ISACA AAISM Exam Prep
ISACA Advanced in AI Security Management (Page 7 )

Updated On: 13-Sep-2026

A large language model (LLM) has been manipulated to provide advice that serves an attacker's objectives.
Which of the following attack types does this situation represent?

  1. Data poisoning
  2. Evasion attack
  3. Privilege escalation
  4. Model inversion

Answer(s): B



Which area of intellectual property law presents the GREATEST challenge in determining copyright protection for AI-generated content?

  1. Enforcing trademark rights associated with AI systems
  2. Protecting trade secrets in AI technologies
  3. Determining the rightful ownership of AI-generated creations
  4. Establishing licensing frameworks for AI-generated works

Answer(s): C

Explanation:

Copyright law traditionally protects works created by human authors. AI-generated content challenges this principle because it is unclear who - if anyone - can be considered the legal author. Determining ownership is therefore the most significant intellectual property issue for AI-generated works.



A financial institution plans to deploy an AI system to provide credit risk assessments for loan applications.
Which of the following should be given the HIGHEST priority in the system's design to ensure ethical decision making and prevent bias?

  1. Regularly update the model with new customer data to improve prediction accuracy.
  2. Restrict the model's decision-making criteria to objective financial metrics only.
  3. Train the system to provide advisory results with final decisions made by human experts.
  4. Integrate a mechanism for customers to appeal decisions directly within the system.

Answer(s): C

Explanation:

Ensuring that humans retain ultimate decision-making authority mitigates ethical and bias-related risks in AI-driven credit assessments. This human-in-the-loop approach allows expert review of AI recommendations, ensuring fairness, accountability, and compliance with regulatory and ethical standards.



Which of the following security framework elements BEST helps to safeguard the integrity of outputs generated by AI algorithms?

  1. Management is prepared to disclose AI system architecture to stakeholders.
  2. Ethical standards are incorporated into security awareness programs.
  3. Risk exposure due to bias in AI outputs is kept within an acceptable range.
  4. Responsibility is defined for legal actions related to AI regulatory requirements.

Answer(s): C

Explanation:

Maintaining AI output integrity involves monitoring and controlling risks such as bias, errors, or manipulation. Keeping risk exposure within an acceptable range ensures that AI-generated results are reliable, trustworthy, and aligned with organizational and regulatory standards.



Which of the following is the BEST mitigation control for membership inference attacks on AI systems?

  1. AI threat modeling
  2. Differential privacy
  3. Cybersecurity-oriented red teaming
  4. Model ensemble techniques

Answer(s): B

Explanation:

Differential privacy adds controlled noise to data or model outputs, preventing attackers from inferring whether specific individuals’ data were included in the training set. This is the most effective mitigation against membership inference attacks, protecting sensitive information while maintaining overall model utility.



Viewing page 7 of 76
Viewing questions 31 - 35 out of 371 questions


Post your Comments and Discuss ISACA AAISM exam prep with other Community members:

AI Tutor AI Tutor 👋 I’m here to help!