Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Isaca AAIR Exam - Topic 1 Question 1 Discussion

An organization uses multiple external data sources to train its AI models. Which of the following is the risk practitioner's BEST recommendation to protect the organization from data poisoning attacks?
B) Continuous monitoring and anomaly detection for data ingestion pipelines
A) Data integrity reviews in response to indications that significant model drift has occurred
C) Stringent controls over model code and deployment artifacts
D) Enhanced regularization and training techniques to limit the influence of anomalies

Isaca AAIR Exam - Topic 1 Question 1 Discussion

Actual exam question for Isaca's AAIR exam
Question #: 1
Topic #: 1
[All AAIR Questions]

An organization uses multiple external data sources to train its AI models. Which of the following is the risk practitioner's BEST recommendation to protect the organization from data poisoning attacks?

Show Suggested Answer Hide Answer
Suggested Answer: B

Data poisoning attacks involve malicious modification of training data to degrade model performance or introduce backdoors. With multiple external data sources, the attack surface for introducing poisoned data is broad and requires proactive, continuous detection at the ingestion stage.

Why B is Correct: The ISACA AAIR adversarial AI guidance identifies continuous monitoring and anomaly detection at the data ingestion pipeline as the most effective defense against data poisoning. By monitoring incoming data in real time for statistical anomalies, unexpected distributions, or known poisoning patterns, organizations can detect and block malicious data before it contaminates training datasets. This preventive approach is superior to reactive detection after poisoning has occurred.

Why A is Wrong: Reactive data integrity reviews triggered by model drift occur after poisoning has already affected model behavior. By this stage, the model may have been deployed and made harmful decisions. Prevention during ingestion is superior to post-drift investigation.

Why C is Wrong: Model code and deployment artifact controls address security of the software pipeline but do not protect training data from external poisoning. Data integrity requires data-layer controls, not code security.

Why D is Wrong: Regularization reduces overfitting to training noise but does not detect or prevent deliberate poisoning attacks. A sufficiently targeted poisoning attack can introduce systematic bias that regularization techniques cannot mitigate.


Contribute your Thoughts:

0/2000 characters
Scarlet
1 day ago
Totally agree with B, monitoring is key!
upvoted 0 times
...
Willow
6 days ago
C seems too focused on code, not data.
upvoted 0 times
...
Kristofer
11 days ago
Wait, can data poisoning really mess things up that much?
upvoted 0 times
...
Ronnie
17 days ago
I think A could be useful too, but not the best.
upvoted 0 times
...
Jody
22 days ago
B is the way to go for sure!
upvoted 0 times
...
Amber
27 days ago
I’m torn between A and B; I know model drift is important, but I feel like monitoring the data ingestion process is crucial to prevent issues from the start.
upvoted 0 times
...
Adela
1 month ago
I lean towards option D because enhanced regularization could help mitigate the impact of any anomalies, but I wonder if that's enough on its own.
upvoted 0 times
...
Gracia
1 month ago
I remember a similar question where data integrity was emphasized, but I feel like that might be too reactive rather than proactive.
upvoted 0 times
...
Kindra
1 month ago
I think option B makes the most sense since continuous monitoring can help catch issues early, but I'm not entirely sure if it's the best choice.
upvoted 0 times
...

Save Cancel