10 free ISACA AAISM practice questions with the correct answer and a full explanation for each, taken from the CertStash pack of 371 questions. Work through them, then open each answer to check your reasoning.
Get all 371 questions (US$39) · Download these 10 as a PDF
Question 1
An AI research team is developing a natural language processing model that relies on several open-source libraries.
Which of the following is the team's BEST course of action to ensure the integrity of the software packages used?
Show answer and explanation
Correct answer: C. Scan the packages and libraries for malware prior to installation.
Scanning packages and libraries for malware before installation directly protects against compromised dependencies. It is a foundational control in securing open-source software supply chains and stops malicious code from entering the development environment. Maintaining lists, retraining, and updating are useful practices, but they do not address the integrity threat posed by potentially compromised packages.
Why the other options are wrong
- A. Maintaining a list ensures consistency but does not verify package integrity or detect malware.
- B. Retraining the model is unrelated to detecting malicious code in package dependencies.
- D. Version currency alone does not verify integrity; a latest-version package can still be malicious.
Question 2
An organization plans to apply an AI system to its business, but developers find it difficult to predict system results due to lack of visibility to the inner workings of the AI model.
Which of the following is the GREATEST challenge associated with this situation?
Show answer and explanation
Correct answer: D. Gaining the trust of end users through explainability and transparency
The lack of visibility into how an AI model reaches its decisions creates a fundamental explainability problem that directly undermines user trust. In business applications, especially those affecting critical decisions, stakeholders and end users need to understand model behavior to trust and accept the system. Without explainability and transparency, adoption becomes difficult regardless of technical performance, making this the greatest challenge among the options presented.
Why the other options are wrong
- A. Risk ownership and uptime are operational concerns, not directly related to lack of model visibility.
- B. Security requirements are separate from the explainability challenge described.
- C. Transaction turnaround time is a performance metric unrelated to model interpretability.
Question 3
Which of the following is MOST important to consider when validating a third-party AI tool?
Show answer and explanation
Correct answer: C. Right to audit
The right to audit a third-party AI tool is the most important validation consideration because it grants the organization the ability to independently verify the tool's behavior, security, data handling, and compliance with requirements. Without audit rights, an organization has no independent recourse to validate claims or investigate issues. Terms and conditions, testing, and certifications are all valuable but are less critical than maintaining the contractual right to examine the system directly.
Why the other options are wrong
- A. Terms and conditions are important but secondary to the ability to verify compliance through audit.
- B. Roundtable testing is useful but does not provide the organization with independent verification rights.
- D. Industry analysis and certifications are helpful context but do not provide direct verification capability.
Question 4
After implementing a third-party generative AI tool, an organization learns about new regulations related to how organizations use AI.
Which of the following would be the BEST justification for the organization to decide not to comply?
Show answer and explanation
Correct answer: C. The risk is within the organization's risk appetite.
If the risk from non-compliance falls within the organization's defined risk appetite, that becomes the justification for a deliberate risk acceptance decision. Organizations can knowingly choose not to comply with certain regulations if they have explicitly accepted the associated risk through governance processes. This is a legitimate risk management decision. The other options do not provide valid justification: industry usage does not override regulations, audits do not excuse compliance, and lack of cost analysis is poor risk management rather than a reason to avoid compliance.
Why the other options are wrong
- A. Industry usage does not provide legal or regulatory justification for non-compliance.
- B. Regular audits do not eliminate regulatory obligations or provide exemption from compliance.
- D. Failure to determine compliance costs is a gap in risk analysis, not a valid reason to avoid compliance.
Question 5
Which of the following is the MOST important consideration when deciding how to compose an AI red team?
Show answer and explanation

Question 6
An organization's CIO provided the AI steering committee with a list of AI technologies in use and tasked them with categorizing the technologies by risk.
Which of the following should the committee do FIRST?
Show answer and explanation
Correct answer: B. Ensure the AI technologies are included in the asset inventory.
Before categorizing AI technologies by risk, the committee must first ensure all technologies are included in a comprehensive asset inventory. A complete inventory is a prerequisite for any risk assessment effort, without knowing what exists and what is documented, the categorization cannot be reliable or comprehensive. This foundational inventory work must precede risk grouping, assessment, or vulnerability identification.
Why the other options are wrong
- A. Grouping similar products is premature without first establishing a complete inventory.
- C. Risk assessment cannot be accurate without first documenting all assets in the inventory.
- D. Vulnerability identification is a downstream activity that depends on asset inventory completion.
Question 7
A large pharmaceutical company using a new AI solution to develop treatment regimens is concerned about potential hallucinations with the introduction of real-world data.
Which of the following is MOST likely to reduce this risk?
Show answer and explanation
Correct answer: C. Human-in-the-loop
Human-in-the-loop controls are the most effective approach to reduce hallucination risks in high-stakes domains like pharmaceutical treatment development. By requiring human review and validation of AI-generated recommendations before they are acted upon, the organization can catch factually incorrect or nonsensical outputs before they cause harm. This is especially critical when real-world data is introduced, as it can trigger unexpected model behaviors. Penetration testing targets security vulnerabilities, data validation improves data quality but not output accuracy, and impact analysis assesses consequences rather than preventing hallucinations.
Why the other options are wrong
- A. Penetration testing addresses security attacks, not AI hallucinations or factual accuracy.
- B. Data validation improves input quality but does not prevent the model from generating false information.
- D. Impact analysis assesses potential consequences but does not reduce the risk of hallucinations occurring.
Question 8
Which of the following should be the PRIMARY consideration for an organization concerned about liabilities associated with unforeseen behavior from agentic AI systems?
Show answer and explanation
Correct answer: D. Accountability model
An accountability model is the primary consideration for managing liabilities from agentic AI systems because it establishes clear responsibility for decisions, actions, and outcomes produced by the system. With autonomous or semi-autonomous AI agents that can take unforeseen actions, organizations need to define who is accountable for those actions, whether the AI vendor, the organization, specific personnel, or some combination. This accountability framework is foundational to managing legal and operational liability. Model dependencies, approved base models, and risk levels are important but secondary to establishing who bears responsibility.
Why the other options are wrong
- A. Model dependencies relate to technical architecture but do not address accountability for system behavior.
- B. Approved base models help ensure quality but do not establish liability or accountability structures.
- C. Acceptable risk level defines tolerance but does not determine who is accountable when unforeseen behavior occurs.
Question 9
During the creation of a new large language model (LLM), an organization procured training data from multiple sources.
Which of the following is MOST likely to address the CISO's security and privacy concerns?
Show answer and explanation
Correct answer: C. Data classification
Data classification is the most appropriate answer for addressing CISO security and privacy concerns when procuring training data from multiple sources. It involves categorizing data by sensitivity level, ownership, and regulatory requirements, enabling the organization to understand what data they have, where it came from, and how to handle it appropriately. This foundational step allows the CISO to apply appropriate protections, identify compliance risks, and make informed decisions about data usage.
Why the other options are wrong
- A. Data minimization reduces data volume but doesn't address the security and privacy concerns of already-procured multi-source data that must be classified and managed.
- B. Data augmentation adds synthetic data to training sets but doesn't address security and privacy concerns about existing procured data.
- D. Data discovery identifies where data exists but doesn't directly address how to handle security and privacy concerns once located.
Question 10
An organization is reviewing an AI application to determine whether it is still needed. Engineers have been asked to analyze the number of incorrect predictions against the total number of predictions made.
Which of the following is this an example of?
Show answer and explanation

That was 10 of 371.
The full ISACA AAISM pack has all 371 questions, each with the answer, the explanation and why the other options are wrong, plus a questions-only copy for timed runs. US$39, paid once, with free monthly updates and a pass-or-your-money-back guarantee.
