Weekend Sale - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmaspas7

Easiest Solution 2 Pass Your Certification Exams

AIGP IAPP Artificial Intelligence Governance Professional Free Practice Exam Questions (2025 Updated)

Prepare effectively for your IAPP AIGP Artificial Intelligence Governance Professional certification with our extensive collection of free, high-quality practice questions. Each question is designed to mirror the actual exam format and objectives, complete with comprehensive answers and detailed explanations. Our materials are regularly updated for 2025, ensuring you have the most current resources to build confidence and succeed on your first attempt.

Page: 2 / 3
Total 164 questions

CASE STUDY

Please use the following answer the next question:

XYZ Corp., a premier payroll services company that employs thousands of people globally, is embarking on a new hiring campaign and wants to implement policies and procedures to identify and retain the best talent. The new talent will help the company's product team expand its payroll offerings to companies in the healthcare and transportation sectors, including in Asia.

It has become time consuming and expensive for HR to review all resumes, and they are concerned that human reviewers might be susceptible to bias.

Address these concerns, the company is considering using a third-party Al tool to screen resumes and assist with hiring. They have been talking to several vendors about possibly obtaining a third-party Al-enabled hiring solution, as long as it would achieve its goals and comply with all applicable laws.

The organization has a large procurement team that is responsible for the contracting of technology solutions. One of the procurement team's goals is to reduce costs, and it often prefers lower-cost solutions. Others within the company are responsible for integrating and deploying technology solutions into the organization's operations in a responsible, cost-effective manner.

The organization is aware of the risks presented by Al hiring tools and wants to mitigate them. It also questions how best to organize and train its existing personnel to use the Al hiring tool responsibly. Their concerns are heightened by the fact that relevant laws vary across jurisdictions and continue to change.

The frameworks that would be most appropriate for XYZ's governance needs would be the NIST Al Risk Management Framework and?

A.

NIST Information Security Risk (NIST SP 800-39).

B.

NIST Cyber Security Risk Management Framework (CSF 2.0).

C.

IEEE Ethical System Design Risk Management Framework (IEEE 7000-21).

D.

Human Rights, Democracy, and Rule of Law Impact Assessment (HUDERIA).

Scenario:

A European AI technology company was found to be non-compliant with certain provisions of the EU AI Act. The regulator is considering penalties under the enforcement provisions of the regulation.

According to the EU AI Act, which of the following non-compliance examples could lead to fines of up to €15 million or 3% of annual worldwide turnover(whichever is higher)?

A.

In case of AI Act prohibitions

B.

In case of breach of a provider's obligations for high-risk AI systems

C.

In case of the supply of misleading information to notified bodies in reply to a request

D.

In case of a breach of AI Act prohibition by the Union institutions, bodies, offices and agencies

A company is creating a mobile app to enable individuals to upload images and videos, and analyze this data using ML to provide lifestyle improvement recommendations. The signup form has the following data fields:

1.First name

2.Last name

3.Mobile number

4.Email ID

5.New password

6.Date of birth

7.Gender

In addition, the app obtains a device's IP address and location information while in use.

What GDPR privacy principles does this violate?

A.

Purpose Limitation and Data Minimization.

B.

Accountability and Lawfulness.

C.

Transparency and Accuracy.

D.

Integrity and Confidentiality.

CASE STUDY

A company is considering the procurement of an AI system designed to enhance the security of IT infrastructure. The AI system analyzes how users type on their laptops, including typing speed, rhythm and pressure, to create a unique user profile. This data is then used to authenticate users and ensure that only authorized personnel can access sensitive resources.

The data processed by the AI system would be classified as:

A.

Non-sensitive personal data, since it does not reveal information about health, gender or race

B.

Organizational data, since it is part of the authentication process

C.

Non-personal data, as long as it is not linked to a user ID

D.

Special category data, if it can be used to uniquely identify a person

According to the GDPR's transparency principle, when an Al system processes personal data in automated decision-making, controllers are required to provide data subjects specific information on?

A.

The existence of automated decision-making and meaningful information on its logic and consequences.

B.

The personal data used during processing, including inferences drawn by the Al system about the data.

C.

The data protection impact assessments carried out on the Al system and legal bases for processing.

D.

The contact details of the data protection officer and the data protection national authority.

CASE STUDY

A global marketing agency is adapting a large language model ("LLM") to generate content for an upcoming marketing campaign for a client's new product: a hard hat designed for construction workers of any gender to better protect them from head injuries.

The marketing agency is accessing the LLM through an application programming interface ("API") developed by a third-party technology company. They want to generate text to be used for targeted advertising communications that highlight the benefits of the hard hat to potential purchasers. Both the marketing agency and the technology company have taken reasonable steps to address Al governance.

The marketing company has:

•           Entered into a contract with the technology company with suitable representations and warranties.

•           Completed an impact assessment on the LLM for this intended use.

•           Built technical guidance on how to measure and mitigate bias in the LLM.

•           Enabled technical aspects of transparency, explainability, robustness and privacy.

•           Followed applicable regulatory requirements.

•           Created specific legal statements and disclosures regarding the use of the Al on its client's advertising.

The technology company has:

•           Provided guidance and resources to developers to address environmental concerns.

•           Build technical guidance on how to measure and mitigate bias in the LLM.

•           Provided tools and resources to measure bias specific to the LLM.

•           Enabled technical aspects of transparency, explainability, robustness and privacy.

•           Mapped and mitigated potential societal harms and large-scale impacts.

•           Followed applicable regulatory requirements and industry standards.

•           Created specific legal statements and disclosures regarding the LLM. including with respect to IP and rights to data.

 

Which stakeholder is responsible for the lawful collection of data used to train the foundational AI model?

A.

The marketing agency

B.

The tech company

C.

The data aggregator

D.

The marketing agency’s client

CASE STUDY

A company is considering the procurement of an AI system designed to enhance the security of IT infrastructure. The AI system analyzes how users type on their laptops, including typing speed, rhythm and pressure, to create a unique user profile. This data is then used to authenticate users and ensure that only authorized personnel can access sensitive resources.

All of the following are obligations of the company as a data controller when implementing its AI system EXCEPT?

A.

Ensuring that third-party processors are based in the same country as the company

B.

Allowing data subject access requests (DSARs)

C.

Implementing technical and organizational measures

D.

Conducting a Data Protection Impact Assessment (DPIA) / Privacy Impact Assessment (PIA)

CASE STUDY

Please use the following answer the next question:

XYZ Corp., a premier payroll services company that employs thousands of people globally, is embarking on a new hiring campaign and wants to implement policies and procedures to identify and retain the best talent. The new talent will help the company's product team expand its payroll offerings to companies in the healthcare and transportation sectors, including in Asia.

It has become time consuming and expensive for HR to review all resumes, and they are concerned that human reviewers might be susceptible to bias.

Address these concerns, the company is considering using a third-party Al tool to screen resumes and assist with hiring. They have been talking to several vendors about possibly obtaining a third-party Al-enabled hiring solution, as long as it would achieve its goals and comply with all applicable laws.

The organization has a large procurement team that is responsible for the contracting of technology solutions. One of the procurement team's goals is to reduce costs, and it often prefers lower-cost solutions. Others within the company are responsible for integrating and deploying technology solutions into the organization's operations in a responsible, cost-effective manner.

The organization is aware of the risks presented by Al hiring tools and wants to mitigate them. It also questions how best to organize and train its existing personnel to use the Al hiring tool responsibly. Their concerns are heightened by the fact that relevant laws vary across jurisdictions and continue to change.

Which other stakeholder groups should be involved in the selection and implementation of the Al hiring tool?

A.

Finance and Legal.

B.

Marketing and Compliance.

C.

Supply Chain and Marketing.

D.

Litigation and Product Development.

Which of the following most encourages accountability over Al systems?

A.

Determining the business objective and success criteria for the Al project.

B.

Performing due diligence on third-party Al training and testing data.

C.

Defining the roles and responsibilities of Al stakeholders.

D.

Understanding Al legal and regulatory requirements.

The processes and methods that allow human users to understand and trust the outputs produced by AI are important in addressing which key regulatory concern?

A.

Interpretable AI

B.

Trustworthy AI

C.

Explainable AI

D.

Responsible AI

A company is working to develop a self-driving car that can independently decide the appropriate route to take the driver after the driver provides an address.

If they want to make this self-driving car “strong” Al, as opposed to "weak,” the engineers would also need to ensure?

A.

Thatthe Al has full human cognitive abilities that can independently decide where to take the driver.

B.

That they have obtained appropriate intellectual property (IP) licenses to use data for training the Al.

C.

That the Al has strong cybersecurity to prevent malicious actors from taking control of the car.

D.

That the Al can differentiate among ethnic backgrounds of pedestrians.

All of the following are common optimization techniques in deep learning to determine weights that represent the strength of the connection between artificial neurons EXCEPT?

A.

Gradient descent, which initially sets weights arbitrary values, and then at each step changes them.

B.

Momentum, which improves the convergence speed and stability of neural network training.

C.

Autoregression, which analyzes and makes predictions about time-series data.

D.

Backpropagation, which starts from the last layer working backwards.

What type of organizational risk is associated with Al's resource-intensive computing demands?

A.

People risk.

B.

Security risk.

C.

Third-party risk.

D.

Environmental risk.

Scenario:

A distributor operating in the EU is responsible for selling imported high-risk AI systems to businesses. The distributor wants to ensure they fulfill all applicable obligations under the EU AI Act.

All of the following are obligations of a distributor of high-risk AI systems under the EU AI Act EXCEPT?

A.

Corrective actions

B.

Verification of CE marking

C.

Registration in EU Database

D.

Communication with national authorities

Scenario:

A global organization wants to align with international frameworks on AI governance. They are reviewing guidance from the OECD on how to incorporate broader governance tools into their AI program.

Codes of conductandcollective agreementsare what type of assessment tools as defined by theOrganization for Economic Cooperation and Development (OECD)?

A.

Educational

B.

Procedural

C.

Technical

D.

Analytic

You are part of your organization’s ML engineering team and notice that the accuracy of a model that was recently deployed into production is deteriorating.

What is the best first step address this?

A.

Replace the model with a previous version.

B.

Conduct champion/challenger testing.

C.

Perform an audit of the model.

D.

Run red-teaming exercises.

The White House Executive Order from November 2023 requires companies that develop dual-use foundation models to provide reports to the federal government about all of the following EXCEPT?

A.

Any current training or development of dual-use foundation models.

B.

The results of red-team testing of each dual-use foundation model.

C.

Any environmental impact study for each dual-use foundation model.

D.

The physical and cybersecurity protection measures of their dual-use foundation models.

A company developing and deploying its own AI model would perform all of the following steps to monitor and evaluate the model's performance EXCEPT?

A.

Publicly disclosing data with forecasts of secondary and downstream harms to stakeholders.

B.

Setting up automated tools to regularly track the model's accuracy, precision and recall rates in real-time.

C.

Implementing a formal incident response plan to address incidents that may occur during system operation.

D.

Establishing a regular schedule for human evaluation of the model's performance, including qualitative assessments.

What is the primary purpose of conducting ethical red-teaming on an Al system?

A.

To improve the model's accuracy.

B.

To simulate model risk scenarios.

C.

To identify security vulnerabilities.

D.

To ensure compliance with applicable law.

What is the most important reason to document the results of AI testing?

A.

To support post-deployment maintenance.

B.

To identify areas for red-teaming focus.

C.

To create a verifiable audit trail.

D.

To limit the need for future testing cycles.

Page: 2 / 3
Total 164 questions
Copyright © 2014-2025 Solution2Pass. All Rights Reserved