Official Bank 0/180

ISACA Advanced in AI Audit (AAIA) - Isaca Actual Exam Questions

Last updated on April 30, 2026

97% Exam Compliance
180 Total Questions
1
Question

When an IS auditor uses generative AI with external RAG (retrieval-augmented generation) to gather evidence during an audit, which of the following poses the GREATEST data security risk?

Options
A

Sensitive internal context may be included in queries sent to external services.

B

Personal information may be shared based on model training data.

C

External search engines only respond to public data.

D

The model might fail to retrieve data from the vector.

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

2
Question

An IS auditor is interviewing management about implemented controls around machine learning (ML) models deployed in the production environment. Which of the following schedules for reviewing the performance of a deployed model would be of GREATEST concern to the auditor?

Options
A

After changes to hardware and software platforms

B

After functionality changes

C

One time prior to migrating to production

D

On an annual recurring basis

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

3
Question

An IS auditor is evaluating an organization’s data governance controls for its AI system. Which of the following represents the GREATEST risk in this context?

Options
A

Inconsistent data management practices

B

Lack of procedures for automated data backup

C

Limited frequency of AI system performance and data accuracy reviews

D

Inadequate controls over data accuracy and privacy compliance

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

4
Question

Which of the following testing techniques would BEST validate whether an organization's data governance program effectively ensures data quality and integrity for AI model training and deployment?

Options
A

Performing a business impact analysis (BIA) to assess the consequences of AI model failure

B

Reviewing the organization’s AI software development life cycle documentation

C

Conducting a penetration test to identify vulnerabilities in the model

D

Assessing data lineage to verify the traceability of data sources

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

5
Question

Which of the following is MOST important to consider when evaluating ethical risk related to data used for training an AI model?

Options
A

Ability to generate diverse outputs

B

Sensitivity and origin of training data

C

Frequency of model updates

D

Cleaning and validation methods for training data

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

Finish Practice?

Are you sure you want to finish? This will end your practice session.