10 free IAPP AIGP practice questions with the correct answer and a full explanation for each, taken from the CertStash pack of 222 questions. Work through them, then open each answer to check your reasoning.
Get all 222 questions (US$39) · Download these 10 as a PDF
Question 1
Machine learning is best described as a type of algorithm by which?
Show answer and explanation
Correct answer: B. Systems can automatically improve from experience through predictive patterns.
Machine learning is fundamentally defined as a system's ability to automatically improve and learn from experience without being explicitly programmed. Option B captures this core concept by emphasizing automatic improvement from experience through predictive patterns, which is the defining characteristic of machine learning.
Why the other options are wrong
- A. This describes AI broadly (mimicking human intelligence) rather than the specific mechanism of machine learning (learning from experience).
- C. This focuses on statistical inference from samples to predict human intelligence, which is not the defining characteristic of machine learning.
- D. While data analysis occurs in machine learning, this describes data mining or knowledge discovery rather than the learning mechanism itself.
Question 2
Random forest algorithms are in what type of machine learning model?
Show answer and explanation
Correct answer: C. Discriminative.
Random forest algorithms are ensemble methods used for classification and regression tasks where the goal is to discriminate between classes based on input features. They are discriminative models because they learn to distinguish between different classes by modeling the decision boundaries directly, rather than modeling the probability distribution of the data itself.
Why the other options are wrong
- A. Symbolic models use explicit rules and logical representations, not the ensemble tree-based approach of random forests.
- B. Generative models learn the underlying probability distribution of data to generate new samples; random forests directly discriminate between classes.
- D. Natural language processing is a specific application domain, not a model type classification.
Question 3
A company developed AI technology that can analyze text, video, images and sound to tag content, including the names of animals, humans and objects.
What type of AI is this technology classified as?
Show answer and explanation
Correct answer: B. Multi-modal model.
A system that processes and analyzes multiple types of data modalities (text, video, images, and sound) simultaneously to perform unified tagging and recognition is the definition of a multi-modal model. Multi-modal AI integrates information from different input types to achieve comprehensive understanding and analysis.
Why the other options are wrong
- A. Deductive inference involves drawing specific conclusions from general principles, not processing multiple data types.
- C. Transformative AI refers to AI with broad societal impact, not the technical architecture of processing multiple data modalities.
- D. Expert systems use knowledge bases and rules to emulate human expertise in specific domains, not unified multi-modal analysis.
Question 4
If it is possible to provide a rationale for a specific output of an AI system, that system can best be described as:
Show answer and explanation
Correct answer: C. Explainable.
Explainability specifically refers to the ability of an AI system to provide a clear rationale or explanation for its outputs and decisions. When a system can articulate why it made a particular decision, it is demonstrating explainability, which is crucial for user trust and understanding of AI behavior.
Why the other options are wrong
- A. Accountability refers to being answerable for actions and outcomes, not specifically the ability to provide rationale.
- B. Transparency means the system's operations are visible, but not necessarily that explanations are provided for specific outputs.
- D. Reliability refers to consistent and dependable performance, not the provision of decision rationales.
Question 5
CASE STUDY
Please use the following to answer the next question:
A company is considering the procurement of an AI system designed to enhance the security of IT infrastructure. The AI system analyzes how users type on their laptops, including typing speed, rhythm and pressure, to create a unique user profile. This data is then used to authenticate users and ensure that only authorized personnel can access sensitive resources.
When prioritizing the updates to its policies, rules and procedures to include the new AI system for user authentication, the organization should:
Show answer and explanation
Correct answer: C. Ensure that any personal data used is only processed for a specific and lawful purpose.
When implementing an AI system that collects and processes personal biometric data (typing patterns), the organization must ensure compliance with data protection principles, particularly the requirement that personal data be processed only for specific, lawful, and justified purposes. This is a fundamental requirement under privacy regulations like GDPR and ensures the organization uses personal data ethically and legally.
Why the other options are wrong
- A. While third-party data sharing may be relevant, the primary concern is ensuring lawful processing of personal data for a specific purpose.
- B. Security controls are important but secondary to establishing the lawful basis and purpose for processing personal data.
- D. Policy complexity reduction for non-technical employees is a communications issue, not the primary governance priority for this scenario.
Question 6
What type of organizational risk is associated with AI’s resource-intensive computing demands?
Show answer and explanation
Correct answer: D. Environmental risk.
AI systems with resource-intensive computing demands consume significant electricity and generate substantial carbon emissions, creating environmental risks. The energy consumption required for training and running large-scale AI models contributes to climate impact and resource depletion, making this an organizational environmental risk.
Why the other options are wrong
- A. People risk relates to workforce impacts and human factors, not computational resource demands.
- B. Security risk concerns data protection and system vulnerabilities, not energy consumption.
- C. Third-party risk involves dependencies on external vendors and suppliers, not the environmental impact of computing resources.
Question 7
A hospital implements an AI system to assist doctors in diagnosing diseases based on historical patient data.
Which one of the following model types best describes this system?
Show answer and explanation
Correct answer: C. Probabilistic.
A disease diagnosis system based on historical patient data uses probabilistic modeling because it must estimate the probability of different diagnoses given symptoms and patient history. Probabilistic models explicitly handle uncertainty and provide probability distributions over possible outcomes, which is essential for medical diagnosis where multiple conditions may be possible with varying likelihoods.
Why the other options are wrong
- A. Inference is the process of making predictions, not a model type classification.
- B. Statistical models encompass a broad category; probabilistic models are the specific type that handles uncertainty with probability distributions.
- D. Deterministic models produce fixed outputs for given inputs with no uncertainty, unsuitable for diagnosis where multiple outcomes have different probabilities.
Question 8
Which of the following AI uses is best described as human-centric?
Show answer and explanation
Correct answer: D. Virtual assistants are used to adapt educational content and teaching methods to individuals, offering personalized recommendations based on ability and needs.
Human-centric AI prioritizes human well-being, autonomy, and individual needs. Option D describes virtual assistants that personalize educational content based on individual ability and needs, directly supporting human development and respecting individual differences. This approach centers on enhancing human capability and choice rather than just optimizing processes or outcomes.
Why the other options are wrong
- A. While beneficial to many, improving weather predictions is more about general utility than focusing on individual human needs and autonomy.
- B. Autonomous robots reducing physical strain benefits workers, but the focus is on automation efficiency rather than personalized human development.
- C. Demand forecasting and inventory management are business optimization goals that benefit consumers generally, not human-centric applications focused on individual needs.
Question 9
Which of the following is a foundational characteristic of effective AI governance?
Show answer and explanation
Correct answer: A. Engagement of a cross-functional team.
Effective AI governance starts with a cross-functional team spanning development, deployment, legal, privacy, security, compliance, ethics and business functions. AI risks are technical, legal and social at once, so no single function can identify or control them alone. Cross-functional engagement is the structural foundation that makes the other practices, such as vendor oversight and role-specific policies, work as intended across the AI lifecycle.
Why the other options are wrong
- B. Vendor management is a supporting process within governance, not the foundation that effective AI governance is built on.
- C. Public filings review may provide external context but is not a core foundational element of internal governance.
- D. Uniform policies across all roles would be ineffective; developers, deployers and users carry different duties and need tailored controls.
Question 10
CASE STUDY
Please use the following to answer the next question:
A company is considering the procurement of an AI system designed to enhance the security of IT infrastructure. The AI system analyzes how users type on their laptops, including typing speed, rhythm and pressure, to create a unique user profile. This data is then used to authenticate users and ensure that only authorized personnel can access sensitive resources.
All of the following are obligations of the company as a data controller when implementing its AI system EXCEPT?
Show answer and explanation
Correct answer: A. Ensuring that third-party processors are based in the same country as the company.
As a data controller under privacy frameworks like GDPR, the company must allow data subject access requests, implement technical and organizational security measures, and conduct impact assessments for high-risk processing. However, there is no requirement that third-party processors be based in the same country as the company. Controllers can use processors in other jurisdictions provided appropriate safeguards and contractual arrangements are in place. Geography alone is not a determining factor for processor selection under modern data protection law.
Why the other options are wrong
- B. Data subject access requests (DSARs) are a core obligation of data controllers under privacy regulations.
- C. Technical and organizational measures to protect personal data are mandatory obligations of data controllers.
- D. Conducting a DPIA/PIA for AI systems processing biometric data for authentication is a legal obligation for high-risk processing.
That was 10 of 222.
The full IAPP AIGP pack has all 222 questions, each with the answer, the explanation and why the other options are wrong, plus a questions-only copy for timed runs. US$39, paid once, with free monthly updates and a pass-or-your-money-back guarantee.
