AAISM Online Practice Questions

Home / ISACA / AAISM

Latest AAISM Exam Practice Questions

The practice questions for AAISM exam was last updated on 2025-12-27 .

Viewing page 1 out of 18 pages.

Viewing questions 1 out of 90 questions.

Question#1

An organization plans to implement a new AI system.
Which of the following is the MOST important factor in determining the level of risk monitoring activities required?

A. The organization’s risk appetite
B. The organization’s number of AI system users
C. The organization’s risk tolerance
D. The organization’s compensating controls

Explanation:
AAISM risk management guidance clarifies that the organization’s risk tolerance is the most important factor in determining how much monitoring is needed. Risk tolerance specifies the amount of risk the organization is willing to accept and defines the threshold for triggering monitoring or mitigation activities. Risk appetite is broader and strategic, while tolerance sets the operational limits. The number of users may influence scale, and compensating controls may affect resilience, but neither dictates monitoring intensity as directly as risk tolerance.
Reference: AAISM Study Guide C AI Risk Management (Risk Appetite vs. Tolerance)
ISACA AI Security Management C Monitoring Based on Risk Tolerance

Question#2

An aerospace manufacturing company that prioritizes accuracy and security has decided to use generative AI to enhance operations.
Which of the following large language model (LLM) adoption plans BEST aligns with the company’s risk appetite?

A. Developing a public LLM to automate critical functions
B. Purchasing an LLM dataset on the open market
C. Contracting LLM access from a reputable third-party provider
D. Developing a private LLM to automate non-critical functions

Explanation:
AAISM recommends aligning AI adoption with organizational risk appetite by limiting blast radius, protecting sensitive data, and staging adoption in lower-risk domains first. Building a private LLM for non-critical functions preserves data control, enables tighter governance (access control, logging, evaluation), and confines any model errors away from safety- or mission-critical operations. A public LLM for critical functions (A) is misaligned with a high-assurance posture; buying open-market datasets (B) raises provenance and licensing risk; third-party access (C) can be appropriate but still introduces vendor/visibility limits and data residency concerns that may not meet aerospace security needs.
Reference: AI Security Management™ (AAISM) Body of Knowledge ― Risk Appetite Mapping to AI Use Cases; Criticality Segmentation; Data Control & Deployment Models. AAISM Study Guide ― Phased Adoption for High-Assurance Environments; Private vs. Hosted LLM Trade-offs; Governance, Evaluation, and Containment Patterns.

Question#3

Which of the following would MOST effectively obtain ongoing support from stakeholders to align AI initiatives with business objectives?

A. Conducting periodic organization-wide AI staff training
B. Addressing and optimizing AI-related risk
C. Developing and monitoring the AI strategic roadmap
D. Quantifying and communicating the value of AI solutions

Explanation:
Sustained stakeholder sponsorship hinges on demonstrated, quantified business value communicated in terms they own (KPIs, ROI, cost-to-serve, risk-adjusted outcomes). AAISM frames stakeholder alignment as a value-assurance loop: define value hypotheses, measure realized value, and continuously communicate results to sponsors. While an AI roadmap (C), risk optimization (B), and training (A) are important, they support rather than drive ongoing executive buy-in. Quantified value narratives secure resources and reinforce alignment to strategic goals.
Reference:
• AI Security Management™ (AAISM) Body of Knowledge: Strategy & Value Realization― value metrics, benefits tracking, stakeholder reporting
• AAISM Study Guide: Business alignment for AI―OKRs/KPIs, ROI cases, benefits realization management

Question#4

Which of the following is the MOST effective use of AI-enabled tools in a security operations center (SOC)?

A. Employing AI-enabled tools to reduce false negatives by detecting subtle attack patterns
B. Using AI-enabled tools exclusively to classify all types of security incidents
C. Replacing human analysis with automated AI decision-making processes
D. Assigning AI-enabled tools to triage non-critical alerts to preserve SOC resources

Explanation:
The most effective SOC application of AI is in detecting subtle, hard-to-find attack patterns that reduce false negatives.
AAISM technical control guidance notes that AI in SOCs is best applied to:
Enhance detection accuracy and sensitivity to anomalies.
Assist analysts in identifying hidden patterns that traditional rule-based systems miss.
Augment―not replace―human decision-making for high-confidence outcomes.
Options B and C incorrectly shift responsibility entirely to AI, which contradicts governance principles requiring human oversight.
Option D is useful for efficiency, but the primary effectiveness comes from improving detection quality.
Therefore, the most effective use is to reduce false negatives and detect subtle attacks.

Question#5

Within an incident handling process, which of the following would BEST help restore end-user trust in an AI system?

A. Remediation of the AI system based on lessons learned
B. The AI model’s outputs are validated by team members
C. AI is used to monitor incident detection and alerts
D. The AI model prioritizes incidents based on business impact

Explanation:
AAISM highlights that post-incident remediation and demonstrating lessons learned is essential to restoring trust. Governance guidance specifies that stakeholders regain confidence only when organizations show clear corrective actions, transparency, and improvements to prevent recurrence.
Validating outputs (B) supports accuracy but is not trust-restoring. Monitoring (C) and prioritization (D) relate to operations, not trust rebuilding.
Reference: AAISM Study Guide C AI Governance; Incident Response and Trust Restoration.

Exam Code: AAISMQ & A: 255 Q&AsUpdated:  2025-12-27

 Get All AAISM Q&As