Topic module

AI Infrastructure and Operations

Auditors evaluate AI infrastructure, compute, storage, network, identity, access, APIs, deployment, logging, backup, reliability, and operational controls.

Long-form learning
Concept to Risk to Memory to Check-up

How to study for ISACA AAIA

Treat each item as an audit decision: understand AI risk, identify criteria, test evidence, assess control effectiveness, then report impact and follow-up.

Core concepts

Concept 1

AI infrastructure supports training, tuning, inference, retrieval, storage, pipelines, APIs, monitoring, and user access.

Exam cue: Scope infrastructure dependencies that can affect AI confidentiality, integrity, or availability.

Concept 2

Operational controls should address identity, least privilege, secrets, network segmentation, logging, capacity, backups, and change management.

Exam cue: Check privileged access to model endpoints, data stores, tools, and pipelines.

Concept 3

Reliability depends on availability targets, dependency mapping, failover, incident procedures, and monitoring.

Exam cue: Review backup and recovery for critical AI-supported processes.

Risk pitfalls and guardrails

Auditing the AI application while ignoring the serving platform.

Guardrail: Avoid treating AI audit as only a technical scan, accepting management assertions without evidence, or omitting prompts, data, vendors, and monitoring.

Leaving API keys and service accounts outside access review.

Guardrail: Avoid treating AI audit as only a technical scan, accepting management assertions without evidence, or omitting prompts, data, vendors, and monitoring.

Assuming infrastructure controls are sufficient without AI-specific logging.

Guardrail: Avoid treating AI audit as only a technical scan, accepting management assertions without evidence, or omitting prompts, data, vendors, and monitoring.

Memory anchors

Serving Platform

A serving platform hosts model or GenAI application calls for users and systems.

Least Privilege

Least privilege gives identities only the access needed for approved AI duties.

Secret Management

Secret management protects API keys, tokens, credentials, and certificates used by AI workloads.

Dependency Map

A dependency map identifies services, data stores, tools, models, vendors, and networks the AI system needs.

Capacity Control

Capacity control ensures compute, memory, storage, and throughput can meet AI workload demand.

Operational Log

An operational log records access, errors, latency, changes, prompts, outputs, and service events as appropriate.

Backup Control

Backup control preserves critical configurations, data, prompts, and assets needed for recovery.

Change Window

A change window controls when high-risk AI infrastructure updates may occur.

Checkpoint rule

Do the check-up only after you can summarize each concept in one sentence and identify one dangerous pitfall from memory.

Knowledge Check (after reading)

Short check-up to confirm understanding of this module.

Check-up Questions

1-2 question checkpoint

A production model endpoint is reachable directly from the internet although only an internal application uses it. What should be changed?

Which control BEST protects credentials used by an AI inference pipeline?

Answer all questions to submit.

Next step personalized recommendations

What is Pass Harbor?

Completely free exam prep for 317 U.S. exams.

  • Practice questions
  • Flashcards
  • Study guides
  • Mock exams
  • No registration
  • No paywall
  • Start instantly
No more expensive exam prep. Quality study tools should be accessible to everyone.