AI0-001 AI Security Practice Question
A company is deploying an AI-based document summarization tool that processes confidential internal reports. The security policy requires that the AI system must not retain any information from the documents after generating the summary. Which measure should be implemented to meet this requirement?
⚠ Common exam trap
The trap here is equating data protection measures like encryption with data retention prevention, which are different security objectives.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable stateless inference so no data is stored
Stateless inference ensures that each request is processed independently without storing any data from the input. This directly prevents the AI system from retaining information, which is the core requirement. Other measures like encryption or access control protect data but do not address retention.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable stateless inference so no data is stored
Why this is correct
Stateless inference ensures that the model processes each request independently without retaining any memory of the input. After generating the summary, the input data is discarded, and no information is persisted. This directly satisfies the requirement that the AI system must not retain any information from the documents, as there is no storage or logging of the content.
- ✗
Implement role-based access control for the AI tool
Why it's wrong here
Role-based access control restricts who can use the tool or access its outputs, but it does not control whether the AI system itself retains information from the documents. Even with strict access control, the system could still store data internally. Thus, it does not meet the non-retention requirement.
- ✗
Encrypt the documents at rest and in transit
Why it's wrong here
Encryption protects data from unauthorized access during storage and transmission, but it does not prevent the AI system from retaining information internally. If the system logs or caches the document content, encryption alone does not address retention. The requirement is about non-retention, not just protection, so this measure is insufficient.
- ✗
Use a private cloud instance for the AI service
Why it's wrong here
A private cloud instance provides dedicated infrastructure but does not guarantee that the AI system will not retain data. The application could still log or cache inputs. The requirement is specifically about the AI's behavior regarding data retention, not the hosting environment. Therefore, this measure does not ensure non-retention.
About these practice questions
Courseiva writes every AI0-001 question from scratch — 962 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.