Weekend Sale - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmaspas7

Easiest Solution 2 Pass Your Certification Exams

AIGP IAPP Artificial Intelligence Governance Professional Free Practice Exam Questions (2025 Updated)

Prepare effectively for your IAPP AIGP Artificial Intelligence Governance Professional certification with our extensive collection of free, high-quality practice questions. Each question is designed to mirror the actual exam format and objectives, complete with comprehensive answers and detailed explanations. Our materials are regularly updated for 2025, ensuring you have the most current resources to build confidence and succeed on your first attempt.

Page: 1 / 3
Total 164 questions

A company deploys an AI model for fraud detection in online transactions. During its operation, the model begins to exhibit high rates of false positives, flagging legitimate transactions as fraudulent.

Which is the best step the company should take to address this development?

A.

Dedicate more resources to monitor the model.

B.

Maintain records of all false positives.

C.

Deactivate the model until an assessment is made.

D.

Conduct training for customer service teams to handle flagged transactions.

In the machine learning context, feature engineering is the process of?

A.

Converting raw data into clean data.

B.

Creating learning schema for a model apply.

C.

Developing guidelines to train and test a model.

D.

Extracting attributes and variables from raw data.

During the development of semi-autonomous vehicles, various failures occurred as a result of the sensors misinterpreting environmental surroundings, such as sunlight.

These failures are an example of?

A.

Hallucination.

B.

Brittleness.

C.

Uncertainty.

D.

Forgetting.

What is the main purpose of accountability structures under the Govern function of the NIST Al Risk Management Framework?

A.

To empower and train appropriate cross-functional teams.

B.

To establish diverse, equitable and inclusive processes.

C.

To determine responsibility for allocating budgetary resources.

D.

To enable and encourage participation by external stakeholders.

CASE STUDY

Please use the following answer the next question:

A local police department in the United States procured an Al system to monitor and analyze social media feeds, online marketplaces and other sources of public information to detect evidence of illegal activities (e.g., sale of drugs or stolen goods). The Al system works by surveilling the public sites in order to identify individuals that are likely to have committed a crime. It cross-references the individuals against data maintained by law enforcement and then assigns a percentage score of the likelihood of criminal activity based on certain factors like previous criminal history, location, time, race and gender.

The police department retained a third-party consultant assist in the procurement process, specifically to evaluate two finalists. Each of the vendors provided information about their system's accuracy rates, the diversity of their training data and how their system works. The consultant determined that the first vendor’s system has a higher accuracy rate and based on this information, recommended this vendor to the police department.

The police department chose the first vendor and implemented its Al system. As part of the implementation, the department and consultant created a usage policy for the system, which includes training police officers on how the system works and how to incorporate it into their investigation process.

The police department has now been using the Al system for a year. An internal review has found that every time the system scored a likelihood of criminal activity at or above 90%, the police investigation subsequently confirmed that the individual had, in fact, committed a crime. Based on these results, the police department wants to forego investigations for cases where the Al system gives a score of at least 90% and proceed directly with an arrest.

Which Al risk would NOT have been identified during the procurement process based on the categories of information requested by the third-party consultant?

A.

Security.

B.

Accuracy.

C.

Explainability.

D.

Discrimination.

Which stakeholder is responsible for lawful collection of data for the training of the foundational AI model?

A.

The marketing agency.

B.

The tech company.

C.

The data aggregator.

D.

The marketing agency's client.

A company initially intended to use a large data set containing personal information to train an Al model. After consideration, the company determined that it can derive enough value from the data set without any personal information and permanently obfuscated all personal data elements before training the model.

This is an example of applying which privacy-enhancing technique (PET)?

A.

Anonymization.

B.

Pseudonymization.

C.

Differential privacy.

D.

Federated learning.

CASE STUDY

Please use the following answer the next question:

A mid-size US healthcare network has decided to develop an Al solution to detect a type of cancer that is most likely arise in adults. Specifically, the healthcare network intends to create a recognition algorithm that will perform an initial review of all imaging and then route records a radiologist for secondary review pursuant agreed-upon criteria (e.g., a confidence score below a threshold).

To date, the healthcare network has taken the following steps: defined its Al ethical principles: conducted discovery to identify the intended uses and success criteria for the system: established an Al governance committee; assembled a broad, crossfunctional team with clear roles and responsibilities; and created policies and procedures to document standards, workflows, timelines and risk thresholds during the project.

The healthcare network intends to retain a cloud provider to host the solution and a consulting firm to help develop the algorithm using the healthcare network's existing data and de-identified data that is licensed from a large US clinical research partner.

In the design phase, what is the most important step for the healthcare network to take when mapping its existing data to the clinical research partner data?

A.

Apply privacy-enhancing technologies to the data.

B.

Identify fits and gaps in the combined data.

C.

Ensure the data is labeled and formatted.

D.

Evaluate the country of origin of the data.

In procuring an AI system from a vendor, which of the following would be important to include in a contract to enable proper oversight and auditing of the system?

A.

Liability for mistakes.

B.

Ownership of data and outputs.

C.

Responsibility for improvements.

D.

Appropriate access to data and models.

The most important factor in ensuring fairness when training an Al system is?

A.

The architecture and model selection.

B.

The data labeling and classification.

C.

The data attributes and variability.

D.

The model accuracy and scale.

Scenario:

A U.S.-based AI governance professional is evaluating resources from the National Institute of Standards and Technology (NIST) to guide the organization’s AI risk assessment strategy. They are particularly interested in programs focused on assessing AI-specific impacts.

The main purpose of NIST’sAssessing Risks and Impacts of AI (ARIA)program is to:

A.

Provide a suite of resources to manage risks

B.

Pilot new standards for AI red-teaming

C.

Promote interoperability across AI systems

D.

Offer a regulatory sandbox for risk reporting

Scenario:

An organization wants to leverage its existing compliance structures to identify AI-specific risks as part of an ongoing data governance audit.

Which of the following compliance-related controls within an organization ismost easily adaptedto identify AI risks?

A.

Privacy training

B.

Penetration testing

C.

Transfer risk assessments

D.

Privacy impact assessments

Which of the following is a subcategory of Al and machine learning that uses labeled datasets to train algorithms?

A.

Segmentation.

B.

Generative Al.

C.

Expert systems.

D.

Supervised learning.

CASE STUDY

Please use the following answer the next question:

Good Values Corporation (GVC) is a U.S. educational services provider that employs teachers to create and deliver enrichment courses for high school students. GVC has learned that many of its teacher employees are using generative Al to create the enrichment courses, and that many of the students are using generative Al to complete their assignments.

In particular, GVC has learned that the teachers they employ used open source large language models (“LLM”) to develop an online tool that customizes study questions for individual students. GVC has also discovered that an art teacher has expressly incorporated the use of generative Al into the curriculum to enable students to use prompts to create digital art.

GVC has started to investigate these practices and develop a process to monitor any use of generative Al, including by teachers and students, going forward.

Which of the following risks should be of the highest concern to individual teachers using generative Al to ensure students learn the course material?

A.

Financial cost.

B.

Model accuracy.

C.

Technical complexity.

D.

Copyright infringement.

Scenario:

Business A provides grammar and writing assistance tools and licenses a generative AI model from Business B to enhance its offerings. Business A is concerned that the AI model might produce inappropriate or toxic content and wants to implement governance processes to prevent this.

Which of the following governance processes should Business A take tobest protect its usersagainst potentially inappropriate text?

A.

Business A should fine-tune the AI model on user-generated text that has been verified to be appropriate

B.

Business A should test that the AI model performs as expected and meets their minimum requirements for filtering toxic or obscene text

C.

Business A should establish a user reporting feature that allows users to flag toxic or obscene text, and report any incidents to Business B

D.

Business A should ask Business B for detailed documentation on the generative AI model's training data and whether it contained toxic or obscene sources

All of the following may be permissible uses of an Al system under the EU Al Act EXCEPT?

A.

To detect an individual's intent for law enforcement purposes.

B.

To promote equitable distribution of welfare benefits.

C.

To implement social scoring.

D.

To manage border control.

CASE STUDY

Please use the following answer the next question:

ABC Corp, is a leading insurance provider offering a range of coverage options to individuals. ABC has decided to utilize artificial intelligence to streamline and improve its customer acquisition and underwriting process, including the accuracy and efficiency of pricing policies.

ABC has engaged a cloud provider to utilize and fine-tune its pre-trained, general purpose large language model (“LLM”). In particular, ABC intends to use its historical customer data—including applications, policies, and claims—and proprietary pricing and risk strategies to provide an initial qualification assessment of potential customers, which would then be routed .. human underwriter for final review.

ABC and the cloud provider have completed training and testing the LLM, performed a readiness assessment, and made the decision to deploy the LLM into production. ABC has designated an internal compliance team to monitor the model during the first month, specifically to evaluate the accuracy, fairness, and reliability of its output. After the first month in production, ABC realizes that the LLM declines a higher percentage of women's loan applications due primarily to women historically receiving lower salaries than men.

During the first month when ABC monitors the model for bias, it is most important to?

A.

Continue disparity testing.

B.

Analyze the quality of the training and testing data.

C.

Compare the results to human decisions prior to deployment.

D.

Seek approval from management for any changes to the model.

What is theprimary purposeof an AI impact assessment?

A.

To determine whether a conformity assessment is needed

B.

To escalate the findings to the appropriate owner(s)

C.

To identify and measure the benefits of an AI system

D.

To anticipate and manage the potential risks and harms of an AI system

According to the GDPR, an individual has the right to have a human confirm or replace an automated decision unless that automated decision?

A.

Is authorized with the data subject s explicit consent.

B.

Is authorized by applicable Ell law and includes suitable safeguards.

C.

Is deemed to solely benefit the individual and includes documented legitimate interests.

D.

Is necessary for entering into or performing under a contract between the data subject and data controller.

Scenario:

An organization is planning to deploy a new internal application that uses AI to make automated decisions about individuals. This application will process personal information and may affect individuals’ access to certain benefits or opportunities.

Which of the following documents must be updated to ensure transparency?

A.

The organization's website privacy notice

B.

The organization's acceptable use policy

C.

The organization's privacy policy

D.

The user privacy notice

Page: 1 / 3
Total 164 questions
Copyright © 2014-2025 Solution2Pass. All Rights Reserved