TechNuggets Academy

AI Governance and Program Management

Free ISACA Advanced in AI Security Management practice — 6 questions on AI Governance and Program Management, with explanations. No sign-up. Full 12-question mixed test →

Question 1 of 6 · Domain 1: AI Governance and Program Management
During a NIST AI RMF implementation, which function is primarily responsible for tracking, evaluating, and responding to AI risks on an ongoing basis after a system has been deployed into production?
The Manage function covers prioritizing, responding to, and continuously monitoring AI risks, including allocating resources to treat residual risk throughout deployment and operation.
Question 2 of 6 · Domain 1: AI Governance and Program Management
A financial services firm wants an independently auditable framework that can result in a formal, accredited certification of its AI management system, similar to how ISO/IEC 27001 certifies information security management systems. Which framework should the firm adopt to meet this specific need?
ISO/IEC 42001 defines requirements for an AI management system (AIMS) and is the standard organizations can be certified against by accredited third-party certification bodies.
Question 3 of 6 · Domain 1: AI Governance and Program Management
Under the EU AI Act, an organization deploys an AI system to automatically screen and rank job applicants' resumes before human recruiters review them. Under which risk classification does this system fall, and what is the PRIMARY obligation that follows?
The EU AI Act's Annex III explicitly classifies AI systems used in recruitment, including resume screening and candidate ranking, as high-risk, triggering obligations such as human oversight, conformity assessment, risk management, and technical documentation.
Question 4 of 6 · Domain 1: AI Governance and Program Management
A security team wants to systematically catalog and communicate adversary tactics and techniques that specifically target machine learning systems (e.g., model evasion, data poisoning) using the same threat-modeling discipline applied to enterprise IT via ATT&CK. Which resource should the team incorporate into the AI security program?
MITRE ATLAS is a knowledge base of adversary tactics, techniques, and case studies specifically targeting AI/ML systems, modeled on the structure of MITRE ATT&CK.
Question 5 of 6 · Domain 1: AI Governance and Program Management
An organization is retiring a legacy fraud-detection model that has been replaced by a newer version. Per AI asset lifecycle management best practice, which action is MOST important to include in the decommissioning procedure?
Proper decommissioning requires revoking access to eliminate shadow AI and attack surface, plus disposing of or retaining associated data in accordance with retention and legal hold requirements to avoid compliance violations or data leakage.
Question 6 of 6 · Domain 1: AI Governance and Program Management
During an active incident, a customer-facing LLM chatbot is discovered to be leaking internal system prompts and confidential data due to a successful prompt injection attack via a connected plugin. Which action should the AI incident response plan direct the team to take FIRST?
Immediate containment—disabling the compromised integration and rolling back to a known-good configuration—stops active data leakage first, consistent with containment-before-eradication IR principles applied to an AI-specific attack vector.
Ready for the real thing?

The full course: two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed explanations.

undefined $34.99 with code FREETEST33 — valid through Oct 6.

Get my $34.99 deal →