This sample moves from AI terminology into Annex A, the Statement of Applicability and the distinction between organisational risk and AI system impact assessment. Reveal each answer to see the reasoning and why the other options fail.
What this exact sample covers
AIMS implementation decisions
AI and machine-learning relationships
Annex A and SoA decisions
Risk versus impact assessment
Question 01Domain 1 · application
Under the EU AI Act’s risk-based classification, an AI system that uses subliminal techniques to materially distort a person’s behaviour in a way likely to cause significant harm falls into which category?
AHigh risk, permitted subject to conformity assessment
BUnacceptable risk, prohibited
CLimited risk, subject only to transparency obligations
the answer and reasoning
Correct answerB. Unacceptable risk, prohibited
The EU AI Act sets four tiers: unacceptable, high, limited and minimal. Unacceptable-risk practices are banned outright rather than regulated, and subliminal manipulation causing significant harm is named among them. An ISO/IEC 42001 implementer needs this tier because a prohibited practice cannot be brought into conformity by controls — it has to be stopped.
Why the other options fail
A. High-risk systems are permitted and regulated, not banned. Placing a prohibited practice here implies it could be made lawful through conformity assessment, which it cannot.
C. Limited risk covers systems needing disclosure — chatbots, deepfakes — where the obligation is to tell people they are dealing with AI. Manipulation causing significant harm is far beyond a transparency duty.
A colleague describes deep learning as “a separate field from machine learning that replaced it”. What is the accurate relationship?
ADeep learning is a subset of machine learning that uses multi-layered neural networks
BMachine learning is a subset of deep learning applied to smaller datasets
CThey are independent disciplines that happen to share statistical methods
the answer and reasoning
Correct answerA. Deep learning is a subset of machine learning that uses multi-layered neural networks
The nesting runs artificial intelligence → machine learning → deep learning. Deep learning is the subset of machine learning built on neural networks with many hidden layers. Competency domain 1 asks candidates to differentiate these subfields, and getting the containment backwards is the most common error.
Why the other options fail
B. This inverts the hierarchy. Machine learning is the broader field; dataset size is not what distinguishes the two.
C. They are not independent. Deep learning sits inside machine learning and inherits its training, validation and evaluation concepts.
In ISO/IEC 42001:2023, which annex contains the reference control objectives and controls that an organisation compares its own controls against?
AAnnex B
BAnnex A
CAnnex C
the answer and reasoning
Correct answerB. Annex A
Annex A holds the reference control objectives and controls. Annex B gives implementation guidance for those controls, Annex C lists potential AI-related organisational objectives and risk sources, and Annex D covers the domains and sectors in which an AIMS can be used. Domain 2 is only five questions, but annex identification is reliably among them.
Why the other options fail
A. Annex B is the implementation guidance that explains how to apply the Annex A controls. It is not the control set itself.
C. Annex C lists potential organisational objectives and risk sources. It informs risk assessment rather than serving as the control reference.
An organisation’s Statement of Applicability lists every Annex A control it has implemented, but records nothing about the controls it left out. What is the defect?
AThe Statement of Applicability should list only excluded controls
BNothing — recording implemented controls is all that is required
CExclusions must be recorded with a justification for each
the answer and reasoning
Correct answerC. Exclusions must be recorded with a justification for each
A Statement of Applicability has to account for the whole Annex A reference set: which controls are necessary, the justification for including them, whether they are implemented, and the justification for excluding any that are not. Silence on exclusions is the single most common finding against this document, because an auditor cannot distinguish a considered exclusion from an oversight.
Why the other options fail
A. This reverses the requirement. Inclusions and their justifications are equally part of the document.
B. An implemented-only list leaves every omitted control ambiguous, and gives an auditor no evidence that the omission was a decision at all.
A team has completed its AI risk assessment and is preparing an AI system impact assessment using the same register and template. Why is this a problem?
AThe two assessments look outward in opposite directions and cannot share a template
BImpact assessments must be performed before risk assessments, not after
CImpact assessment is optional once a risk assessment exists
the answer and reasoning
Correct answerA. The two assessments look outward in opposite directions and cannot share a template
An AI risk assessment asks what could harm the organisation. An AI system impact assessment asks what the organisation’s AI could do to individuals, groups and society. Same shape, opposite direction. Reusing the risk register produces a document that reads plausibly and never leaves the organisation’s point of view — which is exactly what an assessor tests for. This is the requirement with no ISO/IEC 27001 equivalent.
Why the other options fail
B. ISO/IEC 42001 does not impose that ordering, and sequence is not what makes the reuse wrong. The defect is the direction of analysis.
C. The impact assessment is a requirement in its own right. A risk assessment does not discharge it, precisely because it asks a different question.
Casual mode shows feedback as you answer. Full access adds the complete weighted bank, exam mode, saved results and domain-level analysis for this exact qualification.