ISACA AAISM Exam Prep
ISACA Advanced in AI Security Management (Page 6 )

Updated On: 13-Sep-2026

Which of the following should be done FIRST when developing an acceptable use policy for generative AI?

  1. Consult with risk management and legal.
  2. Review AI regulatory requirements.
  3. Determine the scope and intended use of AI.
  4. Review existing company policies.

Answer(s): C

Explanation:

Before creating an acceptable use policy, the organization must clearly define what the AI will be used for and in which contexts. Establishing the scope and intended use provides a foundation for aligning the policy with regulatory requirements, legal considerations, and internal governance standards.



An organization needs large data sets to perform application testing.
Which of the following would BEST fulfill this need?

  1. Using open-source data repositories
  2. Reviewing AI model cards
  3. Performing AI data augmentation
  4. Incorporating data from search content

Answer(s): C

Explanation:

AI data augmentation generates additional training or testing data by creating modified versions of existing datasets (e.g., through transformations, synthesis, or simulation). This approach expands dataset size while maintaining relevance and variability, supporting effective application testing without relying solely on external sources.



In the context of generative AI, which of the following would be the MOST likely goal of penetration testing during a red-teaming exercise?

  1. Generate outputs that are unexpected using adversarial inputs.
  2. Stress test the model's decision-making process.
  3. Degrade the model's performance for existing use cases.
  4. Replace the model's outputs with entirely random content.

Answer(s): A

Explanation:

Penetration testing in red-teaming aims to uncover vulnerabilities by crafting adversarial inputs that cause the model to produce unexpected, unsafe, or incorrect outputs - validating robustness and revealing exploitable failure modes.



Which of the following is MOST important for an organization to consider when implementing a preventive security safeguard into a new AI product?

  1. Penetration testing
  2. Input sanitization
  3. Model output monitoring
  4. Differential privacy

Answer(s): B

Explanation:

Input sanitization ensures that any data fed into the AI system is clean, well-formed, and free from malicious content. As a preventive security safeguard, it reduces the risk of attacks (e.g., injection, poisoning, or adversarial inputs) before they can compromise the AI model’s behavior or integrity.



As organizations increasingly rely on vendors to develop AI systems, which of the following is the MOST effective way to monitor vendors and ensure compliance with ethical and security standards?

  1. Mandating that vendors share source code and AI documentation with the contracting party
  2. Requiring vendors to monitor their adherence to ethics and security standards
  3. Conducting regular audits of vendor processes and adherence to AI development guidelines
  4. Allowing vendors to self-attest ethical AI compliance and implement benchmark monitoring

Answer(s): C

Explanation:

Regular audits provide an independent, systematic way to verify that vendors comply with ethical, security, and regulatory standards throughout the AI development lifecycle. This approach ensures accountability and identifies gaps or risks that self-attestation or internal monitoring alone might miss.



Viewing page 6 of 76
Viewing questions 26 - 30 out of 371 questions


Post your Comments and Discuss ISACA AAISM exam prep with other Community members:

AI Tutor AI Tutor 👋 I’m here to help!