New Year Sale Discount Flat 70% Offer - Ends in 0d 00h 00m 00s - Coupon code: 70diswrap

IAPP AIGP Dumps

Page: 1 / 17
Total 165 questions

Artificial Intelligence Governance Professional Questions and Answers

Question 1

CASE STUDY

Please use the following answer the next question:

XYZ Corp., a premier payroll services company that employs thousands of people globally, is embarking on a new hiring campaign and wants to implement policies and procedures to identify and retain the best talent. The new talent will help the company's product team expand its payroll offerings to companies in the healthcare and transportation sectors, including in Asia.

It has become time consuming and expensive for HR to review all resumes, and they are concerned that human reviewers might be susceptible to bias.

Address these concerns, the company is considering using a third-party Al tool to screen resumes and assist with hiring. They have been talking to several vendors about possibly obtaining a third-party Al-enabled hiring solution, as long as it would achieve its goals and comply with all applicable laws.

The organization has a large procurement team that is responsible for the contracting of technology solutions. One of the procurement team's goals is to reduce costs, and it often prefers lower-cost solutions. Others within the company are responsible for integrating and deploying technology solutions into the organization's operations in a responsible, cost-effective manner.

The organization is aware of the risks presented by Al hiring tools and wants to mitigate them. It also questions how best to organize and train its existing personnel to use the Al hiring tool responsibly. Their concerns are heightened by the fact that relevant laws vary across jurisdictions and continue to change.

Which other stakeholder groups should be involved in the selection and implementation of the Al hiring tool?

Options:

A.

Finance and Legal.

B.

Marketing and Compliance.

C.

Supply Chain and Marketing.

D.

Litigation and Product Development.

Question 2

Random forest algorithms are in what type of machine learning model?

Options:

A.

Symbolic.

B.

Generative.

C.

Discriminative.

D.

Natural language processing.

Question 3

CASE STUDY

Please use the following answer the next question:

XYZ Corp., a premier payroll services company that employs thousands of people globally, is embarking on a new hiring campaign and wants to implement policies and procedures to identify and retain the best talent. The new talent will help the company's product team expand its payroll offerings to companies in the healthcare and transportation sectors, including in Asia.

It has become time consuming and expensive for HR to review all resumes, and they are concerned that human reviewers might be susceptible to bias.

Address these concerns, the company is considering using a third-party Al tool to screen resumes and assist with hiring. They have been talking to several vendors about possibly obtaining a third-party Al-enabled hiring solution, as long as it would achieve its goals and comply with all applicable laws.

The organization has a large procurement team that is responsible for the contracting of technology solutions. One of the procurement team's goals is to reduce costs, and it often prefers lower-cost solutions. Others within the company are responsible for integrating and deploying technology solutions into the organization's operations in a responsible, cost-effective manner.

The organization is aware of the risks presented by Al hiring tools and wants to mitigate them. It also questions how best to organize and train its existing personnel to use the Al hiring tool responsibly. Their concerns are heightened by the fact that relevant laws vary across jurisdictions and continue to change.

The frameworks that would be most appropriate for XYZ's governance needs would be the NIST Al Risk Management Framework and?

Options:

A.

NIST Information Security Risk (NIST SP 800-39).

B.

NIST Cyber Security Risk Management Framework (CSF 2.0).

C.

IEEE Ethical System Design Risk Management Framework (IEEE 7000-21).

D.

Human Rights, Democracy, and Rule of Law Impact Assessment (HUDERIA).

Question 4

Which of the following disclosures is NOT required for an EU organization that developed and deployed a high-risk Al system?

Options:

A.

The human oversight measures employed.

B.

How an individual may contest a decision.

C.

The location(s) where data is stored.

D.

The fact that an Al system is being used.

Question 5

CASE STUDY

A company is considering the procurement of an AI system designed to enhance the security of IT infrastructure. The AI system analyzes how users type on their laptops, including typing speed, rhythm and pressure, to create a unique user profile. This data is then used to authenticate users and ensure that only authorized personnel can access sensitive resources.

The data processed by the AI system would be classified as:

Options:

A.

Non-sensitive personal data, since it does not reveal information about health, gender or race

B.

Organizational data, since it is part of the authentication process

C.

Non-personal data, as long as it is not linked to a user ID

D.

Special category data, if it can be used to uniquely identify a person

Question 6

CASE STUDY

Please use the following answer the next question:

ABC Corp, is a leading insurance provider offering a range of coverage options to individuals. ABC has decided to utilize artificial intelligence to streamline and improve its customer acquisition and underwriting process, including the accuracy and efficiency of pricing policies.

ABC has engaged a cloud provider to utilize and fine-tune its pre-trained, general purpose large language model (“LLM”). In particular, ABC intends to use its historical customer data—including applications, policies, and claims—and proprietary pricing and risk strategies to provide aninitial qualificationassessment of potential customers, which would then be routed a human underwriter for final review.

ABC and the cloud provider have completed training and testing the LLM, performed a readiness assessment, and made the decision to deploy the LLM into production. ABC has designated an internal compliance team to monitor the model during the first month, specifically to evaluate the accuracy, fairness, and reliability of its output. After the first month in production, ABC realizes that the LLM declines a higher percentage of women's loan applications due primarily to women historically receiving lower salaries than men.

What is the best strategy to mitigate the bias uncovered in the loan applications?

Options:

A.

Retrain the model with data that reflects demographic parity.

B.

Procure a third-party statistical bias assessment tool.

C.

Document all instances of bias in the data set.

D.

Delete all gender-based data in the data set.

Question 7

Scenario:

A European AI technology company was found to be non-compliant with certain provisions of the EU AI Act. The regulator is considering penalties under the enforcement provisions of the regulation.

According to the EU AI Act, which of the following non-compliance examples could lead to fines of up to €15 million or 3% of annual worldwide turnover(whichever is higher)?

Options:

A.

In case of AI Act prohibitions

B.

In case of breach of a provider's obligations for high-risk AI systems

C.

In case of the supply of misleading information to notified bodies in reply to a request

D.

In case of a breach of AI Act prohibition by the Union institutions, bodies, offices and agencies

Question 8

Scenario:

A large multinational organization is rolling out a company-wide AI governance initiative. To build awareness and support adoption, they are evaluating different ways to train employees and stakeholders across departments, including legal, technical, marketing, and customer-facing roles.

Which of the following typical approaches is a largeorganization leastlikely touse to responsibly train stakeholders on AI terminology, strategy and governance?

Options:

A.

Providing all technical employees education on AI development so they can retool and participate in the development of AI systems

B.

Providing training on AI ethics, based on the extent to which the organization seeks to promote a responsible AI culture

C.

Providing role-specific training, based on whether the organization uses a centralized, federated or decentralized governance model

D.

Providing information and education to customers and users to understand the capabilities and limitations of the AI tools with which they interact

Question 9

CASE STUDY

A company is considering the procurement of an AI system designed to enhance the security of IT infrastructure. The AI system analyzes how users type on their laptops, including typing speed, rhythm and pressure, to create a unique user profile. This data is then used to authenticate users and ensure that only authorized personnel can access sensitive resources.

When prioritizing the updates to its policies, rules and procedures to include the new AI system for user authentication, the organization should:

Options:

A.

Update third-party data sharing policies

B.

Update security controls for sensitive data

C.

Ensure that any personal data used is only processed for a specific and lawful purpose

D.

Reduce the complexity of the policy to make it easier for non-technical employees to understand

Question 10

What is the primary purpose of an Al impact assessment?

Options:

A.

To define and evaluate the legal risks associated with developing an Al system.

B.

Anticipate and manage the potential risks and harms of an Al system.

C.

To define and document the roles and responsibilities of Al stakeholders.

D.

To identify and measure the benefits of an Al system.

Question 11

An Al system that maintains its level of performance within defined acceptable limits despite real world or adversarial conditions would be described as?

Options:

A.

Robust.

B.

Reliable.

C.

Resilient.

D.

Reinforced.

Question 12

CASE STUDY

A premier payroll services company that employs thousands of people globally, is embarking on a new hiring campaign and wants to implement policies and procedures to identify and retain the best talent. The new talent will help the company's product team expand its payroll offerings to companies in the healthcare and transportation sectors, including in Asia.

It has become time consuming and expensive for HR to review all resumes, and they are concerned that human reviewers might be susceptible to bias.

To address these concerns, the company is considering using a third-party Al tool to screen resumes and assist with hiring. They have been talking to several vendors about possibly obtaining a third-party Al-enabled hiring solution, as long as it would achieve its goals and comply with all applicable laws.

The organization has a large procurement team that is responsible for the contracting of technology solutions. One of the procurement team's goals is to reduce costs, and it often prefers lower-cost solutions. Others within the company deploy technology solutions into the organization’s operations in a responsible, cost-effective manner.

The organization is aware of the risks presented by Al hiring tools and wants to mitigate them. It also questions how best to organize and train its existing personnel to use the Al hiring tool responsibly. Their concerns are heightened by the fact that relevant laws vary across jurisdictions and continue to change.

The organization continues planning the adoption of an AI tool to support hiring, but is concerned about potential bias in content generated by AI systems and how that could affect public perception.

Which of the following measures should the company adopt tobest mitigate its risk of reputational harmfrom using the AI tool?

Options:

A.

Test the AI tool pre- and post-deployment

B.

Ensure the vendor provides indemnification for the AI tool

C.

Require the procurement and deployment teams to agree upon the AI tool

D.

Continue to require the company’s hiring personnel to manually screen all applicants

Question 13

Scenario:

A company is using different types of AI systems to enhance consumer engagement. These include chatbots, recommendation engines, and automated content generation tools.

Which of the following situations would beleast likelyto raise concerns under existing consumer protection laws?

Options:

A.

An AI algorithm being used in a credit decision-making process by a financial institution

B.

An AI customer service system claiming that it is as accurate as a human support agent

C.

An AI tool using scraped digital content to generate news summaries on a publishing website

D.

An online platform offering recommendations to its users by displaying user-specific content and targeted advertisements

Question 14

Scenario:

An organization is building a compliance program to ensure responsible AI deployment. It aims to align operations with AI risk frameworks and mitigate legal, ethical, and operational risks, while still promoting innovation.

Which of the following would be theleast likelystep for an organization to take when designing an integrated compliance strategy for responsible AI?

Options:

A.

Meeting with and obtaining approval from senior management

B.

Launching a survey to understand the concerns and interests of potentially impacted stakeholders

C.

Consulting experts to consider the ethical principles underpinning the use of AI within the organization

D.

Employing a new software platform to modernize existing compliance processes across the organization

Question 15

What is the key feature of Graphical Processing Units (GPUs) that makes them well-suited to running Al applications?

Options:

A.

GPUs run many tasks concurrently, resulting in faster processing.

B.

GPUs can access memory quickly, resulting in lower latency than CPUs.

C.

GPUs can run every task on a computer, making them more robust than CPUs.

D.

The number of transistors on GPUs doubles every two years, makingthe chipssmaller and lighter.

Question 16

What is theprimary purposeof an AI impact assessment?

Options:

A.

To determine whether a conformity assessment is needed

B.

To escalate the findings to the appropriate owner(s)

C.

To identify and measure the benefits of an AI system

D.

To anticipate and manage the potential risks and harms of an AI system

Question 17

Scenario:

An organization wants to leverage its existing compliance structures to identify AI-specific risks as part of an ongoing data governance audit.

Which of the following compliance-related controls within an organization ismost easily adaptedto identify AI risks?

Options:

A.

Privacy training

B.

Penetration testing

C.

Transfer risk assessments

D.

Privacy impact assessments

Question 18

A Canadian company is developing an Al solution to evaluate candidates in the course of job interviews.

Before offering the Al solution in the EU market, the company must take all of the following steps EXCEPT?

Options:

A.

Register the Al solution in a public EU database.

B.

Establish a risk and quality management system.

C.

Engage a third-party auditor to perform a bias audit.

D.

Draw up technical documentation and instructions for use.

Question 19

According to the GDPR's transparency principle, when an Al system processes personal data in automated decision-making, controllers are required to provide data subjects specific information on?

Options:

A.

The existence of automated decision-making and meaningful information on its logic and consequences.

B.

The personal data used during processing, including inferences drawn by the Al system about the data.

C.

The data protection impact assessments carried out on the Al system and legal bases for processing.

D.

The contact details of the data protection officer and the data protection national authority.

Question 20

An EU bank intends to launch a multi-modal Al platform for customer engagement and automated decision-making assist with the opening of bank accounts. The platform has been subject to thorough risk assessments and testing, where it proves to be effective in not discriminating against any individual on the basis of a protected class.

What additional obligations must the bank fulfill prior to deployment?

Options:

A.

The bank must obtain explicit consent from users under the privacy Directive.

B.

The bank must disclose how the Al system works under the Ell Digital Services Act.

C.

The bank must subject the Al system an adequacy decision and publish its appropriate safeguards.

D.

The bank must disclose the use of the Al system and implement suitable measures for users to contest automated decision-making.

Question 21

Scenario:

An enterprise is evaluating multiple third-party generative AI tools to integrate into its platform. As part of its AI governance policy, it is assessing themost effective methodsto reduce risks related to bias, data misuse, and liability when using third-party solutions.

All of the following are commonly adopted processes and policies in reducing potential risks introduced by third-party AI tools or applications EXCEPT:

Options:

A.

Including clauses in the procurement agreement for buyers of generative AI tools to put certain liabilities on the tool supplier

B.

Allowing publicly available information and personally identifiable information (PII) to be incorporated into the prompt

C.

Requiring an independent third-party bias audit for third-party generative AI tools

D.

Requiring new use cases of the generative AI tools or applications to be reviewed and approved by the generative AI governance body

Question 22

Scenario:

An organization is developing a powerful general-purpose AI (GPAI) model that has systemic impact. The compliance team is assessing what legal obligations apply under the EU AI Act.

Under the EU AI Act, which of the following compliance actions appliesonly to General Purpose AI models with systemic risk?

Options:

A.

Publishing a detailed summary of the data used to train the model

B.

Maintaining up-to-date technical documentation, including testing details

C.

Implementing an intellectual property policy to comply with EU copyright laws

D.

Making information available to downstream providers who integrate the model into their AI systems

Question 23

Each of the following actors are typically engaged in the Al development life cycle EXCEPT?

Options:

A.

Data architects.

B.

Government regulators.

C.

Socio-cultural and technical experts.

D.

Legal and privacy governance experts.

Question 24

Scenario:

An organization is evaluating different AI models for integration into its internal workflows. Before moving forward with a particular AI solution from a third-party vendor, the governance team needs to assess the ethical and operational implications of the model.

The most important policy to assess the operations of an AI model is to follow the:

Options:

A.

Acceptable use policy of the model provider

B.

Privacy policy of the model provider

C.

Security policy of the model provider

D.

Code of conduct policy of the model provider

Question 25

A US company has developed an Al system,Crime Buster9619, that collects information about incarcerated individuals to help parole boards predict whether someone is likely to commit another crime if released from prison.

When considering expanding to the EU market, this type of technology would?

Options:

A.

Require the company to register the tool with the EU database.

B.

Be subject approval by the relevant EU authority.

C.

Require a detailed conformity assessment.

D.

Be banned under the EU Al Act.

Question 26

Which of the following is the least relevant consideration in assessing whether users should be given the right to opt out from an Al system?

Options:

A.

Feasibility.

B.

Risk to users.

C.

Industry practice.

D.

Cost of alternative mechanisms.

Question 27

Which type of existing assessment could best be leveraged to create an Al impact assessment?

Options:

A.

A safety impact assessment.

B.

A privacy impact assessment.

C.

A security impact assessment.

D.

An environmental impact assessment.

Question 28

CASE STUDY

Please use the following answer the next question:

A local police department in the United States procured an Al system to monitor and analyze social media feeds, online marketplaces and other sources of public information to detect evidence of illegal activities (e.g., sale of drugs or stolen goods). The Al system works by surveilling the public sites in order to identify individuals that are likely to have committed a crime. It cross-references the individuals against data maintained by law enforcement and then assigns a percentage score of the likelihood of criminal activity based on certain factors like previous criminal history, location, time, race and gender.

The police department retained a third-party consultant assist in the procurement process, specifically to evaluate two finalists. Each of the vendors provided information about their system's accuracy rates, the diversity of their training data and how their system works. The consultant determined that the first vendor’s system has a higher accuracy rate and based on this information, recommended this vendor to the police department.

The police department chose the first vendor and implemented its Al system. As part of the implementation, the department and consultant created a usage policy for the system, which includes training police officers on how the system works and how to incorporate it into their investigation process.

The police department has now been using the Al system for a year. An internal review has found that every time the system scored a likelihood of criminal activity at or above 90%, the police investigation subsequently confirmed that the individual had, in fact, committed a crime. Based on these results, the police department wants to forego investigations for cases where the Al system gives a score of at least 90% and proceed directly with an arrest.

Which Al risk would NOT have been identified during the procurement process based on the categories of information requested by the third-party consultant?

Options:

A.

Security.

B.

Accuracy.

C.

Explainability.

D.

Discrimination.

Question 29

MULTI-SELECT

Please select 3 of the 5 options below. No partial credit will be given.

Training an AI model is time-consuming because of?

Options:

A.

The complexity of the AI model.

B.

The maturity of AI governance.

C.

The volume of training data.

D.

The number of stakeholders.

E.

The quality of the training data.

Question 30

What is the most important factor when deciding whether or not to select a proprietary AI model?

Options:

A.

What business purpose it will serve.

B.

How frequently it will be updated.

C.

Whether its training data is disclosed.

D.

Whether its system card identifies risks.

Question 31

The planning phase of the Al life cycle articulates all of the following EXCEPT the?

Options:

A.

Objective of the model.

B.

Approach to governance.

C.

Choice of the architecture.

D.

Context in which the model will operate.

Question 32

The White House Executive Order from November 2023 requires companies that develop dual-use foundation models to provide reports to the federal government about all of the following EXCEPT?

Options:

A.

Any current training or development of dual-use foundation models.

B.

The results of red-team testing of each dual-use foundation model.

C.

Any environmental impact study for each dual-use foundation model.

D.

The physical and cybersecurity protection measures of their dual-use foundation models.

Question 33

During the development of semi-autonomous vehicles, various failures occurred as a result of the sensors misinterpreting environmental surroundings, such as sunlight.

These failures are an example of?

Options:

A.

Hallucination.

B.

Brittleness.

C.

Uncertainty.

D.

Forgetting.

Question 34

The best practice to manage third-party risk associated with AI systems is to create and implement policies that?

Options:

A.

Focus on the financial stability of third-party vendors as the primary criterion for risk assessment.

B.

Provide for an appropriate level of due diligence and ongoing monitoring based on the defined risk.

C.

Require third-party AI systems to undergo a comprehensive audit by an external cybersecurity firm every six months.

D.

Focus on the technical aspects of AI systems, such as data security, while ethical risks are addressed through suitable contracts.

Question 35

A deployer discovers that a high-risk AI recruiting system has been making widespread errors, resulting in harms to the rights of a considerable number of EU residents who are denied consideration for jobs for improper reasons such as ethnicity, gender and age.

According to the EU AI Act, what should the company do first?

Options:

A.

Notify the provider, the distributor, and finally the relevant market authority of the serious incident.

B.

Identify any decisions that may have been improperly made and re-open them for human review.

C.

Submit an incomplete report to the relevant market authority immediately and follow up with a complete report as soon as possible.

D.

Conduct a thorough investigation of the serious incident within the 15 day timeline and present the completed report to the relevant market authority.

Question 36

An AI system's function, the industry and the location in which it operates are important factors in considering which of the following?

Options:

A.

Organizational accountability.

B.

Internal governance needs.

C.

Diversity of data sources.

D.

Explainability of results.

Question 37

Your organization is searching for a new way to help accurately forecast sales predictions by various types of customers.

Which of the following is the best type of model to choose if your organization wants to customize the model and avoid lock-in?

Options:

A.

A free large language model.

B.

A classic machine learning model.

C.

A proprietary generative AI model.

D.

A subscription-based, multimodal model.

Question 38

Which model is best for efficiency and agility, and tailored for lower-resource settings?

Options:

A.

Supervised learning model.

B.

Multimodal model.

C.

Small language model.

D.

Generative language model.

Question 39

Testing data is defined as a subset of data that is used to?

Options:

A.

Assess a model's on-going performance in production.

B.

Enable a model to discover and learn patterns.

C.

Provide a robust evaluation of a final model.

D.

Evaluate a model’s handling of randomized edge cases.

Question 40

You are the chief privacy officer of a medical research company that would like to collect and use sensitive data about cancer patients, such as their names, addresses, race and ethnic origin, medical histories, insurance claims, pharmaceutical prescriptions, eating and drinking habits and physical activity.

The company will use this sensitive data to build an Al algorithm that will spot common attributes that will help predict if seemingly healthy people are more likely to get cancer. However, the company is unable to obtain consent from enough patients to sufficiently collect the minimum data to train its model.

Which of the following solutions would most efficiently balance privacy concerns with the lack of available data during the testing phase?

Options:

A.

Deploy the current model and recalibrate it over time with more data.

B.

Extend the model to multi-modal ingestion with text and images.

C.

Utilize synthetic data to offset the lack of patient data.

D.

Refocus the algorithm to patients without cancer.

Question 41

When monitoring the functional performance of a model that has been deployed into production, all of the following are concerns EXCEPT?

Options:

A.

Feature drift.

B.

System cost.

C.

Model drift.

D.

Data loss.

Question 42

The best method to ensure a comprehensive identification of risks for a new AI model is?

Options:

A.

An environmental scan.

B.

Red teaming.

C.

Integration testing.

D.

An impact assessment.

Question 43

What is the main purpose of accountability structures under the Govern function of the NIST Al Risk Management Framework?

Options:

A.

To empower and train appropriate cross-functional teams.

B.

To establish diverse, equitable and inclusive processes.

C.

To determine responsibility for allocating budgetary resources.

D.

To enable and encourage participation by external stakeholders.

Question 44

A company has trained an ML model primarily using synthetic data, and now intends to use live personal data to test the model.

Which of the following is NOT a best practice apply during the testing?

Options:

A.

The test data should be representative of the expected operational data.

B.

Testing should minimize human involvement to the extent practicable.

C.

The test data should be anonymized to the extent practicable.

D.

Testing should be performed specific to the intended uses.

Question 45

Please select 3 of the 5 options below. No partial credit will be given.

All of the following are unique characteristics of AI that require a comprehensive approach to governance EXCEPT?

Options:

A.

Autonomy.

B.

Automation.

C.

Adaptability.

D.

Speed and scale.

E.

Superintelligence.

Question 46

All of the following are elements of establishing a global Al governance infrastructure EXCEPT?

Options:

A.

Providing training to foster a culture that promotes ethical behavior.

B.

Creating policies and procedures to manage third-partyrisk.

C.

Understanding differences in norms across countries.

D.

Publicly disclosing ethical principles.

Question 47

What is the best method to proactively train an LLM so that there is mathematical proof that no specific piece of training data has more than a negligible effect on the model or its output?

Options:

A.

Clustering.

B.

Transfer learning.

C.

Differential privacy.

D.

Data compartmentalization.

Question 48

A US-based mortgage lender has purchased a chatbot. They plan to have the chatbot collect information from consumers who are interested in loans and offer the consumers 2-3 different options based on its current pricing and product offerings, which change frequently. This chatbot was initially developed and previously deployed by a Russian airline for booking flights.

The best option for the part of the process that generates the loan offers is?

Options:

A.

Retrieval-Augmented Generation.

B.

Multimodal Generative AI.

C.

Expert System.

D.

Quantum computing

Question 49

Which of the following steps occurs in the design phase of the Al life cycle?

Options:

A.

Data augmentation.

B.

Model explainability.

C.

Risk impact estimation.

D.

Performance evaluation.

Page: 1 / 17
Total 165 questions