Try 12 free ISACA AAISM practice questions
Real exam-style questions taken word for word from the ISACA AAISM study guide. Three are below, with the full answer explanation. Enter your email and the full 12-question PDF is yours.
Unlock the full sampler
Three questions to try right now
Work each one before you open the answer. These are the same style and depth as the Advanced in AI Security Management (AAISM) exam expects.
Question 1. An organization's AI system has expanded its integration surface by connecting to a significantly larger number of third-party systems. Which of the following is the BEST recommendation for an information security manager in this situation?
- A. Monitor server utilization across all connected systems to maintain optimal operational performance.
- B. Clarify and formalize lines of accountability for security control ownership across all integrations.
- C. Conduct thorough due diligence on each new third-party connection before integration is approved.
- D. Introduce equitable cost-allocation mechanisms that distribute integration expenses across all third parties.
Show the answer
Answer: C. Each new third-party integration expands the attack surface and introduces new supply-chain dependencies. Due diligence before integration ensures that each vendor meets the organization's security, privacy, and compliance standards, preventing the organization from inheriting third-party vulnerabilities. Clarifying accountability (B) is important governance work but is secondary to ensuring that the parties being onboarded meet security requirements in the first place. Server utilization monitoring (A) is an operational concern. Cost distribution (D) is a commercial matter, not a security recommendation.
- A: Monitoring server utilization addresses operational performance, not the security risks introduced by expanding the third-party integration footprint.
- B: Formalizing accountability is a useful governance step but does not mitigate the risk introduced by integrating vendors who have not been security-assessed.
- D: Cost-allocation mechanisms address commercial fairness and have no direct bearing on the security risks created by third-party AI system connections.
Question 2. After deploying an AI system that processes anonymized datasets, an organization receives a regulatory warning that AI-enabled re-identification attacks are an emerging threat. Which of the following should the information security manager do FIRST?
- A. Treat anonymization as sufficiently protective and resume normal operations pending further regulatory guidance.
- B. Delete all anonymized datasets immediately and suspend AI services until the risk is formally assessed.
- C. Implement a monitoring and testing program that includes privacy audits and adversarial re-identification testing.
- D. Apply stronger access controls to all services that consume anonymized data.
Show the answer
Answer: C. The security manager's first obligation is to assess actual exposure before taking disruptive or irreversible action. A monitoring and testing program that incorporates privacy audits and adversarial re-identification testing generates the evidence needed to understand whether the risk is material, which then drives proportionate remediation. Doing nothing (A) ignores a credible regulatory warning. Immediately deleting data and suspending services (B) is a disproportionate response without evidence of actual harm. Applying access controls (D) addresses a symptom but bypasses the assessment step needed to determine whether re-identification is actually occurring.
- A: Assuming anonymization remains sufficient contradicts the regulator's warning and exposes the organization to compliance failure.
- B: Deleting datasets and suspending services is an extreme, potentially irreversible action that is premature before the extent of the risk is understood.
- D: Tightening access controls may be part of the eventual treatment plan but should follow, not precede, an assessment that confirms the nature and scope of the exposure.
Question 3. Which of the following is the MOST effective action an organization can take to reduce data security risk when employees use generative AI features embedded in business applications?
- A. Establish intellectual property ownership guidelines and best practices with third-party AI providers.
- B. Require opt-out provisions for organizational data usage in AI service agreements.
- C. Develop and enforce acceptable-use policies for AI, supported by ongoing security awareness training.
- D. Rely on the AI provider's independent audit reports (such as SOC 2) as the primary assurance mechanism.
Show the answer
Answer: C. Generative AI data security risk is most effectively reduced at the point of use by ensuring that employees understand what data is permissible to input, how the AI provider may use that data, and what the consequences of misuse are. Policies and training create behavioral controls that operate continuously, addressing the root-cause risk of sensitive data being inappropriately entered into AI tools. IP ownership guidelines (A) and opt-out provisions (B) are contractual provisions that do not prevent employees from inputting sensitive data in real time. Relying solely on vendor audit reports (D) provides assurance about the provider's posture but gives the organization no direct control over how its employees use the tool.
- A: IP guidelines address ownership disputes after the fact rather than preventing employees from exposing sensitive data through AI tool inputs.
- B: Opt-out provisions in contracts limit the provider's use of data but do not prevent employees from entering confidential or sensitive information into the AI system.
- D: Third-party audit reports validate the provider's controls, not the organization's own data-handling behaviors; this is a passive assurance mechanism rather than an active risk control.
Unlock the full 12-question sampler
All 12 come with the same written explanations the book uses, covering why the right answer is right. We email you the PDF, nothing else.
What you get
The sampler is free. Here is exactly what lands in your inbox.
Print it or work it on screen, then score yourself against the answer key.
Nothing is written for marketing. Every question is lifted from the study guide itself.
A few days later we send one email with a code for the full study guide. That is the entire sequence.
The full ISACA AAISM study guide
The complete guide covers the Advanced in AI Security Management (AAISM) exam objective by objective in plain English, with the full practice question bank behind these samples.
From $20.99
Simply Certified is an independent publisher. AAISM is a trademark of ISACA, which does not sponsor or endorse this product. This page and the sampler are independent study material and are not affiliated with, endorsed by, or sponsored by ISACA.