Try 12 free ISACA AAIA practice questions
Real exam-style questions taken word for word from the ISACA AAIA study guide. Three are below, with the full answer explanation. Enter your email and the full 12-question PDF is yours.
Unlock the full sampler
Three questions to try right now
Work each one before you open the answer. These are the same style and depth as the Advanced in AI Audit (AAIA) exam expects.
Question 1. An organization has deployed an AI-based document repository and is now reviewing its data governance framework to ensure it remains fit for purpose. Which of the following should be the PRIMARY consideration when updating that framework?
- A. Data retention policy
- B. Data classification
- C. Data enrichment
- D. Qualitative data collection
Show the answer
Answer: B. AI-based document repositories depend on properly classified data to enforce appropriate access controls, protection requirements, and compliance obligations across the AI lifecycle. Data classification is foundational: it determines how data is handled, who can access it, how long it must be retained, and what regulatory obligations apply. An IS auditor reviewing the governance update would look first at whether a robust classification scheme is in place before assessing downstream controls.
- A: Retention policy is important but is subordinate to classification, which determines the rules that retention policies then apply to specific data categories.
- C: Data enrichment is a technique for improving data quality and utility; it is not a governance priority when the core concern is ensuring proper handling and protection of existing documents.
- D: Qualitative data collection is a research methodology concept unrelated to the governance framework adjustments triggered by an AI repository deployment.
Question 2. An AI diagnostic system used in a hospital setting shows a measurable drop in accuracy when applied to patients from underrepresented demographic groups. Which of the following is the BEST course of action to address this disparity?
- A. Retrain the model using a dataset that better represents all demographic groups.
- B. Replace all training data with synthetically generated records to remove demographic signals.
- C. Optimize the model's hyperparameters to improve overall classification performance.
- D. Apply data anonymization to remove demographic identifiers from the training dataset.
Show the answer
Answer: A. Decreased accuracy for specific population groups is a classic symptom of training data that underrepresents those groups, producing a biased model. Retraining with a more representative dataset directly corrects the source of the disparity by ensuring the model learns patterns applicable across all relevant populations. An AI auditor evaluating this system would expect the organization to remediate bias at its root cause, which is the data, rather than masking it through anonymization or tuning unrelated parameters.
- B: Synthetic data generation can introduce its own distributional biases and does not guarantee demographic coverage; replacing all real data discards valid signal without addressing the representativeness problem.
- C: Hyperparameter optimization adjusts model configuration but does not change what the model learned from imbalanced training data; it treats a symptom rather than the cause.
- D: Anonymizing demographic identifiers reduces transparency and may make bias harder to detect and audit; it does not make the underlying data more representative.
Question 3. An IS auditor is recommending a key performance indicator (KPI) to assess the output reliability of a natural language processing (NLP) AI model used for document summarization. Which of the following metrics is MOST appropriate?
- A. Landmark localization error
- B. Receiver operating characteristic (ROC) curve
- C. Recall-Oriented Understudy for Gisting Evaluation (ROUGE)
- D. Mean squared error (MSE)
Show the answer
Answer: C. ROUGE measures the quality of text generation by comparing a model's output against reference summaries using recall-based overlap of n-grams and sequences. It is the standard evaluation metric for NLP tasks such as summarization and translation, directly addressing output reliability for the document summarization use case. An IS auditor recommending KPIs for an NLP system should select metrics aligned to the modality and task type.
- A: Landmark localization error is a computer vision metric used to evaluate the positional accuracy of features in images; it has no applicability to text-based NLP models.
- B: The ROC curve measures binary classification model performance by plotting true positive rate against false positive rate; it is not applicable to generative or summarization tasks.
- D: Mean squared error measures the average squared difference between predicted and actual numerical values; it is suited to regression models, not text generation quality assessment.
Unlock the full 12-question sampler
All 12 come with the same written explanations the book uses, covering why the right answer is right. We email you the PDF, nothing else.
What you get
The sampler is free. Here is exactly what lands in your inbox.
Print it or work it on screen, then score yourself against the answer key.
Nothing is written for marketing. Every question is lifted from the study guide itself.
A few days later we send one email with a code for the full study guide. That is the entire sequence.
The full ISACA AAIA study guide
The complete guide covers the Advanced in AI Audit (AAIA) exam objective by objective in plain English, with the full practice question bank behind these samples.
From $20.99
Simply Certified is an independent publisher. AAIA is a trademark of ISACA, which does not sponsor or endorse this product. This page and the sampler are independent study material and are not affiliated with, endorsed by, or sponsored by ISACA.