ISACA · AAISM
Validates the ability to manage AI security across three domains: AI governance and program management, AI risk management including threats and supply chain issues, and AI technologies and controls, covering security architecture design and model lifecycle management.
Practice Questions
600
≈ 4 practice exams
Duration
150 minutes
Passing Score
450/800
Difficulty
AssociateLast Updated
Feb 2026
Use this AAISM practice exam to prepare for ISACA Advanced in AI Security Management (AAISM) with realistic questions, detailed explanations, and focused study modes. The practice bank includes 600 questions for ISACA AAISM, so you can review the exam steadily instead of relying on one long cram session.
As you practice, pay extra attention to patterns in your missed answers. Start with short sessions to identify weak areas, then move into timed quizzes once your accuracy is consistent.
The explanations are especially useful when you want to connect exam wording to the responsibilities and scenarios described in the official certification guidance. Use the free preview first, then unlock the full question bank when you are ready to build a complete study routine.
The ISACA Advanced in AI Security Management (AAISM) is the first and only AI-centric security management certification, launched by ISACA in August 2025. It validates a security professional's ability to manage enterprise-wide AI adoption while identifying, assessing, monitoring, and mitigating AI-specific risks. The credential covers three interconnected practice areas: AI governance and program management, AI risk management including supply chain and threat landscape considerations, and AI technologies and controls encompassing security architecture, data lifecycle management, and safety controls for AI systems.
AAISM was developed in direct response to the accelerating pace of AI tool adoption in enterprises, which frequently outpaces organizational policy and security frameworks. Rather than replacing existing security credentials, it layers AI-domain expertise on top of proven security management foundations. The exam tests 22 core competencies spanning governance frameworks, vendor oversight, incident response for AI systems, and security architecture design specific to AI model lifecycles.
AAISM is exclusively designed for experienced IT security professionals who already hold an active CISM (Certified Information Security Manager) or CISSP (Certified Information Systems Security Professional) credential — these are hard prerequisites, not recommendations. Candidates should also have hands-on experience assessing, implementing, and maintaining AI systems within an enterprise context.
The certification is well-suited for security managers, CISOs, security architects, and risk advisors who are responsible for governing or advising on AI adoption within their organizations. It targets professionals seeking to formalize and validate their AI security expertise as organizations increasingly integrate AI into critical operations, and who need to bridge the gap between traditional security management practices and emerging AI-specific threat landscapes.
Candidates must hold an active CISM or CISSP certification at the time of exam registration — this is a mandatory requirement with no exceptions. There is no formal application process prior to registering for the exam, but ISACA expects candidates to have demonstrated experience in security or advisory roles and some practical expertise with AI systems, including assessing AI risks and implementing or maintaining AI-driven solutions.
While no specific number of years of experience is mandated beyond what CISM or CISSP already require, the exam content assumes familiarity with enterprise security governance, risk management frameworks, and at least a working knowledge of AI technologies, data pipelines, and machine learning model lifecycles. Professionals newer to AI who hold CISM or CISSP should supplement their candidacy with hands-on AI exposure before attempting the exam.
The AAISM exam consists of 90 multiple-choice questions and must be completed within 150 minutes (2.5 hours). It is delivered as a computer-based exam, available either at authorized PSI testing centers worldwide or via live remote proctoring. Note that residents of India, Mainland China, and Hong Kong are restricted to in-person testing at PSI centers and cannot use remote proctoring.
The passing score is 450 on a scale of 800. Exam registration is continuous with no application windows — candidates can register at any time and have a 12-month eligibility window from the date of registration to schedule and sit the exam. Exams can be scheduled up to 90 days in advance and as early as 48 hours after payment is confirmed. The member exam fee is US$459 and the non-member fee is US$599, plus a US$50 application processing fee required after passing to obtain the certification.
AAISM positions certified professionals as specialized experts at the intersection of enterprise security management and artificial intelligence — a niche that is rapidly growing in organizational demand as AI adoption accelerates across industries. The credential supplements the widely respected CISM and CISSP certifications with validated AI-specific expertise, making holders distinctly qualified for roles such as AI Security Manager, Chief AI Security Officer, Security Architect (AI/ML), and AI Risk Advisor. It also strengthens the candidacy of existing CISOs and security directors who need to demonstrate governance competence over AI-driven business transformation.
ISACA has positioned AAISM as the definitive credential for security managers navigating AI governance — a role that did not exist at scale five years ago but is now embedded in enterprise risk and compliance programs globally. As regulators in the EU (AI Act) and other jurisdictions codify AI security and governance requirements, certified professionals are increasingly sought to operationalize compliance. While specific salary benchmarks for AAISM holders are not yet widely published given the credential's 2025 launch, it builds directly on CISM and CISSP — both of which consistently rank among the highest-paying IT certifications globally — and adds a premium AI specialization layer that is expected to command meaningful salary differentiation in the market.
5 sample questions with answers and explanations. The full bank has 600 questions, enough for 4 full-length practice exams.
Preview — answers shown1. An organization implements security controls throughout the AI lifecycle. During which phase is adversarial robustness testing MOST appropriately performed? (Select one!)
Explanation
Adversarial robustness testing is performed during the modeling phase after models are trained and before deployment. This phase includes train, test, evaluate, and retrain cycles where adversarial examples are used to test model resilience. Testing reveals vulnerabilities to evasion attacks and informs adversarial training. The problem definition phase establishes requirements but has no model to test. Data gathering and preparation phases focus on data quality, not model robustness. While adversarial robustness requirements may be defined early, actual testing requires trained models to evaluate decision boundaries and attack resistance.
2. A CISO implements rate limiting for their organization's AI inference API to prevent resource exhaustion attacks. According to OWASP LLM Top 10 2025, which vulnerability is being mitigated? (Select one!)
Explanation
Unbounded Consumption addresses uncontrolled resource usage causing Denial of Service or financial exploitation through excessive API calls. Rate limiting directly prevents resource exhaustion by controlling consumption. Prompt Injection involves manipulating LLM behavior through malicious inputs. Excessive Agency relates to over-permissioned autonomous actions rather than resource consumption. Misinformation addresses factually incorrect outputs, not resource exhaustion.
3. An organization implements ISO/IEC 42001:2023 AI Management System certification. The standard requires implementing specific Annex A controls across the AI lifecycle. How many specific controls does Annex A of ISO/IEC 42001:2023 define? (Select one!)
Explanation
ISO/IEC 42001:2023 establishes 38 specific Annex A controls organized across AI policy requirements, risk evaluation mandates, data governance controls, model lifecycle management, and third-party supplier oversight. These controls provide a comprehensive framework using the Plan-Do-Check-Act methodology across 10 clauses. Major cloud providers including AWS, Microsoft, and Google have achieved ISO 42001 certification demonstrating the standard's industry adoption.
4. An AI security team detects that a production recommendation model's prediction accuracy has degraded from 94% to 78% over three months, despite input feature distributions remaining stable. Which type of model drift has occurred? (Select one!)
Explanation
Concept drift occurs when the relationship between inputs and outputs changes over time, causing performance degradation despite stable input distributions. The stable feature distributions but declining accuracy indicates the underlying patterns have changed. Data drift involves changes in input feature distributions, which the scenario explicitly states remained stable. Prediction drift addresses changes in output distributions but not the underlying accuracy degradation. Feature drift involves individual feature changes, which contradicts the stable input distributions.
5. A data scientist trains a fraud detection model that achieves 98 percent accuracy on training data but only 73 percent accuracy on test data from the same time period. The model demonstrates poor generalization to new transactions. Which problem has occurred? (Select one!)
Explanation
Overfitting occurs when a model performs well on training data but poorly on test data, indicating the model has memorized training examples rather than learning generalizable patterns. The 25 percent accuracy gap between training and test sets is a classic indicator of overfitting. Underfitting occurs when models are too simple to capture underlying patterns and would show poor performance on both training and test data. Concept drift involves changes in the input-output relationship over time. Data drift involves changes in input distributions over time.
IT Risk Fundamentals Certificate
Risk-Fund · 616 questions
ISACA Advanced in AI Audit (AAIA)
AAIA · 600 questions
ISACA Advanced in AI Risk (AAIR)
AAIR · 598 questions
Artificial Intelligence Fundamentals Certificate
AI-Fundamentals · 600 questions
Blockchain Fundamentals Certificate
Blockchain-Fund · 599 questions
Certified Cybersecurity Operations Analyst (CCOA)
CCOA · 593 questions
$17.99
One-time access to this exam