Browse all practice questions for the AAISM Domain 2 Practice Test. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

AAISM Domain 2 Practice Test 2026 – The Complete All-in-One Guide for Exam Success! course image
All questions

These questions are part of the practice quiz. Start practicing

  • Which threat modeling method is described as lacking specificity for AI threats and vulnerabilities, even though it works well with iterative AI development?
  • In reinforcement learning, what is the data structure that stores the estimated value of each state-action pair called?
  • What enables Deep Q-Networks to scale to complex environments instead of maintaining a Q-table?
  • In the NIST AI RMF, which activity covers risk being assessed, analyzed, or tracked?
  • Which model specializes in grid-like data such as images and uses convolutional layers?
  • Which threat modeling approach integrates risk assessment and risk prioritization with a structured modeling approach but is complex and lacks AI-specific threats?
  • Which of the following is included as a component of a fundamental rights impact assessment (FRIA)?
  • Security incidents or failures can result in what impact on the organization’s reputation?
  • Which term applies to machines that are aware of others' emotions and mental states and also their own?
  • Which term identifies the most probable category for a dataset based on probability-based predictions?
  • What term describes the practice of tampering with embedding matrices to skew a model's results?
  • Which cost category covers expenses associated with recovery from data breaches or service disruptions?
  • Data subjects can gain access to data that organizations have about them, including the ability to receive a copy of that information or direct access to the organization's database. Which right does this describe?
  • Which activity compares a model's performance with existing models or baselines to identify improvement opportunities?
  • Which statement best describes data storage and archiving practices?
  • Vendors beyond the third party within a relationship ecosystem (e.g., fourth-party, fifth-party) are referred to as which term?
  • Which term describes the vulnerability where vectors and embeddings used by RAG systems are inadequately protected?
  • Which term describes a neural network architecture where information moves forward in a single pass and is commonly used for image classification?
  • Which approach focuses on grouping data points into clusters based on similarity?
  • Which statement about the AI deployer is accurate?
  • Which simple supervised learning algorithm models the relationship between a dependent variable and independent variables by fitting a linear equation?
  • Which family of methods directly optimizes the policy mapping from states to actions?
  • Which term captures the risk of prompts revealing sensitive internal prompts or guardrails?
  • A common strategy for drawing information from multiple sources by extracting data from its home database, transforming and cleansing it to adhere to common data definitions, and then loading it into the data warehouse describes which process?
  • Which term refers to a set of rules that describe associations between items in large datasets?
  • Which term captures the general issue of LLMs producing false or misleading information that appears credible?
  • Which right states that data subjects have the right to be informed about how their data is collected and used?
  • Which threat modeling approach is described as easy to apply and understand, but lacks AI-specific sophistication?
  • Which threat modeling method is named for being Visual, Agile and Simple Threat?
  • Which model is designed for sequential data and can pass information from one step to the next?
  • Which term describes the inability to explain AI decisions and outcomes, a common concern in security and privacy contexts?
  • Nth Parties involves techniques that equip computers to emulate human behavior, enabling them to learn, make decisions, recognize patterns, and solve complex problems. Which term best describes this field?
  • In piloting, which elements should be included?
  • Which algorithm is commonly used for classification and predictive modeling and aims to find a separating hyperplane between classes?
  • Deep Learning leverages multiple layers of neural networks to extract high-level features from raw input data. Which option best matches this characteristic?
  • Which component is included in a data privacy impact assessment?
  • Which activity in the NIST AI RMF is about prioritizing risk and acting on it based on projected impact?
  • Which risk strategy means the costs of controls exceed the perceived value to be gained?
  • Which testing method evaluates a model's robustness by exposing it to extreme conditions or edge cases?
  • Which term describes a scenario where the model's outputs are inadequately sanitized before being used elsewhere, increasing risk to downstream systems?
  • In the NIST AI RMF, which activity involves recognizing the context and identifying risk related to it?
  • What risk occurs when prompts or instructions used to direct the model contain sensitive information or bypass guardrails?
  • Which model is described as Visual, Agile and Simple Threat?
  • Which term describes risk where data used to train or validate the model can be manipulated to embed backdoors or biases?
  • Which learning paradigm does not have a defined target variable?
  • In neural architecture search, which term describes the techniques used to search for target models, such as random search and Bayesian optimization?
  • Which term describes the techniques that enable computers to emulate human behavior, enabling them to learn, make decisions, recognize patterns, and solve complex problems?
  • In neural architecture search, which term defines the set of properties and constraints used to define the models to explore?
  • Which discriminative classifier has a margin-based objective and often performs well on small datasets?
  • Development-time threats are described as threats that arise during development due to security weaknesses not AI-specific. Which statement best captures this concept?
  • Which model-free reinforcement learning algorithm seeks to learn the value of state-action pairs and uses a Q-table to represent action values?
  • Which risk outcome indicates risk falls within acceptable limits and only monitoring is required?
  • Which term describes early AI systems that operate by reacting to inputs with limited functionality and do not use memory beyond brief experiences?
  • Which clustering approach starts with each data point as a separate cluster and merges them based on dissimilarity?
  • Which threat involves an attacker manipulating a model's parameters, architecture, or libraries to cause undesirable model behavior?
  • What does a privacy impact assessment (PIA) analyze?
  • In AI risk assessment, which assets should be prioritized for identification?
  • Which framework is noted for emphasizing asset identification as a key practice for AI and related data?
  • Which approach is essential for AI risk management to be effective?
  • Which term describes the evaluation designed to protect fundamental rights in AI systems?
  • Which of the following is NOT one of the four key areas of the NIST AI RMF?
  • Generative AI (GenAI) is best described as which of the following?
  • Generative AI models are trained on vast datasets and typically use which combination of learning methods?
  • Failure of systems designed to support business processes can lead to which outcome?
  • Which practice involves evaluating the AI solution in a real-world-like environment prior to full deployment?
  • Which term describes a multidisciplinary field that combines computer science, computer engineering, statistics, and other mathematics to analyze and meaningfully extract insights from large amounts of data?
  • Which risk approach involves moving the impact of risk to an external third party with associated costs?
  • How may cybercriminals utilize AI to enhance their attacks?
  • Which NAS component focuses on training and validating candidate models to compare and select the best one with cost efficiency in mind?
  • Where does computation and learning occur in a neural network?
  • Which data subject right allows individuals to know how their data is being collected and used, with whom it is shared, and how long it is retained?
  • What is model poisoning?
  • Intellectual Property Risk in AI-generated content is most accurately described as arising when which condition exists?
  • Which statement accurately identifies the purpose of a centralized AI database management?
  • Which statement best describes bias and fairness checks in AI governance?
  • Which approach uses neural networks to approximate Q-values for high-dimensional state spaces, instead of a Q-table?
  • Data subjects can request that their data no longer be processed in a certain way that they once approved, but they may still allow the organization to process the data in some fashion. Which right is this?
  • Which describes a complex collection of algorithms designed to mimic the way the human brain functions, with the goal of identifying patterns and making sense of the data?
  • Data subjects have the right to revoke consent, meaning the permission to use their information can be withdrawn and their data must be destroyed. Which right is this?
  • Which AI approach uses historical data and machine learning to forecast future events and trends?
  • Which term describes a basic neural network without cycles, designed for straightforward predictions?
  • Which term describes an organization that uses an AI product or service, directly or via its distribution to users?
  • AI provider refers to which entity?
  • Which neural network architecture features information flowing in one direction from the input layer to the output layer with no loops and is commonly used for image classification and regression tasks?
  • Which issue occurs when LLM outputs are not sufficiently validated or sanitized and are passed to other systems?
  • Which type of machine learning is trained by providing explicit examples of desired results, such as defective vs non-defective items?
  • Misinformation refers to LLMs producing false or misleading information that seems credible due to hallucinations.
  • Which term describes the risk as data used to train/validate being manipulated?
  • Development-time threats arise from security weaknesses not AI-specific and are associated with attack surfaces such as the engineering environment and supply chain. Which statement best characterizes these threats?
  • Which category describes chatbots that pose limited risk and require transparency?
  • Which method predicts the probability of an event based on independent variables and is commonly used for binary classification?
  • If a company's database includes incorrect information, data subjects have the right to request that it is corrected. Which right is this?
  • AI model inversion and related risk areas include focus on AI-specific categories such as multi-agent and environmental considerations. Which statement best describes this focus?
  • Which process involves extracting data from source systems, transforming it, and then loading it into a data warehouse?
  • What is the name of deep learning models that use a generator and a discriminator trained together and competing against each other?
  • Which threat modeling approach focuses on privacy concerns and can be used for data security but lacks AI-specific threats?
  • Which framework analyzes how personal information is collected, used, shared, and maintained within a defined scope, and is foundational in privacy governance?
  • Retrieval augmented generation with LLMs can reveal vulnerabilities due to how vectors and embeddings used to train the model are generated, stored, or retrieved.
  • Data Integrity Monitoring emphasizes which action?
  • Which linear model predicts a continuous outcome by fitting a linear equation?
  • Vendors that fourth-party vendors rely on, continuing the outsourcing chain, are called which party?
  • Which category includes AI systems that cannot materially harm an individual and pose limited risk, with transparency?
  • Which DL architecture uses a generator to create samples and a discriminator to evaluate them?
  • The inability to explain unexpected results from AI systems is a major concern for security professionals. Which concept describes this?
  • Which model family is known for handling nonlinear patterns by recursively splitting data into leaf nodes?
  • What is the primary purpose of bias and fairness checks?
  • Which supply chain party refers to vendors that fourth-party vendors rely on in the outsourcing chain?
  • Machines with a static memory repository for a fixed world rendition and dynamic memory for brief memories are known as what?
  • What is the term for training machine learning models to make a sequence of decisions?
  • What term describes when an attacker uses specific prompts to alter the behavior of an LLM model?
  • What does an access control review primarily monitor?
  • Which term refers to vendors or subcontractors a third-party vendor relies on (vendors of vendors)?
  • Which threat modeling method works well with iterative development common in AI solutions but lacks AI-specific threats?
  • What is the process of evaluating a model against predefined benchmarks, including metrics such as accuracy, precision, and recall?
  • Which limitation notes that some AI risk analyses fail to address AI-specific threats and challenges?
  • In the definitions, the AI provider refers to which entity?
  • Which term groups data points with similar characteristics into clusters?
  • Which AI category includes applications that manipulate behavior, violate rights, or engage in social scoring and are prohibited?
  • Which statement best reflects the potential consequences of the AI deployer role?
  • Which right allows data subjects to request that their data be destroyed after consent is revoked?
  • Which AI category focuses on autonomous decision making to optimize outcomes like customer satisfaction?
  • What term describes the risk that an organization's own employees may misuse AI systems to cause harm?
  • If a competitor steals training data or uses adversarial AI to disrupt services, what is a likely consequence for the enterprise?
  • In data ingestion, which aspect should be examined?
  • Where is the final prediction or result produced in a neural network?
  • Which concept implies machines that could eventually judge their own mental states as well as others'?
  • Which clustering technique partitions data by assigning points to the nearest centroid and requires specifying the number of clusters?
  • If enterprises operate AI solutions in a non-compliant manner with data privacy regulations or AI-related laws, what may be imposed?
  • MAESTRO refers to which entity in the AI deployment ecosystem?
  • In AI risk management, which practice is emphasized as central to identifying assets?
  • Intellectual Property Risk arises when which condition is present?
  • Which field is defined as a multidisciplinary domain that combines computer science, statistics, and visualization to analyze data and extract insights?
  • In dataflow mapping, which aspect should be considered when data is introduced?
  • Which threat modeling method provides a foundation for recognizing vulnerabilities related to the use of AI (e.g., data tampering or denial of service) but lacks AI-specific challenges?
  • Which term best describes an organization that designs, develops, tests, and deploys AI products or services?
  • Which risk strategy involves applying controls to bring risk within acceptable limits?
  • How can enterprises mitigate Intellectual Property Risk in AI-generated content?
  • What is the end result produced by hierarchical clustering?
  • What term describes when an LLM gains the ability to perform actions or call functions via prompts?
  • ML algorithms use which learning methods?
  • Which topic transforms high-dimensional data into a lower-dimensional space to simplify the data while retaining its essential features?
  • FRIA stands for what?
  • Which statement best describes Centralized AI database management?
  • Which technique reduces high-dimensional data to a lower-dimensional representation while preserving essential information?
  • Which class of models uses decision trees to capture nonlinear relationships and can be used for classification, regression, and feature selection?
  • Where does the neural network receive the input data?
  • Which risk arises when data used to train and validate the model is manipulated to introduce vulnerabilities?
  • Which classification method is commonly used to predict class probabilities for binary outcomes?
  • Which practice aligns with data privacy governance by encrypting, anonymizing, and controlling access?
  • AI agents capable of making autonomous decisions to achieve objectives like improving customer satisfaction are known as what?
  • When do runtime security threats occur?
  • What is the AI RMF described as?
  • What type of attack is specifically aimed at disrupting AI-powered services?
  • Deep Learning is defined as which of the following?
  • Which model is noted as being complex and having difficulty addressing internal systems and threats related to them?
  • Which regulation establishes a risk-based framework for AI governance in the European Union?
  • Which learning paradigm does not rely on labeled outcomes?
  • Which actor may use AI to advance its strategic interests, including cyber espionage, surveillance, or warfare?
  • In hierarchical clustering, which approach is the counterpart to agglomerative clustering that starts with a single cluster and splits based on dissimilarities?
  • Which stakeholder group is described as potentially creating AI solutions that do not align with widely accepted ethical standards?
  • The European Union AI Act applies to which entities?
  • Which right allows individuals to limit processing of their data to specific purposes or to pause processing under certain conditions?
  • Which category has AI systems with little or no regulatory oversight, such as spam filters?
  • Which term describes the entities an AI provider directly contracts or collaborates with, such as data providers, model developers, or cloud service providers?
  • Which term captures exposure of personally identifiable information due to use of an LLM?
  • Which term refers to the practice of manipulating embedding representations to distort a model's output?
  • Which term uncovers how items within large datasets are associated with each other and reveals the probability of relationships between data items?
  • Which practice ensures equity across user populations by evaluating model behavior in diverse scenarios?
  • MAESTRO stands for Multi-Agent Environment, Security, Threat Risk, and Outcome and refers to which entity?
  • Which term describes the task of predicting a continuous outcome from a dataset?
  • Which statistical method reduces dimensionality by transforming variables into uncorrelated principal components that capture maximum variance, with the first component explaining the most variance?
  • Which right ensures that once consent is withdrawn, data processing can be ceased, potentially resulting in data deletion?
  • Which statement best describes the primary objective of model testing?
  • Which field uses supervised or unsupervised learning methods to detect patterns in large datasets, allowing machines to learn and adapt?
  • Which practice is explicitly described for data storage and archiving?
  • Which clustering method initializes with K centroids and assigns each point to the nearest centroid?
  • A system that manipulates human behavior in a way that could cause severe harm is categorized as which risk?
  • Unbounded consumption occurs when an LLM enables end users to make excessive inferences, which can lead to denial of service errors and financial loss.
  • Which concept encompasses the creation of machines capable of understanding and mimicking human thought patterns and decision-making processes?
  • Which AI system is one of the earliest forms that automatically generates responses to a limited set of inputs and has limited functionality?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy