Summer Special Flat 65% Limited Time Discount offer - Ends in 0d 00h 00m 00s - Coupon code: suredis

Isaca AAIA ISACA Advanced in AI Audit (AAIA) Exam Practice Test

Demo: 27 questions
Total 90 questions

ISACA Advanced in AI Audit (AAIA) Questions and Answers

Question 1

Which of the following is the PRIMARY objective of AI governance?

Options:

A.

Implementing compliance and ethics controls for AI initiatives

B.

Defining clear roles and responsibilities for AI development, use, and oversight

C.

Ensuring controls over AI are designed well and operate effectively

D.

Promoting a positive return on investment (ROI) from AI projects

Question 2

An IS auditor notes that an AI model achieved significantly better results on training data than on test data. Which of the following problems with the model has the IS auditor identified?

Options:

A.

Underfitting

B.

Overfitting

C.

Generalization

D.

Bias

Question 3

Which of the following controls MOST effectively helps to ensure an AI model is resilient against external threats?

Options:

A.

AI data set anonymization

B.

Monitoring of AI model developers

C.

Monitoring of AI access logs

D.

AI model configuration testing

Question 4

Which of the following is the MOST important task when gathering data during the AI system development process?

Options:

A.

Stratifying the data

B.

Isolating the system

C.

Cleaning the data

D.

Training the system

Question 5

An organization uses an AI image generation platform to create promotional materials. An IS auditor identifies that the platform includes copyrighted images in its training data. Which of the following is the auditor's BEST recommendation to address this issue?

Options:

A.

Implement a manual review process to ensure no copyrighted images are used in generated outputs.

B.

Use a platform that certifies the provenance and licensing of its training data.

C.

Label all AI-generated images to disclaim the possibility of third-party content.

D.

Suspend the use of the platform until the training data is sanitized.

Question 6

To confirm the fairness of AI model decisions, the BEST way to collect reliable evidence during an AI audit is by:

Options:

A.

Analyzing system metadata.

B.

Testing the model with a curated sample data set.

C.

Interviewing developers.

D.

Observing the system’s interactions with end users.

Question 7

Which of the following is the MOST important course of action for an organization prior to allowing end users to utilize an AI tool?

Options:

A.

Develop an AI policy with guidelines on appropriate use.

B.

Determine the impact to the disaster recovery plan (DRP).

C.

Implement baseline performance metrics.

D.

Ensure a cybersecurity insurance clause is in place to include the use of AI.

Question 8

An IS auditor notes the combined number of records utilized within the training, validation, and testing data sets exceeds the total number of records in the original data set. Which of the following is MOST important for the auditor to determine?

Options:

A.

Whether the training, validation, and testing data sets were created in the correct order

B.

Whether data leakage occurred from utilizing overlapping records in the data sets

C.

Whether a sufficient number of records were utilized in the training data set

D.

Whether the validation data set utilized the same number of records as the training data sets

Question 9

Which of the following is MOST important to have in place when initially populating data into a data frame for an AI model?

Options:

A.

The box charts, histograms, scatterplots, and Venn diagrams that identify correlations and outliers

B.

The code for separating data into training and testing data sets

C.

An analysis of exploratory data that checks for incorrect data types, null values, and duplicate entries

D.

An approved risk assessment for including, excluding, or subsequently dropping data attributes from the model

Question 10

In order to streamline operations, a bank has deployed an AI application to automatically detect and prevent further fraud on accounts. However, customers have voiced concerns that their usual transactions are being rejected. Which of the following is the MOST likely cause of the false positives?

Options:

A.

Consent is not properly managed.

B.

Data versioning controls were not developed.

C.

Compute scale training was not performed.

D.

The hyperparameters are not optimized.

Question 11

An organization shares an AI model with external partners. One partner reports that sensitive data has been inadvertently exposed through the model’s outputs. Which of the following is the IS auditor's BEST recommendation?

Options:

A.

Limit the model's outputs to anonymized results while investigating further.

B.

Audit the data pipelines of all partners to identify the source of the leak.

C.

Disable the shared model and notify partners of the potential breach.

D.

Retrain the model immediately and implement privacy-preserving techniques.

Question 12

The PRIMARY objective of auditing AI systems is to:

Options:

A.

Identify biases and decision transparency.

B.

Maximize system efficiency and throughput.

C.

Optimize user experience and interface satisfaction.

D.

Minimize algorithm latency and information storage impacts.

Question 13

The GREATEST benefit of using AI auditing techniques over traditional methods is that AI auditing techniques can:

Options:

A.

eliminate the need for human intervention.

B.

ensure full compliance with regulations.

C.

identify complex data patterns.

D.

significantly reduce data bias.

Question 14

Which of the following is the PRIMARY purpose of an AI acceptable use policy?

Options:

A.

Establishing guidance on the ethical use of AI

B.

Outlining AI usage monitoring procedures

C.

Educating employees on where to find and how to use AI tools

D.

Explaining the distinction between different types of AI

Question 15

Which of the following key performance indicators (KPIs) are MOST important when evaluating whether an AI model meets business objectives?

Options:

A.

Cost of resources required for AI model training

B.

Number of users interacting with the AI model

C.

Frequency of AI model retraining

D.

AI model accuracy in predicting actual outcomes

Question 16

When utilizing a machine learning (ML) model to predict whether a wind turbine electricity generator will fail, which model evaluation metric should be the PRIMARY focus?

Options:

A.

Precision

B.

Specificity

C.

Accuracy

D.

Recall

Question 17

A digital bank utilizes an AI system to generate credit scores. Which of the following would BEST mitigate the risk of sudden and unexplained changes in a borrower’s credit score?

Options:

A.

Ensuring the system is periodically reviewed and calibrated by human experts to maintain stability in predictions

B.

Using only data from the last six months to one year to avoid outdated information affecting the credit score

C.

Allowing the AI to operate fully autonomously to prevent processing delays

D.

Obtaining and validating the credit scores from third-party agencies to cross-check AI-generated results

Question 18

Which of the following controls helps mitigate the risk of competitors poisoning data utilized by a machine learning (ML) model performing sentiment analysis of product reviews?

Options:

A.

Peer reviewing code that acquires product reviews from social media posts

B.

Hiring a marketing firm to text links to customers requesting product reviews for monetary compensation

C.

Augmenting the unbalanced product review data set with the use of oversampling by the model developer

D.

Requiring customers to authenticate access to their accounts prior to writing product reviews

Question 19

During a pre-implementation risk assessment, an AI model is determined to present a significant risk of bias and potential harm in excess of the organization’s risk tolerance. Which of the following is the MOST appropriate response?

Options:

A.

Postpone deployment until the risk can be safely managed.

B.

Enhance the data that the model is trained on.

C.

Obtain board approval for an exception.

D.

Revisit the risk tolerance to ensure it is appropriate.

Question 20

Which use case for an AI model to be used by a food delivery service would pose ethical risk to the organization?

Options:

A.

Correlating time, cost, delivery distance, and customer satisfaction metrics to issue coupons to customers receiving substandard service

B.

Basing driver retention and termination decisions on the number of delivered orders per total hours worked as compared to an industry benchmark

C.

Comparing total food preparation and delivery time to an industry benchmark to set key performance and risk indicators for individual restaurants

D.

Using customer service metrics for service speed and food quality to predict customer retention and forecast revenue

Question 21

An organization is using information gathered from customer accounts to train its AI chatbot. Which of the following is the GREATEST risk associated with this practice?

Options:

A.

Disclosure of personal information

B.

AI bias

C.

Transparency

D.

AI model hallucinations

Question 22

An organization is evaluating change management practices for AI-based decision support models. Which of the following BEST demonstrates effective AI-focused change management?

Options:

A.

Engaging an independent expert to review the model's accuracy and precision on a quarterly basis

B.

Assigning a single data science team member to adjust the model in order to establish accountability

C.

Documenting model updates and retraining sessions to ensure traceability

D.

Deploying two separate copies of the model after each adjustment to compare results

Question 23

An IS auditor is looking to expedite reporting for an audit with complex issues. Which of the following would be the MOST effective way for the auditor to use generative AI?

Options:

A.

Developing action items discussed in closing meetings for management action plans

B.

Developing a draft of an executive summary based on detailed findings and audit scope

C.

Revising audit conclusions with precise verbiage to describe the audit observations

D.

Revising audit background and scope information based on new information from management

Question 24

Which of the following BEST detects model drift or unexpected changes in AI model outputs?

Options:

A.

Standardization of AI configurations

B.

Anomaly monitoring

C.

AI model documentation reviews

D.

AI model retraining

Question 25

An organization uses an AI-powered tool to detect and respond to cybersecurity threats in real time. An IS auditor finds that the tool produces excessive false positives, increasing the workload of the security team. Which of the following techniques should the auditor recommend to BEST evaluate the tool's effectiveness in managing this issue?

Options:

A.

Use a log analysis tool to examine the types and frequency of alerts generated.

B.

Implement a benchmarking tool to compare the system's alerting capability with industry standards.

C.

Conduct penetration testing to assess the system's ability to detect genuine threats.

D.

Deploy a machine learning (ML) validation tool to increase the model's accuracy and performance.

Question 26

An IS auditor is auditing a financial system in which a generative AI tool is used to identify trends in batches of 4,000 rows, while the generative AI tool has a limit of 3,000 tokens. Which of the following is the GREATEST concern?

Options:

A.

The AI will process only a portion of the data set.

B.

The AI will prioritize high-value entries.

C.

The AI will reject the data set and not analyze the data.

D.

The AI output will be biased toward the first 3,000 tokens.

Question 27

Which of the following is the MOST important purpose of conducting a risk assessment for AI models within an organization?

Options:

A.

Categorizing data used by the AI model

B.

Defining mitigation strategies for AI deployment

C.

Monitoring AI model performance on an ongoing basis

D.

Determining whether AI model outputs align with established use cases

Demo: 27 questions
Total 90 questions