Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Isaca AAIR Exam - Topic 1 Question 4 Discussion

Which of the following is the MOST important reason for a risk practitioner to classify AI risk using threat actor profiles?
B) To tailor controls to adversary motivations and capabilities
A) To align AI threat and vulnerability risk with the overall IT control taxonomy
C) To develop response metrics for AI cybersecurity incidents
D) To ensure external threats to corporate assets are given highest priority

Isaca AAIR Exam - Topic 1 Question 4 Discussion

Actual exam question for Isaca's AAIR exam
Question #: 4
Topic #: 1
[All AAIR Questions]

Which of the following is the MOST important reason for a risk practitioner to classify AI risk using threat actor profiles?

Show Suggested Answer Hide Answer
Suggested Answer: B

Threat actor profiling characterizes the motivations, capabilities, and likely attack methods of potential adversaries. In AI risk management, understanding who the likely attackers are and what they seek enables the design of controls specifically matched to the actual threat landscape.

Why B is Correct: According to ISACA AAIR threat-based risk management guidance, the most important reason for threat actor profiling is to tailor controls to adversary motivations and capabilities. Different threat actors---nation-state attackers, criminal organizations, competitors, insiders, activists---have different objectives (espionage vs. financial gain vs. disruption), capabilities (sophisticated vs. opportunistic), and methods. Controls calibrated to actual threat actor profiles are significantly more effective than generic controls that may not address the specific threats the organization actually faces.

Why A is Wrong: Aligning AI threats with IT control taxonomy is a governance integration activity that improves control consistency but does not capture the threat actor-specific tailoring value of profiling. Taxonomy alignment is an administrative benefit; threat-tailored controls are a security effectiveness benefit.

Why C is Wrong: Response metrics for cybersecurity incidents are developed for incident management planning. Threat actor profiling informs control design and incident response strategies but is not primarily used to develop response metrics.

Why D is Wrong: Prioritizing external threats over internal threats is a security strategy choice that threat actor profiling does not prescribe. Many AI attacks, including insider threats and social engineering, are internal. Profiling should result in appropriate prioritization based on actual threat likelihood, not a blanket prioritization of external threats.


Contribute your Thoughts:

0/2000 characters
Kenda
1 day ago
C could be useful too, but not as critical as B.
upvoted 0 times
...
Vincenza
6 days ago
Totally agree with B, understanding adversaries is crucial.
upvoted 0 times
...
Kris
11 days ago
Surprised that D is even an option, seems too narrow!
upvoted 0 times
...
Thea
17 days ago
I think A is just as important for overall alignment.
upvoted 0 times
...
Corrinne
22 days ago
B is definitely the way to go! Tailoring controls is key.
upvoted 0 times
...
Denny
27 days ago
I vaguely remember a question about prioritizing threats, which might relate to D, but I think the motivations behind threats are more crucial.
upvoted 0 times
...
Dahlia
1 month ago
I feel like we discussed response metrics in class, but I can't recall if that was the main focus. C could be relevant, but I'm leaning towards B.
upvoted 0 times
...
Edwin
1 month ago
I'm not entirely sure, but I remember something about aligning risks with IT controls being important. Maybe A is also a strong contender?
upvoted 0 times
...
Hassie
1 month ago
I think option B makes the most sense since understanding adversary motivations can really help in tailoring our defenses.
upvoted 0 times
...

Save Cancel