Summer Limited Time 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: wrap60

Isaca AAIA Dumps

Page: 1 / 9
Total 90 questions

ISACA Advanced in AI Audit (AAIA) Questions and Answers

Question 1

Which of the following is the PRIMARY objective of AI governance?

Options:

A.

Implementing compliance and ethics controls for AI initiatives

B.

Defining clear roles and responsibilities for AI development, use, and oversight

C.

Ensuring controls over AI are designed well and operate effectively

D.

Promoting a positive return on investment (ROI) from AI projects

Question 2

An organization is using information gathered from customer accounts to train its AI chatbot. Which of the following is the GREATEST risk associated with this practice?

Options:

A.

Disclosure of personal information

B.

AI bias

C.

Transparency

D.

AI model hallucinations

Question 3

Which of the following is the PRIMARY reason IS auditors must be aware that generative AI may return different investment recommendations from the same set of data?

Options:

A.

Limitations can arise in the quantification of risk profiles.

B.

Neural node access varies each time the process is executed.

C.

Computational logic is based on probabilities.

D.

Servers are reconfigured periodically.

Question 4

A healthcare organization uses an AI model to analyze patient data and provide diagnostic recommendations. Which of the following MOST effectively detects data drift related to the model's predictions?

Options:

A.

Comparing incoming patient data distributions with the training data set

B.

Applying overrides to allow healthcare professionals to correct the AI model’s recommendations

C.

Conducting periodic model retraining to ensure alignment with updated patient data

D.

Using adversarial testing to simulate scenarios that stress test the model’s predictions

Question 5

The PRIMARY objective of auditing AI systems is to:

Options:

A.

Identify biases and decision transparency.

B.

Maximize system efficiency and throughput.

C.

Optimize user experience and interface satisfaction.

D.

Minimize algorithm latency and information storage impacts.

Question 6

Which of the following is the BEST way to support the development and design of high-risk AI systems?

Options:

A.

Regularly back up the AI system's data to a secure, offsite location.

B.

Conduct regular training sessions for users on data privacy.

C.

Ensure the availability of trustworthy data sets.

D.

Implement multi-factor authentication (MFA) for all users accessing the AI system.

Question 7

An IS auditor is performing an inventory audit for a manufacturing organization. Which of the following would BEST enable the auditor to identify types of products without assistance from organizational staff?

Options:

A.

Natural language processing

B.

Speech modeling

C.

Robotic process automation (RPA)

D.

Computer vision

Question 8

An IS auditor is looking to expedite reporting for an audit with complex issues. Which of the following would be the MOST effective way for the auditor to use generative AI?

Options:

A.

Developing action items discussed in closing meetings for management action plans

B.

Developing a draft of an executive summary based on detailed findings and audit scope

C.

Revising audit conclusions with precise verbiage to describe the audit observations

D.

Revising audit background and scope information based on new information from management

Question 9

A retail organization uses an AI model to forecast inventory based on customer purchasing trends and updates the model quarterly. The model recently failed to recognize a surge in demand during a popular shopping season. Which of the following issues does this situation BEST demonstrate?

Options:

A.

Limited data set diversity impacting model training

B.

Data drift impacting system forecasting

C.

Overfitting issues due to a small training data set

D.

Lack of outlier checks in data affecting forecast accuracy

Question 10

When an IS auditor is reviewing results from an AI system, which of the following would cause the GREATEST risk?

Options:

A.

Inability to identify where an AI system is housed

B.

System output not being checked for inconsistencies

C.

Cascading failures of AI system outputs

D.

Difficulty of documenting AI algorithm processes

Question 11

The BEST way to prevent sensitive information disclosure by large language model (LLM) chatbots is through:

Options:

A.

Manual monitoring

B.

Access controls

C.

Data sanitization

D.

Data masking

Question 12

Which of the following is an IS auditor's MOST important course of action when determining whether source data should be entered into approved generative AI tools to assist with an audit?

Options:

A.

Validate that the tool is leveraging the latest model.

B.

Validate that the tool provides a privacy notice.

C.

Determine whether any AI model hallucinations have occurred.

D.

Determine whether the information is reliable.

Question 13

When auditing an AI system, which of the following steps ensures that AI model behavior is aligned with organizational objectives?

Options:

A.

Algorithm debugging

B.

Data transformation

C.

Model training

D.

Problem framing

Question 14

An organization uses an AI image generation platform to create promotional materials. An IS auditor identifies that the platform includes copyrighted images in its training data. Which of the following is the auditor's BEST recommendation to address this issue?

Options:

A.

Implement a manual review process to ensure no copyrighted images are used in generated outputs.

B.

Use a platform that certifies the provenance and licensing of its training data.

C.

Label all AI-generated images to disclaim the possibility of third-party content.

D.

Suspend the use of the platform until the training data is sanitized.

Question 15

An IS auditor reviewing documentation for an AI model notes that the modeler utilized a K-means clustering algorithm, which clusters data into categories for correlations and analysis. Which of the following is the MOST important risk for the auditor to consider?

Options:

A.

K-means clustering is not a common data clustering method due to its complexity and difficulty categorizing data correctly.

B.

K-means clustering requires the modeler to supervise the learning analysis, which can introduce bias.

C.

K-means clustering algorithms are significantly sensitive to outliers and dependent on the similarity of units of measure.

D.

K-means clustering determines the number of clusters for the modeler without supervision.

Question 16

A digital bank utilizes an AI system to generate credit scores. Which of the following would BEST mitigate the risk of sudden and unexplained changes in a borrower’s credit score?

Options:

A.

Ensuring the system is periodically reviewed and calibrated by human experts to maintain stability in predictions

B.

Using only data from the last six months to one year to avoid outdated information affecting the credit score

C.

Allowing the AI to operate fully autonomously to prevent processing delays

D.

Obtaining and validating the credit scores from third-party agencies to cross-check AI-generated results

Question 17

Which of the following AI system characteristics would BEST help an IS auditor evaluate the system's algorithm?

Options:

A.

The AI system algorithm uses training data to inform decision output.

B.

The AI system provides multiple options for model training.

C.

The AI system provides transparent justification of decisions.

D.

The AI system uses archived transaction data to provide decisions.

Question 18

Which of the following is MOST important to consider when deciding whether to implement an AI solution?

Options:

A.

The cost of AI implementation

B.

The speed of AI implementation

C.

The space required for AI hardware

D.

The ethical implications of AI

Question 19

In the context of an AI implementation, which of the following actions is MOST critical for an organization's change management program?

Options:

A.

Ensuring the organization has a dedicated AI governance committee

B.

Reviewing documentation for AI system changes, updates, and patches

C.

Conducting a comprehensive risk assessment specific to AI-related changes

D.

Verifying that all employees have completed mandatory AI ethics training

Question 20

A bank uses a video-based know your customer (KYC) verification process. Cybercriminals exploit this process by using deepfake technology to impersonate bank customers. Which of the following countermeasures is the BEST way for the bank to mitigate this risk?

Options:

A.

Requesting additional identity and address documents for verification

B.

Leveraging AI-based liveness detection during video verification

C.

Encrypting all customer data and communication

D.

Discontinuing the use of the video-based verification process

Question 21

An organization is evaluating change management practices for AI-based decision support models. Which of the following BEST demonstrates effective AI-focused change management?

Options:

A.

Engaging an independent expert to review the model's accuracy and precision on a quarterly basis

B.

Assigning a single data science team member to adjust the model in order to establish accountability

C.

Documenting model updates and retraining sessions to ensure traceability

D.

Deploying two separate copies of the model after each adjustment to compare results

Question 22

An organization is adopting AI for its procurement and inventory teams, raising concern from stakeholders that they will lose their jobs due to AI. Which of the following is the BEST way for the IS auditor to assess whether the potential negative impacts were minimized?

Options:

A.

Review human-centered design practices to determine how they were considered.

B.

Review the AI roadmap for short-term and long-term milestones.

C.

Review how the project management team collected feedback in engagement activities.

D.

Review the current state assessment of how AI may impact the organization.

Question 23

An organization's system development process has been enhanced with AI. Which of the following features presents the GREATEST risk?

Options:

A.

The AI allocates resources for new system development projects.

B.

Non-technical users are validating AI results.

C.

The AI personalizes applications for the user.

D.

All codes are generated by AI without human oversight.

Question 24

Which of the following is the MOST important task when gathering data during the AI system development process?

Options:

A.

Stratifying the data

B.

Isolating the system

C.

Cleaning the data

D.

Training the system

Question 25

Which of the following is the GREATEST risk associated with using AI in audit planning?

Options:

A.

Increased planning costs

B.

Scope creep

C.

Incomplete data

D.

Limited knowledge

Question 26

Which use case for an AI model to be used by a food delivery service would pose ethical risk to the organization?

Options:

A.

Correlating time, cost, delivery distance, and customer satisfaction metrics to issue coupons to customers receiving substandard service

B.

Basing driver retention and termination decisions on the number of delivered orders per total hours worked as compared to an industry benchmark

C.

Comparing total food preparation and delivery time to an industry benchmark to set key performance and risk indicators for individual restaurants

D.

Using customer service metrics for service speed and food quality to predict customer retention and forecast revenue

Question 27

An IS auditor is interviewing management about implemented controls around machine learning (ML) models deployed in the production environment. Which of the following schedules for reviewing the performance of a deployed model would be of GREATEST concern to the auditor?

Options:

A.

After changes to hardware and software platforms

B.

After functionality changes

C.

One time prior to migrating to production

D.

On an annual recurring basis

Page: 1 / 9
Total 90 questions