Certified AI Consultant (CAIC™) — Questions and Answers
Question 1: Which data splitting strategy ensures that the proportion of each class is maintained in both train and test sets?
- Random split
- Chronological split
- K-fold split
- Stratified split (Correct answer)
Correct answer: Stratified split
Stratified splitting preserves the class distribution of the full dataset in each resulting subset, critical for imbalanced classification problems.
Question 2: An AI consultant reviewing a healthcare AI system recommends implementing 'human-in-the-loop' oversight. The primary security and risk benefit of this control is:
- It speeds up model inference by offloading decisions
- It reduces the amount of training data required
- It ensures a human can catch and override erroneous or harmful AI decisions before they cause harm (Correct answer)
- It prevents the model from being retrained without authorization
Correct answer: It ensures a human can catch and override erroneous or harmful AI decisions before they cause harm
Human-in-the-loop oversight provides a critical safety check that can catch and stop harmful AI outputs before they impact patients.
Question 3: Which cryptographic protocol property ensures that past AI API session traffic cannot be decrypted even if the server's private key is later compromised?
- Public key infrastructure (PKI)
- Certificate pinning
- Perfect Forward Secrecy (PFS) (Correct answer)
- OCSP stapling
Correct answer: Perfect Forward Secrecy (PFS)
PFS uses ephemeral session keys (e.g., ECDHE) so that compromising the long-term private key does not expose previously recorded session traffic.
Question 4: An AI consultant is designing a feature engineering pipeline. Which transformation converts a high-cardinality categorical variable (e.g., ZIP codes) into numeric inputs without creating thousands of sparse columns?
- Ordinal encoding with arbitrary integers
- Target encoding (Correct answer)
- Binary encoding with label assignment
- One-hot encoding
Correct answer: Target encoding
Target encoding replaces each category with the mean of the target variable for that category, capturing signal without the dimensionality explosion of one-hot encoding.
Question 5: Which task involves training an AI model to answer questions based on a provided passage of text?
- Text summarization
- Extractive question answering (Correct answer)
- Part-of-speech tagging
- Machine translation
Correct answer: Extractive question answering
Extractive question answering locates and extracts spans of text from a provided context passage that directly answer a given question.
Question 6: Which evaluation metric is commonly used to assess the quality of machine-generated text against reference text?
- BLEU score (Correct answer)
- AUC-ROC
- F1 score
- RMSE
Correct answer: BLEU score
BLEU (Bilingual Evaluation Understudy) score compares n-gram overlap between generated and reference text and is widely used for NLP tasks like translation.
Question 7: An enterprise wants to implement AI governance across dozens of models. Which architectural component acts as the central control plane for policy enforcement?
- An individual model's internal validation logic
- The cloud provider's IAM permission system
- A dedicated GPU cluster for compliance workloads
- An AI governance layer with policy engines, audit logging, and model metadata registry (Correct answer)
Correct answer: An AI governance layer with policy engines, audit logging, and model metadata registry
A centralized governance layer can enforce consistent policies (bias thresholds, explainability requirements, data lineage) across all models rather than relying on per-model implementations.
Question 8: Which AI application would a CAIC consultant most likely recommend for automating customer support ticket routing?
- Text classification with NLP (Correct answer)
- Reinforcement learning from human feedback
- Time-series forecasting
- Computer vision object detection
Correct answer: Text classification with NLP
Text classification models can automatically categorize incoming support tickets by topic, urgency, or department, enabling intelligent routing without human intervention.
Question 9: What is 'right to explanation' as it applies to automated AI decisions affecting individuals in the US context?
- An individual's right to receive a meaningful explanation of how an automated decision that affects them was made (Correct answer)
- The right to request open-source access to model weights
- A developer's right to document proprietary algorithms
- The vendor's right to explain pricing models
Correct answer: An individual's right to receive a meaningful explanation of how an automated decision that affects them was made
The right to explanation gives individuals the ability to understand the logic behind automated decisions that significantly affect them, influenced by GDPR Article 22 and emerging US state laws.
Question 10: Which vendor management strategy reduces lock-in risk when an AI project depends heavily on a proprietary cloud ML platform?
- Signing a longer-term contract for better pricing
- Storing all data exclusively in the vendor's proprietary format
- Disabling export features to simplify the architecture
- Using open standards and abstracting vendor-specific APIs behind an interface layer (Correct answer)
Correct answer: Using open standards and abstracting vendor-specific APIs behind an interface layer
Abstracting vendor APIs behind a common interface layer allows swapping providers without rewriting core application logic.
Question 11: What is the purpose of cross-validation in machine learning?
- To validate the model's performance on new, unseen data (Correct answer)
- To test the model on the same data multiple times.
- To reduce the number of features.
- To avoid using the test data.
Correct answer: To validate the model's performance on new, unseen data
Cross-validation is a crucial technique in machine learning used to assess how well a model will generalize to an independent dataset. It involves partitioning the data into multiple subsets, training the model on a portion of these subsets, and testing it on the remaining unseen subset. This process is repeated multiple times, providing a more robust and reliable estimate of the model's performance and helping to detect issues like overfitting.
Question 12: Which type of attack attempts to determine whether a specific individual's data was used in training an AI model?
- Membership inference attack (Correct answer)
- Model inversion attack
- Prompt injection attack
- Adversarial evasion attack
Correct answer: Membership inference attack
Membership inference attacks query a model to infer whether a given data point was part of its training set.
Question 13: A team wants to ensure their AI model can be rolled back quickly in production. The BEST DevOps practice to support this is:
- Manual rollback scripts maintained by developers
- Single environment deployment
- Blue-green deployment with model registry versioning (Correct answer)
- Deploying only during off-peak hours
Correct answer: Blue-green deployment with model registry versioning
Blue-green deployments allow instant traffic switching, and a model registry tracks versions so any prior version can be promoted without code changes.
Question 14: Which best practice ensures that ethical requirements are addressed throughout the AI development lifecycle rather than only at launch?
- Post-deployment bias bounty programs
- Annual third-party audits after release
- Publishing model performance benchmarks publicly
- Ethics-by-design: embedding ethical review at every development phase (Correct answer)
Correct answer: Ethics-by-design: embedding ethical review at every development phase
Ethics-by-design integrates ethical review into requirements, data collection, model development, and deployment stages, preventing issues from being discovered too late.
Question 15: In an AI system processing sensitive PII for predictions, which architectural control ensures data minimization at the system boundary?
- Data masking and tokenization applied before data enters the AI pipeline (Correct answer)
- Encrypting the trained model weights at rest
- Restricting API access with OAuth 2.0 tokens
- Storing predictions in an append-only audit log
Correct answer: Data masking and tokenization applied before data enters the AI pipeline
Masking and tokenizing PII before it enters the pipeline ensures the AI components never process raw sensitive data, enforcing data minimization at the architectural boundary.
Question 16: What is the purpose of data analysis in CAIC practice?
- Creating attractive charts only
- Transforming raw data into insights for informed decision-making (Correct answer)
- Replacing professional judgment
- Collecting data regardless of relevance
Correct answer: Transforming raw data into insights for informed decision-making
Data analysis examines, cleans, and models data to discover useful information and support decision-making.
Question 17: What is the key difference between 'AI safety' and 'AI security' as risk domains?
- AI safety focuses on unintended harmful outcomes from AI behavior; AI security focuses on deliberate attacks by adversaries (Correct answer)
- AI safety applies only to robotics; AI security applies only to NLP models
- AI safety concerns physical hardware failures; AI security concerns software bugs
- AI safety is regulated by NIST; AI security is regulated by the EU
Correct answer: AI safety focuses on unintended harmful outcomes from AI behavior; AI security focuses on deliberate attacks by adversaries
AI safety addresses unintended harms from flawed design or misalignment, while AI security addresses intentional exploitation by adversaries.
Question 18: What is the key advantage of using a pre-trained foundation model over building an NLP model from scratch for an enterprise deployment?
- They require significantly less labeled training data and development time (Correct answer)
- Foundation models have no licensing costs
- They eliminate the need for infrastructure entirely
- They are always smaller and faster than custom models
Correct answer: They require significantly less labeled training data and development time
Foundation models encode broad linguistic knowledge from massive pre-training, so organizations can adapt them with minimal task-specific labeled data, saving significant time and cost.
Question 19: An organization deploys AI models across cloud and on-premises environments. Which architectural pattern best manages this complexity?
- Vendor-locked proprietary AI cloud platform
- Single on-premises cluster with VPN tunneling to cloud storage
- Hybrid ML platform with abstraction layers enabling portable model packaging (e.g., ONNX, containers) (Correct answer)
- Manually synchronized model files between environments
Correct answer: Hybrid ML platform with abstraction layers enabling portable model packaging (e.g., ONNX, containers)
Abstraction layers using open standards like ONNX and containerized serving runtimes make models portable across environments without re-engineering for each target infrastructure.
Question 20: A prompt injection attack against an LLM-powered customer service bot successfully makes it reveal internal system instructions. Which control would most directly mitigate this?
- Encrypting the model weights
- Enabling multi-factor authentication for end users
- Using a smaller model with fewer parameters
- Implementing output filtering and strict prompt sandboxing (Correct answer)
Correct answer: Implementing output filtering and strict prompt sandboxing
Output filtering and prompt sandboxing limit the model's ability to expose sensitive instructions or be manipulated via crafted inputs.
Question 21: Which storage class is most cost-effective for storing AI training data that is accessed once per month for retraining?
- Archive (cold) storage
- Standard (hot) storage
- Local SSD storage
- Infrequent access (warm) storage (Correct answer)
Correct answer: Infrequent access (warm) storage
Infrequent access storage tiers (e.g., AWS S3-IA, Azure Cool Blob) balance retrieval speed with lower storage costs for data accessed monthly.
Question 22: Which database replication topology provides the highest read scalability for an AI system that reads feature data 1000x more than it writes?
- Active-active bidirectional replication with conflict resolution
- Synchronous multi-master replication
- Single primary with multiple read replicas and load-balanced reads (Correct answer)
- Synchronous streaming replication with one standby
Correct answer: Single primary with multiple read replicas and load-balanced reads
A single primary with multiple read replicas distributes the read workload across many nodes while centralizing writes on the primary to avoid conflicts.
Question 23: What is the role of an IDS (Intrusion Detection System) versus an IPS (Intrusion Prevention System) in protecting AI infrastructure?
- IDS blocks traffic; IPS only logs it
- IDS detects and alerts on threats; IPS detects and actively blocks threats (Correct answer)
- They are functionally identical
- IDS operates at Layer 7; IPS operates at Layer 3 only
Correct answer: IDS detects and alerts on threats; IPS detects and actively blocks threats
An IDS passively monitors and generates alerts, while an IPS sits inline and can automatically drop or block malicious traffic in real time.
Question 24: A team discovers that their AI model performs well in development but poorly in production. This is BEST described as:
- Overfitting
- Train-serve skew (Correct answer)
- Underfitting
- Data leakage
Correct answer: Train-serve skew
Train-serve skew occurs when the data distribution or feature engineering in production differs from the training environment.
Question 25: An AI consultant is designing a disaster recovery plan for a production model serving pipeline. Which RTO/RPO combination represents the strictest requirement?
- RTO=1h, RPO=4h
- RTO=15min, RPO=1min (Correct answer)
- RTO=48h, RPO=48h
- RTO=24h, RPO=24h
Correct answer: RTO=15min, RPO=1min
Lower RTO (recovery time) and RPO (recovery point) values indicate stricter requirements; 15-minute RTO and 1-minute RPO demand near-real-time replication and hot standby.
Question 26: Which metric is most important when evaluating cloud GPU instance performance for distributed AI training?
- Disk IOPS
- Inter-GPU bandwidth (e.g., NVLink or InfiniBand throughput) (Correct answer)
- Public IP address allocation speed
- DNS resolution latency
Correct answer: Inter-GPU bandwidth (e.g., NVLink or InfiniBand throughput)
Distributed training relies on frequent gradient synchronization between GPUs; high inter-GPU bandwidth (NVLink, InfiniBand) directly reduces communication bottlenecks.
Question 27: What is one of the challenges in implementing AI in business?
- Easy integration with existing systems.
- Minimal workforce training.
- Lack of data and poor data quality (Correct answer)
- Low cost of implementation.
Correct answer: Lack of data and poor data quality
One of the most significant hurdles in implementing AI is the availability and quality of data. AI models rely heavily on large, clean, and relevant datasets for effective training and performance; without them, the AI system cannot learn accurately or provide reliable insights, leading to flawed outcomes.
Question 28: What is the primary purpose of a model registry in an MLOps architecture?
- Scheduling distributed training jobs across GPU clusters
- Storing raw training datasets for reproducibility
- Monitoring live model performance and triggering alerts
- Centralizing model artifact versioning, metadata, and stage promotion across the model lifecycle (Correct answer)
Correct answer: Centralizing model artifact versioning, metadata, and stage promotion across the model lifecycle
A model registry tracks model versions, associated metadata (metrics, lineage, parameters), and manages promotion stages (staging → production) to enable governed model lifecycle management.
Question 29: Which principle of responsible AI ensures that AI system decisions can be understood and traced by humans?
- Interoperability
- Explainability (Correct answer)
- Scalability
- Redundancy
Correct answer: Explainability
Explainability (also called interpretability) ensures that AI decisions and the reasoning behind them can be understood by developers, auditors, and affected individuals.
Question 30: Which gate is MOST appropriate to include in an AI CI/CD pipeline to prevent data quality regressions?
- Code style linting check
- Manual stakeholder sign-off
- Automated data validation and schema checks (Correct answer)
- UI smoke testing
Correct answer: Automated data validation and schema checks
Automated data validation checks enforce schema, null rates, and distribution bounds so pipeline failures catch data quality issues immediately.
Question 31: A company wants to implement Change Data Capture (CDC) from PostgreSQL to feed real-time feature updates into an AI feature store. Which PostgreSQL capability enables this?
- Physical streaming replication to a read replica
- Logical replication slots with WAL decoding (e.g., pgoutput or Debezium) (Correct answer)
- Trigger-based audit tables on each source table
- pg_cron scheduled queries
Correct answer: Logical replication slots with WAL decoding (e.g., pgoutput or Debezium)
Logical replication slots expose decoded WAL events as structured row-level changes that CDC tools like Debezium can consume and forward to downstream feature stores.
Question 32: What is a common challenge in machine learning?
- Overfitting models and data quality issues (Correct answer)
- Excess data being irrelevant.
- Lack of interest in AI.
- Low cost of computational power.
Correct answer: Overfitting models and data quality issues
A common and significant challenge in machine learning is overfitting, where a model learns the training data too well, including noise and outliers, leading to poor performance on new, unseen data. Another major challenge involves data quality issues, such as missing values, inconsistencies, or biases in the training data. These issues can severely impact a model's accuracy and reliability, making data preprocessing a crucial step.
Certified AI Consultant (CAIC™)
The CAIC™ is offered by the United States Artificial Intelligence Institute (USAII®) and validates expertise in AI strategy, machine learning, NLP, solution architecture, responsible AI, and the business value of AI. It is designed for professionals who advise organizations on adopting and implementing AI solutions.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds