✅ Free practice — no sign-up📝 Real exam-style questions💡 Detailed explanations💸 30-day money-back via Udemy
Question 1 of 12 · Domain 1: AI Governance and Program Management
A financial services firm deploys an AI system in the EU that evaluates consumers' creditworthiness and determines loan eligibility. Under the EU AI Act, how should this AI system be classified, and what does that classification require?
The EU AI Act explicitly lists credit scoring/creditworthiness assessment of natural persons in Annex III as a high-risk use case, triggering obligations including conformity assessment, technical documentation, risk management systems, logging, and human oversight before and during deployment.
Question 2 of 12 · Domain 2: AI Risk Management
An enterprise risk appetite statement states that risks rated 'Low' are accepted without additional controls, while risks rated 'Medium' or higher require documented treatment before go-live. A pre-deployment AI risk assessment rates a customer-facing LLM chatbot's exposure to prompt injection leading to sensitive data disclosure as 'Medium.' Which treatment approach BEST aligns with the stated risk appetite?
The appetite statement requires documented treatment for Medium+ risks. Mitigation via layered controls (input/output filtering, prompt hardening) directly reduces likelihood/impact of prompt injection to bring residual risk within tolerance, which is the standard treatment path an AI security manager applies before acceptance.
Question 3 of 12 · Domain 3: AI Technologies and Controls
A company deploys a RAG-based chatbot that retrieves from multiple internal data sources with different sensitivity levels, including HR salary records and public product documentation. Employees without HR clearance report receiving salary data in chatbot answers. Which control BEST addresses this issue?
Retrieval-time access control filtering (retrieval-augmented generation authorization) ensures the model only ever receives documents the requesting user is authorized to see, eliminating the leakage path regardless of prompt content.
Question 4 of 12 · Domain 1: AI Governance and Program Management
A CISO wants to first establish organizational culture, roles, accountability structures, and policies for managing AI risk before conducting detailed risk identification for specific AI systems. Which NIST AI Risk Management Framework function does this activity primarily belong to?
The Govern function of the NIST AI RMF is cross-cutting and foundational — it addresses culture, policies, roles, accountability, and processes for AI risk management across the organization, and is intended to be established before or alongside the other functions.
Question 5 of 12 · Domain 2: AI Risk Management
During a security review, an attacker submits thousands of carefully varied queries to a deployed image-classification API and uses the returned confidence scores to reconstruct a functionally equivalent copy of the underlying proprietary model. Which adversarial technique does this describe?
Model extraction (query-synthesis/model-stealing) involves systematically querying an exposed inference API to reconstruct model parameters or a functional surrogate, matching the MITRE ATLAS technique 'Exfiltration via ML Model Inference API' — a core mapped threat in AAISM threat-and-vulnerability content.
Question 6 of 12 · Domain 3: AI Technologies and Controls
An agentic AI assistant has been granted a single service account with broad administrative permissions across ticketing, email, and cloud infrastructure so it can complete multi-step tasks autonomously. The security team wants to reduce the blast radius if the agent is manipulated through prompt injection. Which control is MOST appropriate?
Least-privilege, scoped credentials per tool combined with human-in-the-loop approval for high-impact actions directly limits what a compromised or manipulated agent can do, which is the core mitigation for excessive agency in agentic AI systems.
Question 7 of 12 · Domain 1: AI Governance and Program Management
During a model retraining cycle, a security team discovers that a portion of the training dataset was subtly manipulated by an external contributor, causing the model to misclassify a specific category of inputs. Which approach BEST supports organizational readiness to respond to this type of AI-specific incident?
AAISM guidance emphasizes integrating AI-specific incident types (data poisoning, model drift/behavior anomalies, adversarial input attacks, model theft) into the existing enterprise incident response process through dedicated playbooks and escalation criteria, rather than building a parallel, siloed process.
Question 8 of 12 · Domain 2: AI Risk Management
A security manager is negotiating a contract with a foundation-model provider that will host the organization's fine-tuning workloads. From a security-risk perspective, which contractual clause is MOST important to secure before onboarding?
The data-usage/training-data clause directly governs whether confidential or regulated organizational data could leak into the vendor's shared model weights or be exposed to other tenants, making it the primary security-relevant term in AI vendor risk management per AAISM guidance on foundation-model provider evaluation.
Question 9 of 12 · Domain 3: AI Technologies and Controls
Which control is MOST effective at detecting and blocking adversarial prompt injection attempts before they reach the underlying LLM in a production deployment?
An input guardrail/prompt-shield layer intercepts and inspects prompts before they reach the model, allowing detection and blocking of injection patterns pre-execution, which is the recommended defensive layer for this threat.
Question 10 of 12 · Domain 1: AI Governance and Program Management
A security program manager is designing the data fields to capture in the organization's AI asset inventory to support security risk assessment and audit readiness. Which element is MOST important to include?
AI asset and data lifecycle management requires tracking provenance (source and history of training data), model versioning, and lineage so security teams can assess exposure to poisoning, licensing/IP risk, drift, and support incident investigation and audit trails.
Question 11 of 12 · Domain 2: AI Risk Management
An organization operates a recommendation model that retrains nightly on unvalidated user click-feedback data with no anomaly screening or human review of the training set. The security team must prioritize which threat to address first. Which threat should receive the HIGHEST priority?
The described architecture — automated nightly retraining on unvalidated, user-controllable feedback with no anomaly screening — creates a direct, low-effort attack surface for data poisoning, where adversaries can persistently and cumulatively corrupt the model's behavior. This is the most exploitable and highest-impact threat given the described control gap, so it should be prioritized first per AAISM threat-prioritization guidance.
Question 12 of 12 · Domain 3: AI Technologies and Controls
An AI system autonomously approves loan applications under $5,000 but organizational policy requires human review for higher-risk decisions. Which configuration best implements risk-tiered human oversight at critical decision points?
A risk-tiered oversight model routes higher-consequence decisions to human reviewers while allowing automation for low-risk cases, balancing efficiency with accountability at genuinely critical decision points, which is the AAISM-recommended approach to human oversight.
Ready for the real thing?
The full course: two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed explanations.
undefined$34.99 with code FREETEST33 — valid through Oct 6.
The exam fee is approximately $599 and varies by region — confirm current pricing with the certification vendor before you book.
What topics are on the exam?
It covers 3 domains: AI Governance and Program Management (31%), AI Risk Management (31%), AI Technologies and Controls (38%). The full course has a dedicated chapter, lab and practice-test coverage for each.
Is this practice test really free?
Yes — all questions on this page are free with explanations and no sign-up. The paid Udemy course adds two full-length timed exams, video lessons and hands-on labs.
How do I get the discount?
Use code FREETEST33 at checkout for $34.99 (list undefined) through Oct 6 — the enroll button applies it automatically.
Will this prepare me for the real exam?
The questions mirror the real exam's style and are mapped to the official domains. This is exam-focused preparation — combine the free test with the full course's timed simulations to gauge your readiness.