ISACA AAISM Exam Prep
ISACA Advanced in AI Security Management (Page 29 )

Updated On: 13-Sep-2026

Which of the following is the GREATEST benefit of implementing an AI tool to safeguard sensitive data and prevent unauthorized access?

  1. Timely initiation of incident response
  2. Reduced number of false positives
  3. Timely analysis of endpoint activities
  4. Reduced need for data classification

Answer(s): A

Explanation:

AI tools that monitor sensitive data and access patterns can quickly detect anomalies or potential breaches. Early detection enables prompt initiation of incident response, minimizing the impact of unauthorized access and improving overall data security posture.



Which of the following would BEST help mitigate vulnerabilities associated with hidden triggers in generative AI
models?

  1. Monitoring model outputs and suspicious patterns to detect trigger activations
  2. Regularly retraining the model using a diverse data set
  3. Applying differential privacy and masking sensitive patterns in the training data
  4. Incorporating adversarial training to expose and neutralize potential triggers

Answer(s): D

Explanation:

Adversarial training involves deliberately introducing challenging or malicious inputs during model development to identify hidden triggers. By exposing these vulnerabilities, the AI model can be adjusted or fortified, reducing the risk of malicious activation of undesired behaviors.



Which of the following is the MOST important course of action prior to placing an in-house developed AI solution into production?

  1. Deploy a prototype of the solution.
  2. Perform a privacy, security, and compliance gap analysis.
  3. Obtain senior management sign-off.
  4. Perform testing, evaluation, validation, and verification.

Answer(s): D

Explanation:

Before deploying an AI solution into production, it is critical to thoroughly test and validate its performance, accuracy, and reliability. Verification ensures the system meets design specifications, while validation confirms it fulfills intended use cases. This step mitigates operational, ethical, and regulatory risks.



Which of the following is a key risk indicator (KRI) for an AI system used for threat detection?

  1. Number of training epochs
  2. Number of layers in the neural network
  3. Training time of the model
  4. Number of system overrides by cyber analysts

Answer(s): D

Explanation:

Frequent overrides indicate that the AI system’s threat detection outputs are often incorrect or require human correction. Monitoring this KRI helps assess the system’s reliability, effectiveness, and risk exposure, guiding improvements and governance decisions.



The PRIMARY benefit of implementing moderation controls in generative AI applications is that it can:

  1. filter out harmful or inappropriate content.
  2. increase the model's ability to generate diverse and creative content.
  3. ensure the generated content adheres to privacy regulations.
  4. optimize the model's response time.

Answer(s): A

Explanation:

Moderation controls act as a safeguard to detect and block outputs that are offensive, unsafe, or otherwise inappropriate. This reduces ethical, legal, and reputational risks associated with generative AI applications while maintaining user trust.



Viewing page 29 of 76
Viewing questions 141 - 145 out of 371 questions


Post your Comments and Discuss ISACA AAISM exam prep with other Community members:

AI Tutor AI Tutor 👋 I’m here to help!