Advanced in AI Security Management Free Sample Questions

Create a free account to browse all 20 sample questions. The full practice test includes 226 questions. Use the simulator for timed and flashcard mode.

Try Simulator

AAISM Sample Questions

  1. Question 1

    Q1

    A multinational financial institution is establishing its AI Governance Framework. The Chief AI Security Officer (CAISO) is defining the responsibilities of the AI Steering Committee. According to ISACA best practices and the COBIT for AI rationale, which of the following is the PRIMARY responsibility of this committee regarding AI risk appetite?

    Show answer & explanation

    Correct answer: B

    The AI Steering Committee acts as a bridge between the Board of Directors and operational management. Its primary role regarding risk is to translate the high-level enterprise risk appetite set by the Board into actionable AI-specific risk tolerance levels that guide project approval and control implementation.

  2. Question 2

    Q2

    An organization is adopting the NIST AI Risk Management Framework (AI RMF) to govern its generative AI deployments. During the 'Map' function, the team is struggling to identify potential downstream impacts. Which of the following activities is MOST critical during this phase to ensure comprehensive context establishment?

    Show answer & explanation

    Correct answer: B

    The 'Map' function in NIST AI RMF is focused on establishing context. Characterizing the intended purpose, users, and deployment environment is the foundational step to identifying risks. Without this context, downstream risks cannot be accurately mapped.

  3. Question 3

    Q3

    You are designing a secure architecture for a healthcare AI model that processes highly sensitive patient data. To minimize privacy risks during the training phase without exposing raw data to the central server, you decide to implement Federated Learning.

    Review the diagram below representing the proposed flow. What critical security control is missing from the aggregation step (Server) to prevent the reconstruction of individual user data from gradient updates?

    Show answer & explanation

    Correct answer: B

    In Federated Learning, sending raw gradients to a server can still leak information about the training data (model inversion/inference attacks). To prevent this at the aggregation step, Secure Aggregation (often using SMPC) or adding Differential Privacy (noise) to the updates is required to ensure the server sees only the aggregate update, not individual contributions.

    sequenceDiagram participant Client1 participant Client2 participant Server Client1->>Client1: Train Local Model Client2->>Client2: Train Local Model Client1->>Server: Send Gradient (Encrypted/Noisy) Client2->>Server: Send Gradient (Encrypted/Noisy) Note over Server: Secure Aggregation Required Here Server->>Server: Update Global Model Server-->>Client1: Send New Global Model Server-->>Client2: Send New Global Model
  4. Question 4

    Q4

    A retail company is updating its Acceptable Use Policy (AUP) to address the use of public Generative AI tools by employees. Which of the following provisions is MOST critical to include to prevent data leakage while maintaining productivity?

    Show answer & explanation

    Correct answer: B

    The most critical risk with public GenAI tools is the training of the provider's models on user data. An AUP must explicitly prohibit entering sensitive data (PII, IP, secrets) into public tools, while allowing use for non-sensitive tasks to balance security and productivity.

  5. Question 5

    Q5Multiple answers

    Which of the following activities are considered 'High Risk' under the EU AI Act and would require the most stringent conformity assessments? (Select TWO)

    Show answer & explanation

    Correct answers: A, C

    Under the EU AI Act, systems used in employment, workers management, and access to self-employment (e.g., CV screening software) are classified as High Risk due to their potential impact on fundamental rights.

    AI systems evaluating creditworthiness of natural persons or establishing their credit score are High Risk as they determine access to essential private services.

  6. Question 6

    Q6

    A security analyst discovers that a deployed image recognition model has been misclassifying images that contain a specific, imperceptible pattern of noise overlay. This pattern appears to have been intentionally crafted. This is an example of which type of adversarial attack?

    Show answer & explanation

    Correct answer: B

    This describes an Evasion Attack (often using adversarial examples). The attacker manipulates the input data (inference time) with perturbations (noise) to cause the model to make a prediction error. It does not tamper with the training data itself.

  7. Question 7

    Q7

    The ___________ is a document that provides a high-level description of the AI model, including its intended use, limitations, training data provenance, and performance metrics, serving as a key transparency control.

    Show answer & explanation

    Correct answer: A

    A Model Card (introduced by Google researchers and widely adopted) is a standardized document that details performance characteristics, intended use, limitations, and ethical considerations of an AI model.

  8. Question 8

    Q8

    When integrating a third-party AI model into a critical business process, which of the following is the MOST effective method to mitigate supply chain risks related to hidden backdoors or malicious code in the model artifacts?

    Show answer & explanation

    Correct answer: B

    Cryptographic signing of model artifacts (e.g., using Sigstore or similar tools) ensures integrity and authenticity. Validating the signature before loading prevents the execution of tampered models or models from untrusted sources, directly addressing the risk of supply chain injection attacks.

  9. Question 9

    Q9

    True or False: In the context of AI security, 'Explainability' (XAI) is purely an ethical requirement and has no impact on security incident investigation.

    Show answer & explanation

    Correct answer: B

    False. Explainability is critical for security forensics. If an AI system behaves maliciously (e.g., due to an adversarial attack or poisoning), security analysts need explainability tools (like SHAP or LIME) to understand why the model made that decision and identify the root cause of the breach.

  10. Question 10

    Q10

    An organization uses a Large Language Model (LLM) to summarize customer support tickets. Security testing reveals that by crafting a specific prompt, an attacker can force the model to ignore its safety guidelines and reveal its initial system instructions. What is this vulnerability called?

    Show answer & explanation

    Correct answer: A

    Prompt Injection (specifically direct injection or jailbreaking) involves manipulating the input to override the model's original instructions or safety constraints. This allows the attacker to control the model's output.

Register free to unlock 10 more sample questions

Create a free account to continue with the rest of the AAISM sample set.

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 226 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon