ISACA AAISM Exam Prep
ISACA Advanced in AI Security Management (Page 9 )

Updated On: 13-Sep-2026

Which of the following is the MOST effective use of AI-enabled tools in a security operations center (SOC)?

  1. Employing AI-enabled tools to reduce false negatives by detecting subtle attack patterns
  2. Replacing human analysis with automated AI decision-making processes
  3. Assigning AI-enabled tools to triage non-critical alerts to preserve SOC resources
  4. Using AI-enabled tools exclusively to classify all types of security incidents

Answer(s): A

Explanation:

AI is most effective in the SOC when it enhances threat detection, particularly for subtle or complex patterns that humans might miss. Reducing false negatives improves overall security posture by ensuring that potential attacks are identified and addressed promptly without replacing human judgment.



When implementing a generative AI system, which of the following approaches will BEST prevent misalignment between the corporate risk appetite and tolerance?

  1. Creating and maintaining an AI risk register
  2. Establishing and monitoring acceptable levels of AI system risk
  3. Performing an AI impact assessment
  4. Ensuring effective AI key performance indicators (KPIs)

Answer(s): B

Explanation:

Defining and continuously monitoring acceptable risk levels ensures that the AI system operates within the organization’s risk appetite and tolerance. This alignment allows decision-makers to manage potential harms proactively, maintaining consistency with strategic and ethical objectives.



Which of the following controls BEST mitigates the inherent limitations of generative AI models?

  1. Adopting AI-specific regulations
  2. Classifying and labeling AI systems
  3. Ensuring human oversight
  4. Reverse engineering the models

Answer(s): C

Explanation:

Generative AI models can produce incorrect, biased, or unsafe outputs due to inherent limitations. Human oversight allows experts to review, validate, and correct outputs, mitigating risks and ensuring that the AI’s use aligns with organizational, ethical, and regulatory standards.



Which of the following recommendations would BEST help a service provider mitigate the risk of lawsuits arising from generative AI's access to and use of internet data?

  1. Review log information that records how data was collected.
  2. Disclose service provider policies to declare compliance with regulations.
  3. Activate filtering logic to exclude intellectual property flags.
  4. Appoint a data steward specialized in AI to strengthen security governance.

Answer(s): B

Explanation:

Transparently communicating policies regarding data collection and usage demonstrates regulatory compliance and sets clear boundaries for how generative AI accesses and uses internet data. This reduces legal exposure by informing users and stakeholders of adherence to intellectual property and data protection laws.



Which of the following types of testing can MOST effectively mitigate prompt hacking?

  1. Adversarial
  2. Input
  3. Load
  4. Regression

Answer(s): A

Explanation:

Adversarial testing involves deliberately crafting inputs designed to exploit weaknesses in AI models, such as prompt injection or manipulation. This approach identifies vulnerabilities that could be exploited in prompt hacking, allowing developers to implement safeguards and improve model robustness.



Viewing page 9 of 76
Viewing questions 41 - 45 out of 371 questions


Post your Comments and Discuss ISACA AAISM exam prep with other Community members:

AI Tutor AI Tutor 👋 I’m here to help!