ISACA AAIA Exam Prep
ISACA Advanced in AI Audit (Page 20 )

Updated On: 10-Sep-2026

Which of the following insider threats involving the use of AI would present the GREATEST risk?

  1. Leaking of system hyperparameters
  2. Launching social engineering attacks
  3. Destroying system backups
  4. Exfiltrating sensitive data

Answer(s): D

Explanation:

Exfiltrating sensitive data presents the greatest risk because it results in direct loss of confidentiality, potential regulatory violations, and severe organizational harm. AI tools can amplify this threat by enabling large-scale or automated extraction of sensitive information.



Which of the following is the BEST recommendation to mitigate excessive agency when implementing an AI system as a browser extension?

  1. Minimize browser extension functionality.
  2. Remove user access to browser extensions.
  3. Maximize browser extension functionality.
  4. Use open source browser extensions.

Answer(s): A

Explanation:

Minimizing browser extension functionality reduces the system’s autonomous actions and limits unintended behaviors, thereby mitigating excessive agency and ensuring the AI operates within controlled and intended boundaries.



An organization is reviewing its existing data governance framework after implementing an AI-based document repository solution.
Which of the following should be the PRIMARY consideration for the organization?

  1. Data retention policy
  2. Data classification
  3. Data enrichment
  4. Qualitative data collection

Answer(s): B

Explanation:

Data classification is the primary consideration because AI-based document repositories rely heavily on properly categorized data to ensure appropriate access, handling, protection, and compliance throughout the AI life cycle.



An IS auditor is reviewing change documentation of an AI model.
Which of the following would pose the GREATEST risk?

  1. Management has not tested the model.
  2. Test results are not in a standardized format.
  3. There is a low number of test scenarios.
  4. The seed used for testing is not documented.

Answer(s): C

Explanation:

A low number of test scenarios poses the greatest risk because insufficient testing fails to validate model behavior across normal, edge, and high-risk conditions. This increases the likelihood that significant errors, bias, or failures will go undetected before deployment.



What is the MOST important reason government organizations should provide regular AI training programs for all staff?

  1. To minimize the cost of AI deployment
  2. To ensure staff are up to date on ethical considerations
  3. To allow staff to understand the tools available
  4. To reduce learning using outdated information

Answer(s): B

Explanation:

Regular AI training ensures staff remain current on ethical considerations, promoting responsible and compliant use of AI systems within government organizations where ethical and legal standards are critical.



Viewing page 20 of 113
Viewing questions 96 - 100 out of 536 questions


Post your Comments and Discuss ISACA AAIA exam prep with other Community members:

AI Tutor AI Tutor 👋 I’m here to help!