ISACA AAISM Exam Prep
ISACA Advanced in AI Security Management (Page 3 )

Updated On: 13-Sep-2026

An organization's CIO provided the AI steering committee with a list of AI technologies in use and tasked them with categorizing the technologies by risk.
Which of the following should the committee do FIRST?

  1. Begin grouping similar AI products and solutions together.
  2. Ensure the AI technologies are included in the asset inventory.
  3. Assess risk levels based on risk appetite and regulatory requirements.
  4. Identify vulnerabilities related to the technologies in use.

Answer(s): B

Explanation:

Before categorizing AI technologies by risk, the committee must first have a complete and accurate inventory of all AI assets. Without knowing exactly which technologies are in use, any risk assessment or categorization would be incomplete or unreliable. The inventory provides the foundation for subsequent grouping, vulnerability identification, and risk assessment.



A large pharmaceutical company using a new AI solution to develop treatment regimens is concerned about potential hallucinations with the introduction of real-world data.
Which of the following is MOST likely to reduce this risk?

  1. Penetration testing
  2. Data asset validation
  3. Human-in-the-loop
  4. AI impact analysis

Answer(s): C

Explanation:

Incorporating a human-in-the-loop allows experts to review, verify, and correct AI outputs, which is especially critical in high-stakes domains like pharmaceuticals. This approach mitigates the risk of hallucinations (incorrect or fabricated outputs) when the AI processes real-world data, ensuring decisions remain accurate and safe.



Which of the following should be the PRIMARY consideration for an organization concerned about liabilities associated with unforeseen behavior from agentic AI systems?

  1. Model dependencies
  2. Approved base models
  3. Acceptable risk level
  4. Accountability model

Answer(s): D

Explanation:

For agentic AI systems, the primary concern is who is responsible for actions the AI takes, especially if they lead to harm or legal issues. Establishing a clear accountability model ensures that liabilities are assigned, oversight is maintained, and proper governance is in place to manage unforeseen behavior.



During the creation of a new large language model (LLM), an organization procured training data from multiple sources.
Which of the following is MOST likely to address the CISO's security and privacy concerns?

  1. Data minimization
  2. Data augmentation
  3. Data classification
  4. Data discovery

Answer(s): C



An organization is reviewing an AI application to determine whether it is still needed. Engineers have been asked to analyze the number of incorrect predictions against the total number of predictions made.
Which of the following is this an example of?

  1. Model validation
  2. Control self-assessment (CSA)
  3. Explainable decision-making
  4. Key performance indicator (KPI)

Answer(s): D



Viewing page 3 of 76
Viewing questions 11 - 15 out of 371 questions


Post your Comments and Discuss ISACA AAISM exam prep with other Community members:

AI Tutor AI Tutor 👋 I’m here to help!