Key details for this exam, checked against the published exam outline
Each question shows the correct answer and an explanation of why it is right
An organization is implementing AI agent development across multiple engineering teams. Which of the following is the MOST important focus of AI-specific security training for developers?
For developer-facing, near-term hardening of AI agents, AAISM prioritizes secure agent design and runtime controls against prompt injection, unsafe memory/tool use, and tool-execution compromise. These are primary exploitation paths for agents that read external content, persist memory, and call tools with elevated privileges. Training must center on: guarding tool invocation, constraining memory scope, sanitizing/validating inputs, and isolating high-risk actions. Topics like bias/fairness (B) and policy/hallucinations (C) are important but are governance/assurance concerns; API abuse and plug-in risk (D) matter, yet the core, developer-controlled attack surface for agents is injection and unsafe tool/memory design.
Which of the following is the PRIMARY purpose of a dedicated AI system policy?
Per AAISM, an AI policy is a governance instrument that defines objectives, principles, roles, responsibilities, accountability, and control requirements for AI systems across their lifecycle. It establishes the framework within which performance, compliance, ethics, risk appetite, security, privacy, and sustainability objectives are set and operationalized. Environmental considerations (A), accuracy optimization (B), and regulatory compliance (D) are important outcomes addressed under the policy, but the primary purpose is to provide the overarching framework for objectives and controls.
An organization plans to use AI to analyze the shopping patterns of its customers to predict interests and send targeted, customized marketing emails. Which of the following should be done FIRST?
The first action, before any processing of personal data for AI-driven profiling and targeted communications, is to establish a lawful basis for processing. Under AAISM-aligned privacy governance, explicit and informed consent is prioritized for new or sensitive uses such as interest profiling and targeted marketing. Consent ensures purpose limitation, transparency, and user control prior to model ingestion and campaign activation. Training teams, updating terms of service, or verifying contact details are important, but they do not provide legal authority to process data; therefore, they follow after consent is obtained.
An organization is evaluating a SaaS-based HR system that uses AI for resume vetting. Which control is MOST important?
AAISM states that HR systems performing candidate evaluation must prioritize training data fairness, representativeness, and bias mitigation because biased HR decisions carry regulatory, ethical, and litigation risks.
Backups (B) and encryption (D) relate to availability and confidentiality, not fairness. Conformity assessments (C) are helpful but secondary.
An organization is adopting an agentic AI solution from an external vendor to support internal IT operations. Which of the following provides the MOST reliable and independently verifiable evidence of implemented security controls?
AAISM states that when evaluating external AI vendors, independently issued third-party audit reports (SOC, ISO, AI assurance assessments) provide the strongest evidence of implemented controls because they are objective, repeatable, and externally verified.
Peer reviews (A) lack formality, internal red-team reports (C) are non-independent, and whitepapers (D) are marketing documents without assurance value.
Which of the following controls BEST mitigates the risk of bias in AI models?
Bias in AI models primarily stems from limitations or imbalances in training data. The AAISM study materials emphasize that the most effective way to mitigate this risk is through diverse data sourcing strategies that ensure coverage across demographics, scenarios, and contexts. Access controls protect data security, not fairness. Data reconciliation ensures accuracy but does not address representational imbalance. Cryptographic hashing preserves integrity but has no impact on bias mitigation. To reduce systemic unfairness, the critical control is sourcing diverse and representative data.
AAISM Exam Content Outline -- AI Technologies and Controls (Bias and Fairness Management)
AI Security Management Study Guide -- Data Governance and Bias Reduction Strategies
Exam domains verified against: Official Isaca AAISM exam guide, last checked September 2026.
Advise stakeholders on implementing AI security solutions through appropriate policy, data governance, program management, and incident response. This covers stakeholder considerations, industry frameworks, regulatory requirements, AI strategies and policies, AI asset and data lifecycle management, AI security program development, and business continuity planning.
Assess and manage risks, threats, vulnerabilities, and supply chain issues related to enterprise-wide AI adoption. This includes risk assessment and treatment, threat and vulnerability identification, and vendor and supply chain management specific to AI systems.
Sample question from this domain above: Q5
Optimize AI security by applying security technologies, techniques, and controls tailored to AI systems. This covers AI security architecture and design, model lifecycle stages like selection and training, data management controls, privacy and ethical controls, and security monitoring.
Common questions about the exam itself