed and deployed a high-risk Al system?

Options:

A.

The human oversight measures employed.

B.

How an individual may contest a decision.

C.

The location(s) where data is stored.

D.

The fact that an Al system is being used.

Question 48

What is the primary reason the EU is considering updates to its Product Liability Directive?

Options:

A.

To increase the minimum warranty level for defective goods.

B.

To define new liability exemptions for defective products.

C.

Address digital services and connected products.

D.

Address free and open-source software.

Question 49

CASE STUDY

Please use the following answer the next question:

Good Values Corporation (GVC) is a U.S. educational services provider that employs teachers to create and deliver enrichment courses for high school students. GVC has learned that many of its teacher employees are using generative Al to create the enrichment courses, and that many of the students are using generative Al to complete their assignments.

In particular, GVC has learned that the teachers they employ used open source large language models (“LLM”) to develop an online tool that customizes study questions for individual students. GVC has also discovered that an art teacher has expressly incorporated the use of generative Al into the curriculum to enable students to use prompts to create digital art.

GVC has started to investigate these practices and develop a process to monitor any use of generative Al, including by teachers and students, going forward.

All of the following may be copyright risks from teachers using generative Al to create course content EXCEPT?

Options:

A.

Content created by an LLM may be protectable under U.S. intellectual property law.

B.

Generative Al is generally trained using intellectual property owned by third parties.

C.

Students must expressly consent to this use of generative Al.

D.

Generative Al often creates content without attribution.

Demo: 49 questions
Total 165 questions