ISACA AAISM Exam Prep
ISACA Advanced in AI Security Management (Page 2 )

Updated On: 13-Sep-2026

An AI research team is developing a natural language processing model that relies on several open-source libraries.
Which of the following is the team's BEST course of action to ensure the integrity of the software packages used?

  1. Maintain a list of frequently used libraries to ensure consistent application in projects.
  2. Retrain the model regularly to handle package and library updates.
  3. Scan the packages and libraries for malware prior to installation.
  4. Use the latest version of all libraries from public repositories.

Answer(s): C

Explanation:

Scanning open-source packages and libraries for malware before installation ensures software integrity and prevents the introduction of malicious code into the AI system. This step verifies that dependencies are safe and have not been tampered with, which is critical for maintaining trust and security in the development environment.



An organization plans to apply an AI system to its business, but developers find it difficult to predict system results due to lack of visibility to the inner workings of the AI model.
Which of the following is the GREATEST challenge associated with this situation?

  1. Assigning a risk owner who is responsible for system uptime and performance
  2. Continuing operations to meet expected AI security requirements
  3. Determining average turnaround time for AI transaction completion
  4. Gaining the trust of end users through explainability and transparency

Answer(s): D

Explanation:

The inability to understand or explain how an AI model produces its results represents a lack of explainability and transparency. This is a major trust issue, as users and stakeholders need to comprehend the model’s reasoning to validate its reliability, fairness, and compliance with governance requirements.



Which of the following is MOST important to consider when validating a third-party AI tool?

  1. Terms and conditions
  2. Roundtable testing
  3. Right to audit
  4. Industry analysis and certifications

Answer(s): C

Explanation:

When validating a third-party AI tool, the right to audit is most important because it allows the organization to independently verify the vendor’s compliance with security, privacy, and ethical standards. This ensures transparency in how data is handled and models are managed, reducing risks related to hidden vulnerabilities or misuse.



After implementing a third-party generative AI tool, an organization learns about new regulations related to how organizations use AI.
Which of the following would be the BEST justification for the organization to decide not to comply?

  1. The AI tool is widely used within the industry.
  2. The AI tool is regularly audited.
  3. The risk is within the organization's risk appetite.
  4. The cost of noncompliance was not determined.

Answer(s): C

Explanation:

An organization may justify limited or delayed compliance if the associated risk of noncompliance is assessed to be within its defined risk appetite. This reflects a formal risk management decision, balancing potential regulatory consequences against operational or strategic priorities. Compliance decisions should be risk-informed rather than based solely on popularity, audits, or undefined costs.



Which of the following is the MOST important consideration when deciding how to compose an AI red team?

  1. Resource availability
  2. Time-to-market constraints
  3. Skills matrix
  4. AI use cases

Answer(s): C

Explanation:

The red team must have the right mix of technical and domain skills (ML, security testing, data/privacy, adversarial techniques, and relevant governance knowledge) so it can effectively identify and exploit weaknesses in the AI system; composing the team by capability ensures thorough, targeted evaluation.



Viewing page 2 of 76
Viewing questions 6 - 10 out of 371 questions


Post your Comments and Discuss ISACA AAISM exam prep with other Community members:

AI Tutor AI Tutor 👋 I’m here to help!