ISACA AAISM Exam Prep
ISACA Advanced in AI Security Management (Page 14 )

Updated On: 13-Sep-2026

Which of the following controls BEST mitigates the risk of data poisoning?

  1. Data validation
  2. Intrusion detection
  3. Digital watermarking
  4. Data set restoration

Answer(s): A

Explanation:

Data validation ensures that incoming training data is accurate, complete, and consistent with expected patterns. By verifying and filtering data before it is used for model training, organizations can prevent malicious or corrupted inputs that could compromise model integrity, effectively mitigating data poisoning risks.



An organization utilizes AI-enabled mapping software to plan routes for delivery drivers. A driver following the AI route drives the wrong way down a one-way street, despite numerous signs.
Which of the following biases does this scenario demonstrate?

  1. Selection
  2. Reporting
  3. Confirmation
  4. Automation

Answer(s): D

Explanation:

This scenario illustrates automation bias, where individuals over-rely on AI recommendations, trusting the system even when it contradicts observable real-world cues (e.g., traffic signs). Overdependence on AI can lead to errors when humans fail to critically assess automated guidance.



An automotive manufacturer uses AI-enabled sensors on machinery to monitor variables such as vibration, temperature, and pressure.
Which of the following BEST demonstrates how this approach contributes to operational resilience?

  1. Scheduling repairs for critical equipment based on real-time condition monitoring
  2. Conducting monthly manual reviews of maintenance schedules
  3. Performing regular maintenance based on manufacturer recommendations
  4. Automating equipment repairs without any human intervention

Answer(s): A

Explanation:

Using AI-enabled sensors for continuous monitoring allows the organization to perform predictive maintenance, addressing potential issues before failures occur. This proactive approach enhances operational resilience by reducing downtime, preventing costly breakdowns, and ensuring continuity of manufacturing processes.



When an attacker uses synthetic data to reverse engineer an organization's AI model, it is an example of which of the following types of attack?

  1. Prompt
  2. Poisoning
  3. Distillation
  4. Inversion

Answer(s): C

Explanation:

Model distillation attacks involve using synthetic or carefully crafted data to query an AI model repeatedly and reconstruct its underlying parameters or behavior. This allows attackers to approximate the original model without direct access, effectively reverse engineering it.



An organization develops and implements an AI-based plug-in for users that summarizes their individual emails.
Which of the following is the GREATEST risk associated with this application?

  1. Insufficient rate limiting for APIs
  2. Data format incompatibility
  3. Lack of application vulnerability scanning
  4. Inadequate controls over parameters

Answer(s): D

Explanation:

An AI-based email summarization plug-in processes sensitive personal and business information. If parameters controlling data access, processing scope, or output are insufficiently restricted, the application could expose confidential content, mishandle sensitive information, or generate inaccurate summaries, posing the greatest risk.



Viewing page 14 of 76
Viewing questions 66 - 70 out of 371 questions


Post your Comments and Discuss ISACA AAISM exam prep with other Community members:

AI Tutor AI Tutor 👋 I’m here to help!