ISACA AAISM Exam Prep
ISACA Advanced in AI Security Management (Page 8 )

Updated On: 13-Sep-2026

From a risk perspective, which of the following is the MOST important step when implementing an adoption strategy for AI systems?

  1. Establishing a comprehensive AI risk assessment framework
  2. Implementing a robust risk analysis methodology tailored to AI-specific tasks
  3. Conducting an AI risk assessment and updating the enterprise risk register
  4. Benchmarking against peer organizations' AI risk strategies

Answer(s): C

Explanation:

From a risk perspective, the critical step is to formally assess AI-specific risks and document them in the enterprise risk register. This ensures that AI risks are identified, quantified, monitored, and managed alongside other organizational risks, providing a foundation for informed adoption decisions and governance.



Which of the following is MOST important to monitor in order to ensure the effectiveness of an organization's AI vendor management program?

  1. Vendor results in compliance training programs
  2. Vendor participation in industry AI research
  3. Vendor reviews of external AI threat reports
  4. Vendor compliance with AI-related requirements

Answer(s): D

Explanation:

The primary goal of AI vendor management is to ensure that third-party providers adhere to contractual, regulatory, and ethical standards. Monitoring vendor compliance with AI-related requirements directly confirms that vendors meet security, privacy, and governance obligations, reducing organizational risk.



After deployment, an AI model's output begins to drift outside of the expected range.
Which of the following is the development team's BEST course of action?

  1. Return to an earlier phase in the AI life cycle.
  2. Take the AI model offline.
  3. Adjust the hyperparameters of the AI model.
  4. Create an emergency change request to correct the issue.

Answer(s): A



The PRIMARY ethical concern of generative AI is that it may:

  1. cause information integrity issues.
  2. cause information to become unavailable.
  3. breach the confidentiality of information.
  4. produce unexpected data that could lead to bias.

Answer(s): A

Explanation:

Generative AI can produce outputs that are plausible but incorrect or misleading, compromising the accuracy and trustworthiness of information. This integrity issue is a primary ethical concern, as it can affect decision-making, reputation, and compliance.



To ensure AI tools do not jeopardize ethical principles, it is MOST important to validate that:

  1. stakeholders have approved alignment with company values.
  2. AI tools are evaluated by the privacy department before implementation.
  3. outputs of AI tools do not perpetuate adverse biases.
  4. the organization has implemented a responsible development policy.

Answer(s): C

Explanation:

The core ethical concern in AI is preventing harm caused by biased or unfair outputs. Validating that AI tools do not perpetuate adverse biases ensures fairness, equity, and responsible decision-making, directly addressing ethical risks in AI deployment.



Viewing page 8 of 76
Viewing questions 36 - 40 out of 371 questions


Post your Comments and Discuss ISACA AAISM exam prep with other Community members:

AI Tutor AI Tutor 👋 I’m here to help!