AI0-001 AI Security Practice Question
A company is deploying a new AI system that processes personal data. To comply with privacy regulations, they want to minimize the risk of membership inference attacks. Which THREE practices should they adopt? (Select three.)
⚠ Common exam trap
CompTIA often tests the misconception that larger models are inherently more secure, but the trap here is that increasing model size actually amplifies overfitting and memorization, thereby increasing vulnerability to membership inference attacks.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use differential privacy during training
Option A (Use differential privacy during training) is correct because differential privacy adds calibrated noise to the training process, which bounds how much any single individual's data can influence the model, directly reducing the signal that membership inference attacks exploit. Option B (Implement access controls on the model API) is correct because membership inference typically requires repeated, query-based probing of the model's outputs; restricting who can query the API and how often limits an adversary's ability to run the statistical tests needed to infer training-set membership. Option D (Enable audit logging of all model interactions) is correct because logging queries and responses enables detection of the anomalous, high-volume probing patterns characteristic of membership inference attempts, supporting timely investigation and response. Option C (Increase model size to improve accuracy) is not correct because larger, higher-capacity models tend to overfit training data more, which increases rather than minimizes membership inference risk. Option E (Use homomorphic encryption for model inference) is not correct because homomorphic encryption protects data confidentiality during computation but does not prevent an authorized client from analyzing the returned outputs to infer membership.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use differential privacy during training
Why this is correct
Differential privacy adds calibrated noise during training, bounding any single record's influence on the model. This directly reduces the confidence gap between member and non-member records that membership inference exploits, satisfying the regulatory risk-minimisation goal.
- ✓
Implement access controls on the model API
Why this is correct
Access controls on the model API restrict who can query the model and how often, reducing the query volume attackers need to run membership inference. Limiting unauthorised probing directly lowers the risk of inferring training-set membership.
- ✗
Increase model size to improve accuracy
Why it's wrong here
Larger models memorise training records more readily, sharpening the confidence gap that membership inference exploits, so this raises rather than lowers risk. It is tempting because scaling parameters genuinely improves accuracy on legitimate tasks, and that is the scenario where enlarging the model is the right call.
- ✓
Enable audit logging of all model interactions
Why this is correct
Audit logging records who queried the model and when, enabling detection of the repeated probing typical of membership inference attempts. It satisfies the privacy-compliance constraint by providing traceability, so anomalous access patterns can be investigated and the training-data exposure risk reduced.
- ✗
Use homomorphic encryption for model inference
Why it's wrong here
Homomorphic encryption protects data while computations run on it, but membership inference exploits the model's output patterns, which encrypted inference does not alter. It is tempting because it genuinely preserves confidentiality in outsourced computation scenarios, such as a hospital sending encrypted records to a third-party analytics provider.
About these practice questions
One of 962 original AI0-001 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.