Skip to content

612-51 Practice Questions

Prepare for 612-51 with more than an answer.

150 questions in the full set12 sample questionsUpdated Mar 12, 2026
Time limit
180 minutes
Questions on the exam
100
Passing score
70% (cut scores can range from 60% to 85% depending on exam form)
Level
Professional
Valid for
Governed by EC-Council Continuing Education (ECE) scheme
Domains covered on the exam 11
  1. AI Foundations and Technology Ecosystem9%
  2. AI Concerns, Ethical Principles, and Responsible AI9%
  3. AI Strategy and Planning9%
  4. AI Governance and Frameworks10%
  5. AI Regulatory Compliance10%
  6. AI Risk and Threat Management10%
  7. Third-Party AI Risk Management and Supply Chain Security9%
  8. AI Security Architecture and Controls9%
  9. Building Privacy, Trust, and Safety in AI Systems9%
  10. AI Incident Response and Business Continuity8%
  11. AI Assurance, Testing, and Auditing8%
  1. 1

    Before launching a Generative AI initiative, an organization conducts a Data Maturity Assessment. They find that their unstructured data (documents, emails) lacks classification labels and access controls. Why is this a 'Blocker' for the AI strategy?

    Show answer details

    Correct answer: D

    In Generative AI (specifically RAG or fine-tuning), the model flattens access controls. If the underlying data is not classified and segregated, a user with low clearance might ask the AI a question that retrieves sensitive data (like executive salaries or trade secrets) that the AI was trained on or has access to. Without data governance (classification/ACLs), GenAI becomes a massive data leakage vector. This is a strategic blocker.

  2. 2

    When defining an AI Roadmap, an organization faces a 'Build vs. Buy' decision for a Customer Support Agent. From a Responsible AI governance perspective, what is the primary advantage of the 'Build' (Open Source / Custom) approach over 'Buy' (SaaS API)?

    Show answer details

    Correct answer: C

    The 'Build' approach gives the organization complete control over the entire stack. This allows for specific interventions to mitigate bias, strict control over where data is stored (data sovereignty), and the ability to audit the model weights directly. 'Buy' (SaaS) often involves 'black box' APIs where the organization cannot inspect the model's inner workings or guarantee how their data is used for future training by the vendor.

  3. 3

    An organization is establishing an AI Ethics Board. To ensure the board is effective and not just 'ethics washing,' which structural characteristic is MOST critical?

    Show answer details

    Correct answer: C

    For an AI Ethics Board to be effective, it must have 'teeth'—specifically, the formal authority (decision rights) to stop or modify projects that do not meet ethical standards. Without veto power or a binding escalation path to the CEO/Board of Directors, the Ethics Board is merely advisory and can be ignored when business pressure mounts, leading to 'ethics washing' (appearance of ethics without substance).

  4. 4

    A multinational financial institution is implementing a new credit risk scoring model based on deep learning. The Governance Committee requires a strict MLOps pipeline to ensure reproducibility and compliance with the EU AI Act. Specifically, they need to ensure that no model is deployed to production without passing a specific set of bias and performance checks.

    The pipeline stages are: Data Preparation -> Training -> Evaluation -> Model Registry -> Production Deployment -> Monitoring. At which stage should the 'Governance Gate' be strictly enforced to prevent non-compliant models from reaching the inference endpoint, and what specific artifact must be signed off?

    Show answer details

    Correct answer: A

    The critical governance gate in an MLOps pipeline for compliance is after the model has been trained, validated, and registered, but BEFORE it is deployed to production. This ensures that only models with a signed-off Model Card (documenting intended use, limitations, and performance) and a Validation Report (proving it meets bias and accuracy thresholds) are released. Placing the gate here prevents non-compliant artifacts from impacting users.

    flowchart LR Data[Data Prep] --> Train[Training] Train --> Eval[Evaluation] Eval --> Reg[Model Registry] Reg --> Gate{Governance Gate} Gate --Pass--> Deploy[Production Deployment] Gate --Fail--> Reject[Archive/Retrain] style Gate fill:#f96,stroke:#333,stroke-width:2px
  5. 5

    An organization is debating whether to deploy a Generative AI model or a Discriminative AI model for a fraud detection use case. The Chief Risk Officer (CRO) is concerned about 'hallucinations' and the ability to explain specific denial decisions to regulators. Which technology choice presents the HIGHEST governance risk regarding factual accuracy and explainability in this context?

    Show answer details

    Correct answer: D

    Generative AI models (like LLMs) are designed to create new content based on learned patterns and are statistically probabilistic in a way that can lead to 'hallucinations' (plausible but factually incorrect outputs). For fraud detection, where factual accuracy and precise explainability of a binary decision (Fraud/Not Fraud) are required, Generative AI introduces significantly higher governance risks compared to Discriminative AI, which classifies data based on decision boundaries.

  6. 6

    A healthcare provider is deploying a Retrieval-Augmented Generation (RAG) system to assist doctors with diagnosis. The system retrieves medical journals from a vector database to ground the LLM's answers. From a governance perspective, what is the PRIMARY risk specific to the 'Retrieval' component of this architecture?

    Show answer details

    Correct answer: A

    In a RAG architecture, the 'Retrieval' component fetches context (chunks of text) based on semantic similarity. If the vector database contains outdated medical protocols or retrieves irrelevant information that semantically matches the query, the LLM (the 'Generation' component) will use this bad context to generate an answer. Governance must ensure the knowledge base is curated and version-controlled to prevent the 'garbage in, garbage out' effect at the retrieval stage.

Create an account to continue.