Free Practice Questions for AAISM
Exam-style questions and explanations by OpenExamPrep.
Loading practice questions...
Explore More ISACA Certifications
Continue into nearby exams from the same family. Each card keeps practice questions, study guides, flashcards, videos, and articles in one place.
More From This Family
Videos and articles for deeper review.
Key Facts: AAISM Exam
90
Exam Questions
ISACA AAISM ECO
2.5 hours
Time Limit
ISACA / PSI
450/800
Passing Score
ISACA scaled score
31/31/38
Domain Weights
Governance / Risk / Controls
$459
Member Exam Fee
ISACA (+ $50 application fee)
CISM or CISSP
Required Prerequisite
ISACA AAISM page
ISACA's AAISM (Advanced in AI Security Management) is a 2025-launch credential designed for security leaders extending CISM or CISSP into AI security. The exam is 90 multiple-choice questions in 2.5 hours with a 450/800 scaled passing score, delivered through PSI in test centers or remote proctoring. Candidates must hold an active CISM or CISSP and have a six-month eligibility window after registration. The exam covers AI Governance and Program Management (31%), AI Risk Management (31%), and AI Technologies and Controls (38%), with the standard fee of $459 for ISACA members or $599 for non-members plus a $50 application processing fee.
Sample AAISM Practice Questions
Try these sample questions to review concepts for the AAISM exam. Each question includes a detailed explanation. Start the interactive quiz above for the full 100+ question experience with AI tutoring.
1An enterprise CISO is establishing accountability for AI security across business units. Which approach BEST aligns with ISO/IEC 42001 (AI Management System) and NIST AI RMF Govern function expectations?
2Which of the following is the PRIMARY purpose of an AI security policy within an enterprise security program?
3An AI security committee is being formed. Which membership composition BEST supports cross-functional governance of AI risk?
4A model card for a deployed customer-service LLM lists training data sources, intended use, and known limitations but omits any security review notes. From an AAISM perspective, what is the MOST significant gap?
5An organization is choosing a baseline AI management framework. Which standard formally defines an AI Management System (AIMS) with certification scheme?
6Within the NIST AI RMF 1.0 core, which function is responsible for cultivating a culture of risk management and is intended to apply across all stages of the AI lifecycle?
7A multinational deploys an HR-screening LLM that processes EU resumes. Which regulatory consideration MUST appear in the AI security program?
8Which document defines the strategic direction, scope, milestones, and resource plan for an enterprise AI security capability over a multi-year horizon?
9An AI security manager wants to track program effectiveness with leading rather than lagging indicators. Which is the BEST example of a leading KRI for AI security?
10An enterprise wants to classify training data used for a customer-support LLM. Which classification approach is MOST aligned with AI program governance and privacy expectations?
About the AAISM Exam
The ISACA Advanced in AI Security Management (AAISM) is a hard-prerequisite credential for security managers responsible for governing and securing AI systems. It validates AI governance and program management, AI risk management, and AI security technologies and controls aligned with ISACA's exam content outline, NIST AI RMF 1.0, ISO/IEC 42001, OWASP Top 10 for LLM Applications, and MITRE ATLAS. Candidates must hold an active CISM or CISSP to register.
Exam sponsor: ISACA / PSI. The requirements and fees below concern the certification or admission exam, separate from our free practice resources.
Assessment
90 multiple-choice questions across three domains: AI Governance and Program Management (31%), AI Risk Management (31%), and AI Technologies and Controls (38%). Delivered by PSI in test centers or via online proctoring.
Time Limit
2.5 hours
Passing Score
450/800
Exam / Certification Fees
$459 (members) / $599 (non-members) + $50 application fee
Exam sponsor websiteReported exam pass rate: Not published by ISACA. ISACA does not publish official AAISM pass-rate statistics. Exam sponsor website
Fees, eligibility, and exam policies can change. Confirm them with the exam sponsor before applying or paying.
Our practice resources: topics covered
We aim to reflect publicly available exam outlines and topic information in our study resources. Coverage, format, and difficulty may differ from the actual exam, and we cannot guarantee that every detail is accurate or current. Confirm exam requirements, fees, and policies with the official exam sponsor.
AI Governance and Program Management
Stakeholder considerations, industry frameworks, and regulatory requirements (NIST AI RMF, ISO/IEC 42001, EU AI Act, GDPR, CCPA); AI strategies, policies, and procedures; AI asset and data lifecycle management; AI security program development; business continuity and incident response for AI
AI Risk Management
AI risk assessment, thresholds, and treatment; AI threat and vulnerability management; AI vendor and supply chain management; adversarial ML and MITRE ATLAS techniques; OWASP Top 10 for LLM Applications 2025
AI Technologies and Controls
AI security architecture and design; AI lifecycle controls (model selection, training, validation); data management controls; privacy, ethical, trust and safety controls; privacy-enhancing technologies (differential privacy, federated learning, MPC, homomorphic encryption, confidential computing); security monitoring and ML observability
Preparing for the AAISM Exam
What You Need to Know
- Passing score: 450/800
- Assessment: 90 multiple-choice questions across three domains: AI Governance and Program Management (31%), AI Risk Management (31%), and AI Technologies and Controls (38%). Delivered by PSI in test centers or via online proctoring.
- Time limit: 2.5 hours
- Exam / certification fees: $459 (members) / $599 (non-members) + $50 application fee Official sources
Using Our Practice Resources
- Work through all 100 available questions
- Review every answer and explanation
- Track weak areas and revisit them
- Use our AI tutor for tough concepts
AAISM: Suggested Study Strategy
Frequently Asked Questions
What is the ISACA AAISM exam?
AAISM (Advanced in AI Security Management) is ISACA's 2025-launch credential for security leaders responsible for governing and securing AI systems. It is positioned as an advanced credential and requires an active CISM or CISSP certification to register. The 90-question, 2.5-hour exam is delivered through PSI.
What are the AAISM domain weights?
The AAISM exam content outline defines three domains: AI Governance and Program Management (31%), AI Risk Management (31%), and AI Technologies and Controls (38%). Domain 3 carries the most weight and emphasizes technical interpretation, control selection, and security judgment for AI systems.
Who is eligible to take the AAISM exam?
Candidates must hold an active CISM or CISSP certification at registration. ISACA also expects experience in security or advisory roles and some expertise assessing, implementing, or maintaining AI systems. After registration, candidates have a six-month eligibility window to schedule and take the exam.
How much does AAISM cost?
The exam fee is US$459 for ISACA members and US$599 for non-members. There is also a one-time US$50 application processing fee due after passing the exam. ISACA annual maintenance fees apply after certification.
What is the AAISM passing score?
Like ISACA's other credentials, AAISM uses a scaled score from 200 to 800 and a passing score of 450 or higher. The 90-question exam combines knowledge-based and scenario-based items.
How should I study for AAISM?
Start from the ISACA AAISM exam content outline, then layer in NIST AI RMF 1.0, ISO/IEC 42001, the EU AI Act, OWASP Top 10 for LLM Applications 2025, and MITRE ATLAS. Practice scenario decisions across governance, risk, and controls, and prioritize Domain 3 (38%) for technical depth on architecture, lifecycle controls, monitoring, and privacy-enhancing technologies.
How does AAISM differ from CISM and CISSP?
CISM is broad information security management; CISSP is broad security architecture and engineering. AAISM is purpose-built for AI security: AI-specific governance, risk, and controls, including model lifecycle, prompt injection, vector databases, agent security, and AI supply chain. AAISM is designed to extend, not replace, CISM or CISSP.