20+ practice questions focused on AI Security — one of the most tested topics on the CompTIA AI+ AI0-001 exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start AI Security PracticeA security team is threat modeling an AI system that recommends financial products. They want to analyze threats unique to the ML pipeline using STRIDE. Which threat is LEAST applicable to the data collection and preprocessing stage?
Explanation: Denial of Service (DoS) is least applicable to the data collection and preprocessing stage because DoS threats typically target the availability of the model serving infrastructure (e.g., API endpoints, inference servers) rather than the static data ingestion pipeline. In the ML pipeline, DoS is more relevant during model deployment and inference, where an attacker could overwhelm the system with requests, not during the collection or preprocessing of training data.
A financial firm deploys an LLM for automated trading advice. To prevent over-reliance, which combination of guardrails should be implemented? (Assume multiple options but choose the MOST comprehensive single approach.)
Explanation: Output filtering and content moderation directly address over-reliance by ensuring the LLM's trading advice includes disclaimers, risk warnings, and confidence levels, and by blocking overly assertive or misleading outputs. This combination prevents users from blindly trusting the model, which is critical in high-stakes financial environments where automated advice must be treated as a decision-support tool, not a definitive source.
An organization deploys a large language model (LLM) to summarize confidential emails. They are concerned about sensitive information being exposed through the model's responses. Which attack should they be MOST worried about?
Explanation: Prompt injection is the most immediate threat because it allows an attacker to override the LLM's system instructions, potentially causing it to reveal confidential email content in its responses. Unlike other attacks, prompt injection directly exploits the model's inability to distinguish between user input and trusted instructions, making it the primary vector for leaking sensitive data from summarization tasks.
A machine learning engineer notices that a fraud detection model's false positive rate has increased significantly over the past week. The model was retrained two weeks ago with new data. Which attack is MOST likely responsible?
Explanation: Data poisoning occurs when an attacker corrupts the training data used to retrain a model, causing the model to learn incorrect patterns. Since the fraud model was retrained two weeks ago with new data and the false positive rate rose afterward, the timing strongly implicates poisoned training data that skewed the model's decision boundary. This is the classic signature of a poisoning attack on the training pipeline.
A security team is threat modeling an AI-powered recommendation system. Using STRIDE, which THREE threats are MOST relevant to the model's training data pipeline?
Explanation: Option A is correct because tampering with training data (data poisoning) directly maps to STRIDE's Tampering category and is a primary threat to a training data pipeline, where an adversary alters or injects samples to corrupt the model's learned behavior. Option B is correct because elevation of privilege applies when an attacker gains unauthorized rights to the training pipeline (e.g., abusing weak IAM roles or service accounts) to manipulate jobs, data, or artifacts beyond their intended access. Option E is correct because information disclosure of training data, including model inversion attacks that reconstruct sensitive training samples from model outputs, is a core STRIDE threat to the confidentiality of the data pipeline. Option C does not belong because, although spoofing is a STRIDE category, the scenario's focus on the training data pipeline is better captured by tampering, privilege escalation, and data disclosure; spoofing of data sources is a less central and more generic concern here. Option D does not belong because repudiation concerns denying having performed an action and is primarily addressed through logging and non-repudiation controls, not a top threat to the integrity and confidentiality of the training data pipeline.
+15 more AI Security questions available
Practice all AI Security questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of AI Security. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
AI Security questions on the AI0-001 frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. AI Security is tested as part of the CompTIA AI+ AI0-001 blueprint. Practicing with targeted AI Security questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free AI0-001 practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but AI Security is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full AI Security practice session with instant scoring and detailed explanations.
Start AI Security Practice →