ISACA AAISM Exam Prep
ISACA Advanced in AI Security Management (Page 10 )

Updated On: 13-Sep-2026

An organization recently introduced a generative AI chatbot that can interact with users and answer their queries.
Which of the following would BEST mitigate hallucination risk identified by the risk team?

  1. Performing model testing and validation
  2. Ensuring model developers have been trained in AI risk
  3. Fine-tuning the foundational model
  4. Training the foundational model on large data sets

Answer(s): C



An organization plans to implement a new AI system.
Which of the following is the MOST important factor in determining the level of risk monitoring activities required?

  1. The organization's risk appetite
  2. The organization's risk tolerance
  3. The organization's number of AI system users
  4. The organization's compensating controls

Answer(s): B

Explanation:

Risk tolerance defines the acceptable level of variation from expected outcomes that the organization is willing to endure. Determining this threshold guides the intensity and frequency of risk monitoring for AI systems, ensuring that controls are proportionate to potential impact and aligned with organizational objectives.



Which of the following employee awareness topics would MOST likely be revised to account for AI-enabled cyber risk?

  1. Malicious insider threats
  2. Clean desk policy
  3. Authentication controls
  4. Social engineering

Answer(s): D

Explanation:

AI-enabled cyber risks, such as deepfake emails or AI-generated phishing messages, enhance the sophistication of social engineering attacks. Revising employee awareness programs to address these AI-driven threats helps staff recognize and respond effectively, reducing the likelihood of successful attacks.



Which of the following BEST ensures the integrity of data sets used to train AI models?

  1. Collection and retention of only necessary data sets
  2. Tracking and verification of data sets via cryptographic controls
  3. Clear documentation of data sources, types used, and processing steps
  4. Appropriate storage of data sets according to documented classification processes

Answer(s): B

Explanation:

Using cryptographic techniques, such as hashing or digital signatures, ensures that training datasets are not tampered with or altered. This preserves the integrity of the data, which is critical for reliable AI model performance and trustworthy outputs.



An organization decides to contract a vendor to implement a new set of AI libraries.
Which of the following is MOST important to address in the master service agreement to protect data used during the AI training process?

  1. Data pseudonymization
  2. Right to audit
  3. Independent certification
  4. Continuous data monitoring

Answer(s): B

Explanation:

Including a right to audit in the master service agreement allows the organization to verify that the vendor properly handles, secures, and uses data during AI training. This ensures compliance with contractual, regulatory, and privacy requirements, reducing risk associated with third-party data management.



Viewing page 10 of 76
Viewing questions 46 - 50 out of 371 questions


Post your Comments and Discuss ISACA AAISM exam prep with other Community members:

AI Tutor AI Tutor 👋 I’m here to help!