Pre-Summer Sale Discount Flat 70% Offer - Ends in 0d 00h 00m 00s - Coupon code: 70diswrap

Isaca AAIA Dumps

Page: 1 / 27
Total 273 questions

ISACA Advanced in AI Audit (AAIA) Questions and Answers

Question 1

An organization uses an AI-powered tool to detect and respond to cybersecurity threats in real time. An IS auditor finds that the tool produces excessive false positives, increasing the workload of the security team. Which of the following techniques should the auditor recommend to BEST evaluate the tool ' s effectiveness in managing this issue?

Options:

A.

Use a log analysis tool to examine the types and frequency of alerts generated.

B.

Implement a benchmarking tool to compare the system ' s alerting capability with industry standards.

C.

Conduct penetration testing to assess the system ' s ability to detect genuine threats.

D.

Deploy a machine learning (ML) validation tool to increase the model ' s accuracy and performance.

Question 2

Which of the following is the MOST important reason to conduct regular threat modeling exercises for AI systems and data?

Options:

A.

To proactively identify potential vulnerabilities in AI systems

B.

To assess the performance of AI algorithms

C.

To comply with AI regulatory requirements

D.

To prevent instances of AI model drift

Question 3

An organization is evaluating change management practices for AI-based decision support models. Which of the following BEST demonstrates effective AI-focused change management?

Options:

A.

Engaging an independent expert to review the model ' s accuracy and precision on a quarterly basis

B.

Assigning a single data science team member to adjust the model in order to establish accountability

C.

Documenting model updates and retraining sessions to ensure traceability

D.

Deploying two separate copies of the model after each adjustment to compare results

Question 4

Which of the following is the BEST recommendation to mitigate excessive agency when implementing an AI system as a browser extension?

Options:

A.

Minimize browser extension functionality.

B.

Remove user access to browser extensions.

C.

Maximize browser extension functionality.

D.

Use open-source browser extensions.

Question 5

Which metric is MOST important to consider when reviewing the performance of a machine learning model in avoiding false positive results?

Options:

A.

Precision

B.

Accuracy

C.

F1 score

D.

Recall

Question 6

Which of the following techniques would be MOST effective as part of incident management procedures for a prompt injection attack?

Options:

A.

Fine-tune the AI model.

B.

Scan inputs for code-like structure of text.

C.

Deploy input validation to sanitize abuse prompts.

D.

Monitor the prompts for excessive special characters.

Question 7

An organization is developing an AI system that integrates data from multiple external sources without clearly defined data ownership policies. Which of the following is the GREATEST concern in this situation?

Options:

A.

Deficiencies in policies and procedures validating AI model accuracy

B.

Limited documentation of user access permissions

C.

Excessive dependence on automated data collection and cleansing

D.

Gaps in AI privacy compliance and accountability

Question 8

When developing an audit plan, which of the following is MOST important specifically for the transparency of an AI application?

Options:

A.

Explainability testing

B.

Regression testing

C.

Compliance testing

D.

Validation testing

Question 9

An IS auditor reviewing the latest AI chatbot release identifies that, despite high accuracy rates, non-English users complain about the model ' s poor accuracy. Which of the following controls is BEST at ensuring detection of subgroup regressions?

Options:

A.

Weighted metric with higher accuracy targets

B.

Human review for non-English languages after go-live

C.

Translate all outputs to English and evaluate in English for consistency

D.

Comparative language evaluations with parity thresholds

Question 10

Which of the following is the GREATEST risk associated with using AI in audit planning?

Options:

A.

Increased planning costs

B.

Scope creep

C.

Incomplete data

D.

Limited knowledge

Question 11

An IS auditor reviewed an AI-enabled software for processing a bank ' s financial information and discovered errors in the training data. Which of the following would BEST mitigate this risk?

Options:

A.

Functional testing of the application

B.

Data quality testing

C.

User interface testing

D.

Model validation on benchmark data

Question 12

An IS auditor notes the combined number of records utilized within the training, validation, and testing data sets exceeds the total number of records in the original data set. Which of the following is MOST important for the auditor to determine?

Options:

A.

Whether the training, validation, and testing data sets were created in the correct order

B.

Whether data leakage occurred from utilizing overlapping records in the data sets

C.

Whether a sufficient number of records were utilized in the training data set

D.

Whether the validation data set utilized the same number of records as the training data sets

Question 13

Which of the following is the MOST important task when gathering data during the AI system development process?

Options:

A.

Stratifying the data

B.

Isolating the system

C.

Cleaning the data

D.

Training the system

Question 14

Which of the following is the MOST important consideration when auditing the data used for training an AI model?

Options:

A.

Timeliness

B.

Predictability

C.

Representativeness

D.

Understandability

Question 15

Which of the following do supervised AI learning models PRIMARILY use to train algorithms?

Options:

A.

Unlabeled data sets

B.

Clustered data sets

C.

Labeled data sets

D.

Randomized data sets

Question 16

When initiating an AI governance program, which of the following is MOST critical to ensure the AI system aligns with organizational objectives and stakeholder needs?

Options:

A.

Defining AI regulatory compliance requirements before business needs

B.

Prioritizing AI hardware and infrastructure acquisition

C.

Establishing continuous AI system monitoring

D.

Identifying specific processes for the AI use case

Question 17

Which of the following AI documents would support an IS auditor assessing hyperparameter tuning records?

Options:

A.

Data sheets

B.

Model development logs

C.

Explainability reports

D.

Risk assessment reports

Question 18

Which of the following techniques BEST supports machine learning (ML) training in sentiment analysis?

Options:

A.

Analysis of variance

B.

Log-rank test

C.

Image recognition

D.

Logistic regression

Question 19

A retail organization uses an AI model to forecast inventory based on customer purchasing trends and updates the model quarterly. The model recently failed to recognize a surge in demand during a popular shopping season. Which of the following issues does this situation BEST demonstrate?

Options:

A.

Limited data set diversity impacting model training

B.

Data drift impacting system forecasting

C.

Overfitting issues due to a small training data set

D.

Lack of outlier checks in data affecting forecast accuracy

Question 20

A car rental company is developing an AI system to dynamically adjust rental pricing based on demand, location, and customer profiles. Which of the following is the MOST important reason to conduct specific testing during development?

Options:

A.

To ensure the model’s pricing logic aligns with business strategy

B.

To ensure the system integrates seamlessly with legacy booking platforms

C.

To confirm that the AI system can handle high volumes of customer queries

D.

To verify that pricing decisions do not result in discriminatory outcomes

Question 21

Which of the following is the BEST reason that recurrent neural networks enable language translation of documents?

Options:

A.

The process is sequential.

B.

The process uses association rules.

C.

The process is specialized for grid data.

D.

The process is unidirectional.

Question 22

What is the MOST important reason government organizations should provide regular AI training programs for all staff?

Options:

A.

To minimize the cost of AI deployment

B.

To ensure staff are up to date on ethical considerations

C.

To allow staff to understand the tools available

D.

To reduce learning using outdated information

Question 23

A health organization has deployed an AI model to analyze chest X-rays. The model reports high accuracy, but thresholds are unclear and performance is not broken down by patient demographics. Why is accuracy alone insufficient to evaluate this model?

Options:

A.

The model may perform poorly for certain groups, leading to hidden fairness risks.

B.

Accuracy can only be calculated on structured tabular datasets.

C.

A high accuracy score always indicates low false positives.

D.

Performance is identical across all demographic subgroups.

Question 24

Which of the following is the MOST significant benefit of performing frequent AI model testing and retraining?

Options:

A.

Assessing the impact of attacks

B.

Removing unnecessary model features

C.

Ensuring model scalability

D.

Ensuring the model is updated with current data

Question 25

Which of the following is an IS auditor ' s MOST important course of action when determining whether source data should be entered into approved generative AI tools to assist with an audit?

Options:

A.

Validate that the tool is leveraging the latest model.

B.

Validate that the tool provides a privacy notice.

C.

Determine whether any AI model hallucinations have occurred.

D.

Determine whether the information is reliable.

Question 26

An organization has exhausted its internal data sources to train an AI model. Which of the following is the BEST source to obtain new data?

Options:

A.

Data from web scraping

B.

Copyright-free data

C.

Extended retention of internal data

D.

Shadow data

Question 27

Which of the following is the GREATEST risk associated with normalizing a data set before splitting it into training, testing, and validation sets?

Options:

A.

The model affects data distribution.

B.

The model requires external validation.

C.

The model gains indirect knowledge from data leakage.

D.

The developer uses tree-based models with the normalized data set.

Question 28

Which of the following should be done FIRST when developing an incident management process for AI threats?

Options:

A.

Establish incident classification procedures

B.

Define clear roles and responsibilities

C.

Configure SIEM for security alerts

D.

Develop incident escalation procedures

Question 29

Which of the following is the GREATEST challenge facing IS auditors evaluating the explainability of generative AI models?

Options:

A.

Differences of opinion regarding model types

B.

Difficulties in preventing the input of biased data

C.

Performance issues due to excessive computation

D.

Algorithms changing as AI continues to learn

Question 30

During a pre-implementation risk assessment, an AI model is determined to present a significant risk of bias and potential harm in excess of the organization’s risk tolerance. Which of the following is the MOST appropriate response?

Options:

A.

Postpone deployment until the risk can be safely managed.

B.

Enhance the data that the model is trained on.

C.

Obtain board approval for an exception.

D.

Revisit the risk tolerance to ensure it is appropriate.

Question 31

An organization is conducting an audit of an AI decision-making system being used for talent recruitment. Which of the following is MOST critical to evaluate in order to ensure the system meets stakeholder needs?

Options:

A.

Predictive accuracy

B.

Input validation

C.

Decision timeliness

D.

Decision fairness

Question 32

During a walk-through, an IS auditor observes an AI engineer entering a prompt that manipulates the AI model’s behavior. Which of the following is the BEST control to prevent this?

Options:

A.

Enforce an input/output template

B.

Deploy adversarial training

C.

Encrypt the underlying data

D.

Retrain the model immediately

Question 33

An IS auditor observes that an AI-based fraud detection system used by an insurance organization produces inconsistent outcomes when processing similar cases. Which of the following is the auditor ' s MOST efficient recommendation?

Options:

A.

Introduce a human-in-the-loop mechanism for all decisions.

B.

Analyze the training data and model evaluation parameters.

C.

Strengthen user access controls and authorization for the AI system.

D.

Regularly update the AI algorithm to improve consistency.

Question 34

From a data appropriateness and bias perspective, which of the following should be of GREATEST concern when reviewing an AI model used in a credit scoring system?

Options:

A.

The model incorporates the applicant ' s loan history to assess spending habits.

B.

The model utilizes historical credit data to predict future credit behavior.

C.

The model considers the applicant ' s income level as a key factor in the credit decision.

D.

The model uses postal codes as a primary factor in determining creditworthiness.

Question 35

An IS auditor is testing an AI-based fraud detection system that flags suspicious transactions and finds that the system has a high false positive rate. Which of the following testing methods should be prioritized to BEST optimize the detection rate?

Options:

A.

Regression testing

B.

Cross-validation testing

C.

Substantive testing

D.

Benford ' s Law analysis

Question 36

Which of the following is MOST important for an IS auditor to consider when collecting data for analysis by AI tools?

Options:

A.

Data classification categories

B.

Location of and access restrictions to the data

C.

Data format and syntax requirements

D.

Model weights used for AI training

Question 37

Which of the following should be done FIRST when an AI chatbot has been identified as giving harmful advice?

Options:

A.

Implement prompt sanitization filters.

B.

Enable real-time auditing.

C.

Enable content output filters.

D.

Segment user access based on risk profiles.

Question 38

Which of the following is the PRIMARY reason IS auditors must be aware that generative AI may return different investment recommendations from the same set of data?

Options:

A.

Limitations can arise in the quantification of risk profiles.

B.

Neural node access varies each time the process is executed.

C.

Computational logic is based on probabilities.

D.

Servers are reconfigured periodically.

Question 39

Which role is BEST suited to define the implementation roadmaps for adopting AI solutions?

Options:

A.

Risk management committee

B.

Steering committee

C.

Product management

D.

Internal audit

Question 40

An insurance company uses an AI model to set premium rates. To align with AI-related policies on fairness, which of the following is the FIRST course of action?

Options:

A.

Training alternate AI models and comparing biases with the primary model

B.

Reviewing AI model training data to identify potential biases

C.

Modifying the AI model’s training dataset to address potential biases

D.

Allowing customers to contest premium rates provided by the AI model

Question 41

An organization is training a skin cancer recognition model. Photographs collected from which of the following sources would present the GREATEST risk associated with data integrity?

Options:

A.

Research facility receiving grants for cancer research

B.

Open-source data augmentation files

C.

Social media platform with images from all over the world

D.

Cohort of dermatologists with signed patient consent forms

Question 42

Which of the following is the GREATEST risk when a generative AI tool used for threat detection produces inaccurate or misleading information?

Options:

A.

Potential threats to organizational systems may be overlooked.

B.

AI-related key risk indicator (KRI) values may become less reliable.

C.

Prompt injection attacks may become more likely to succeed.

D.

The model may exaggerate the severity of threats and vulnerabilities.

Question 43

An IS auditor is evaluating an organization’s data governance controls for its AI system. Which of the following represents the GREATEST risk in this context?

Options:

A.

Inconsistent data management practices

B.

Lack of procedures for automated data backup

C.

Limited frequency of AI system performance and data accuracy reviews

D.

Inadequate controls over data accuracy and privacy compliance

Question 44

A digital bank utilizes an AI system to generate credit scores. Which of the following would BEST mitigate the risk of sudden and unexplained changes in a borrower’s credit score?

Options:

A.

Ensuring the system is periodically reviewed and calibrated by human experts to maintain stability in predictions

B.

Using only data from the last six months to one year to avoid outdated information affecting the credit score

C.

Allowing the AI to operate fully autonomously to prevent processing delays

D.

Obtaining and validating the credit scores from third-party agencies to cross-check AI-generated results

Question 45

Which of the following BEST helps in detecting AI model drift?

Options:

A.

Engaging periodic external reviews of model outputs and identifying root causes

B.

Establishing a model performance baseline and implementing continuous monitoring

C.

Using linear regression techniques and conducting cluster analysis

D.

Evaluating model accuracy rates for stability and performing qualitative data analysis

Question 46

Which of the following BEST ensures representativeness in AI systems when assessing training data periodically?

Options:

A.

Training data is manually reviewed for bias.

B.

Data validation processes are automated and consistently performed.

C.

Training data remains relevant and reflects evolving real-world conditions.

D.

Synthetic data is used to train the AI systems.

Question 47

An IS auditor uses an internally developed generative AI tool to prepare a status update for audit stakeholders. Which of the following is the auditor’s MOST appropriate course of action?

Options:

A.

Compare results with a publicly available generative AI tool to ensure outputs are similar.

B.

Assess whether the information provided is complete and accurate.

C.

Regenerate the results to ensure similar outputs are provided.

D.

Share and review the results with management.

Question 48

Which of the following is the MOST essential attribute of an AI-driven audit tool?

Options:

A.

Explainability of model conclusions

B.

Optimization of audit resources

C.

Use of labeled training datasets

D.

Support for a range of statistical methods

Question 49

An IS auditor is testing an AI model used for determining insurance premiums and eligibility. Which of the following is the MOST effective testing method to identify bias in algorithm outputs?

Options:

A.

Regression testing

B.

Cross-cluster analysis

C.

Disparate impact analysis

D.

Predictive analytics

Question 50

Which of the following controls MOST effectively helps to ensure an AI model is resilient against external threats?

Options:

A.

AI data set anonymization

B.

Monitoring of AI model developers

C.

Monitoring of AI access logs

D.

AI model configuration testing

Question 51

Which of the following is MOST important for an IS auditor to review during an AI system audit in order to determine compliance with intellectual property and data rights?

Options:

A.

Data performance metrics

B.

Data usage agreements

C.

Use of open-source intellectual property

D.

Model runtime efficiency logs

Question 52

Which of the following BEST detects model drift or unexpected changes in AI model outputs?

Options:

A.

Standardization of AI configurations

B.

Anomaly monitoring

C.

AI model documentation reviews

D.

AI model retraining

Question 53

Which of the following presents the GREATEST risk when an organization deploys a machine learning model in a public cloud environment for real-time predictions?

Options:

A.

Cloud provider employees have limited AI skills

B.

AI model audit trails have not been comprehensively documented

C.

The service level agreement (SLA) does not include network latency and inference guarantees

D.

The cloud provider has not adopted an ethical AI governance framework

Question 54

Which of the following should be an IS auditor ' s GREATEST concern when using a predictive AI tool to analyze data abnormalities?

Options:

A.

The false positives or false negatives generated by the AI tool

B.

The ease of integrating the AI tool with existing data audit software

C.

The speed at which the AI tool processes large data sets

D.

The cost of implementing and maintaining the AI tool for data audit purposes

Question 55

Which of the following techniques is BEST to use when there is a limited dataset of detailed images available to train a convolutional neural network (CNN) model?

Options:

A.

Splitting the dataset 50/50 between training and testing sets

B.

Minority class undersampling

C.

Transfer learning from an open-source model

D.

Duplication of current dataset

Question 56

When an IS auditor is reviewing results from an AI system, which of the following would cause the GREATEST risk?

Options:

A.

Inability to identify where an AI system is housed

B.

System output not being checked for inconsistencies

C.

Cascading failures of AI system outputs

D.

Difficulty of documenting AI algorithm processes

Question 57

An organization plans to implement an AI search and chatbot solution provided by an external vendor. Which of the following is MOST important for an IS auditor to confirm?

Options:

A.

Whether the solution is tied to a bilingual evaluation understudy (BLEU) metric

B.

Whether the vendor can provide an independent third-party attestation

C.

Whether the solution effectively enables web integration

D.

Whether the organization or the vendor has the test plan for the solution

Question 58

An IS auditor is reviewing a dataset used by a university to train a predictive machine learning model. Which of the following MOST likely indicates risk that the model could not process all data and make necessary correlations?

Options:

A.

Student Number field in integer format

B.

Grade Level field in float format

C.

Final Grade Percent field in object format

D.

Having an undergraduate degree in Boolean format

Question 59

Which of the following testing techniques would BEST validate whether an organization ' s data governance program effectively ensures data quality and integrity for AI model training and deployment?

Options:

A.

Performing a business impact analysis (BIA) to assess the consequences of AI model failure

B.

Reviewing the organization’s AI software development life cycle documentation

C.

Conducting a penetration test to identify vulnerabilities in the model

D.

Assessing data lineage to verify the traceability of data sources

Question 60

An IS auditor is auditing an AI system that predicts inventory needs. The system recently failed to predict a stock outage for a key product. Which of the following audit tests would BEST validate the system ' s accuracy?

Options:

A.

Unit testing of the forecasting algorithm

B.

Load testing during peak sales periods

C.

Sensitivity analysis on input variables

D.

Historical testing with past sales data

Question 61

Which use case for an AI model to be used by a food delivery service would pose ethical risk to the organization?

Options:

A.

Correlating time, cost, delivery distance, and customer satisfaction metrics to issue coupons to customers receiving substandard service

B.

Basing driver retention and termination decisions on the number of delivered orders per total hours worked as compared to an industry benchmark

C.

Comparing total food preparation and delivery time to an industry benchmark to set key performance and risk indicators for individual restaurants

D.

Using customer service metrics for service speed and food quality to predict customer retention and forecast revenue

Question 62

A healthcare AI tool recommends treatments with high success rates but significant risk. The hospital prioritizes patient safety over innovation. What is the BEST course of action?

Options:

A.

Adjust the AI ' s parameters to align with the hospital’s risk tolerance.

B.

Discontinue using the AI tool and rely solely on doctor expertise.

C.

Obtain patients ' consent for the use of their data by the AI tool.

D.

Use the AI tool only for low-risk situations.

Question 63

Which of the following will provide the BEST evidence to support the alignment of an AI model with an organization ' s business objectives?

Options:

A.

AI model vulnerability assessment

B.

AI change management requests

C.

AI model inventory

D.

AI acceptable use policy

Question 64

Which of the following strategies used by modelers to enhance data accuracy has the GREATEST risk of bias and information loss?

Options:

A.

Filling blank attributes in records with the mean, median, or mode within a grouping

B.

Identifying and deleting duplicate entries in the data set

C.

Separating multiple data attributes within one field into individual attribute columns

D.

Placing numerical data into bins or buckets for a manageable quantity of correlations and result analyses

Question 65

An IS auditor identifies that an AI model occasionally invents nonexistent medical test results. Which of the following recommendations would BEST mitigate this risk?

Options:

A.

Decreasing the top-p sampling

B.

Increasing the model context

C.

Increasing the temperature

D.

Enabling frequency penalties on rare words

Question 66

A manufacturing company installs an AI system to control robotic arms on its assembly line. The system learns over time, adjusting its movements based on production results to improve accuracy. What type of learning is the robot MOST likely using?

Options:

A.

Supervised learning

B.

Reinforcement learning

C.

Deep learning

D.

Unsupervised learning

Question 67

An organization using AI to create digital content faces challenges in protecting its intellectual property. Which of the following is the BEST way to mitigate this risk?

Options:

A.

Separate training and production data.

B.

Implement watermarking.

C.

Apply adversarial training.

D.

Implement a firewall.

Question 68

Which of the following would be MOST useful for an IS auditor when testing high-impact rare scenarios that have not yet occurred in a production environment?

Options:

A.

Anonymized historical data

B.

Synthetic data

C.

De-identified data

D.

Benchmark dataset

Question 69

Which of the following is the MOST important reason to establish AI governance structures that extend beyond regulatory compliance?

Options:

A.

To align with global AI data privacy standards

B.

To mitigate reputational risk associated with public scrutiny of AI systems

C.

To ensure ethical integrity throughout the AI life cycle

D.

To establish guardrails limiting AI system functionality to approved use cases

Question 70

An IS auditor for a veterinary clinic was informed that the dog breed categorical variable is necessary for the predictive model. Which of the following introduces the MOST risk?

Options:

A.

Data scaling was not utilized.

B.

Clustering was not utilized.

C.

Ordinal label encoding was utilized.

D.

One-hot encoding was utilized.

Question 71

A bank uses a video-based know your customer (KYC) verification process. Cybercriminals exploit this process by using deepfake technology to impersonate bank customers. Which of the following countermeasures is the BEST way for the bank to mitigate this risk?

Options:

A.

Requesting additional identity and address documents for verification

B.

Leveraging AI-based liveness detection during video verification

C.

Encrypting all customer data and communication

D.

Discontinuing the use of the video-based verification process

Question 72

Which of the following is MOST important for an IS auditor to consider when identifying AI risk in a know your customer (KYC) application within a banking organization?

Options:

A.

Intellectual property leakage and invalidation

B.

Benchmarking against peer organizations

C.

Incident response plan

D.

Business disruption and financial impact

Question 73

Which of the following is the MOST important step in an AI incident management process to ensure continuous improvement?

Options:

A.

Define ownership

B.

Root cause analysis

C.

Archive logs

D.

Assess severity

Question 74

A healthcare organization uses an AI model to analyze patient data and provide diagnostic recommendations. Which of the following MOST effectively detects data drift related to the model ' s predictions?

Options:

A.

Comparing incoming patient data distributions with the training data set

B.

Applying overrides to allow healthcare professionals to correct the AI model’s recommendations

C.

Conducting periodic model retraining to ensure alignment with updated patient data

D.

Using adversarial testing to simulate scenarios that stress test the model’s predictions

Question 75

Which of the following is the BEST recommendation for an organization that has adopted " vibe coding " (using AI to generate code based on high-level natural language prompts)?

Options:

A.

Discontinue the current practice.

B.

Adopt a security checklist for code review.

C.

Prompt the AI to review its own code.

D.

Build the organization ' s own cryptography.

Question 76

Which of the following is the BEST use of AI to audit relationships for conflicts of interest or collusion?

Options:

A.

Correlation matrix

B.

Time series analysis

C.

Graph analytics

D.

Monte Carlo simulation

Question 77

After AI training data has been tested for biases, which of the following is MOST important to check to validate the effectiveness of the testing?

Options:

A.

Feedback on data validation is obtained from key stakeholders

B.

Possible impacts from AI outputs remain within the acceptable risk level

C.

AI processes will meet expected service turnaround time

D.

Sensitive information from users is securely masked before input

Question 78

An IS auditor notes that an AI modelachieved significantly better results on training data than on test data. After the development, a quality assurance (QA) team checks that all input variables and parameters match the technical design. Which of the following BEST describes this activity?

Options:

A.

Model validation

B.

Model verification

C.

Model testing

D.

Model tuning

Question 79

An organization is using information gathered from customer accounts to train its AI chatbot. Which of the following is the GREATEST risk associated with this practice?

Options:

A.

Disclosure of personal information

B.

AI bias

C.

Transparency

D.

AI model hallucinations

Question 80

An organization ' s system development process has been enhanced with AI. Which of the following features presents the GREATEST risk?

Options:

A.

The AI allocates resources for new system development projects.

B.

Non-technical users are validating AI results.

C.

The AI personalizes applications for the user.

D.

All codes are generated by AI without human oversight.

Question 81

An organization shares an AI model with external partners. One partner reports that sensitive data has been inadvertently exposed through the model’s outputs. Which of the following is the IS auditor ' s BEST recommendation?

Options:

A.

Limit the model ' s outputs to anonymized results while investigating further.

B.

Audit the data pipelines of all partners to identify the source of the leak.

C.

Disable the shared model and notify partners of the potential breach.

D.

Retrain the model immediately and implement privacy-preserving techniques.

Question 82

An IS auditor is evaluating a cybersecurity system that uses agentic AI for autonomous threat detection and incident response. Which of the following is MOST important for the auditor to consider?

Options:

A.

The agent operates across systems, which might require network expansion.

B.

The agent processes data autonomously, reducing the need for analyst intervention.

C.

The agent ' s audit logs are lengthier than traditional logs.

D.

The agent can take automated actions that may disrupt business operations.

Page: 1 / 27
Total 273 questions