Courseiva
AI Security →hardMultiple Select

AI0-001 AI Security Practice Question

A company is developing an AI-powered recruitment tool. To prevent bias and ensure fairness, they want to audit the model's training data and outputs. Which TWO practices should they implement as part of secure AI development?

⚠ Common exam trap

AI0-001 often tests the confusion between ML performance hyperparameters (learning rate, batch size, parallelism) and genuine security/governance controls, so candidates pick tuning knobs instead of practices that actually mitigate bias and protect data.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Threat modeling using STRIDE for AI-specific threats

Option B is correct because threat modeling with STRIDE helps identify AI-specific security and fairness risks (e.g., tampering with training data, information disclosure, or elevation of privilege in the ML pipeline) before they manifest, directly supporting a secure and auditable AI development process. Option D is correct because implementing access controls on the training dataset enforces least privilege and prevents unauthorized modification or exfiltration of data, which is essential for maintaining data integrity and enabling trustworthy bias audits. Options A and E are incorrect because model parallelism and larger batch sizes are performance/scalability tuning techniques that do not address fairness, bias auditing, or security. Option C is incorrect because increasing the learning rate is a hyperparameter change that affects convergence and training dynamics, not the governance or security posture of the AI system.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enabling model parallelism

    Why it's wrong here

    Model parallelism splits a single model across devices to fit memory or speed training; it neither records data lineage nor inspects predictions for bias. It is the right choice when a model exceeds one accelerator's memory, not when the requirement is auditing training data and outputs for fairness.

  • ✓

    Threat modeling using STRIDE for AI-specific threats

    Why this is correct

    STRIDE threat modelling adapted for AI enumerates threats such as tampering with training data and information disclosure through outputs, exposing bias-introducing attack paths before deployment. This satisfies the requirement to audit training data and outputs as part of secure AI development.

  • ✗

    Increasing the model's learning rate

    Why it's wrong here

    Learning rate controls how far weights shift per update; it has no bearing on inspecting training data or auditing outputs for bias. Raising it risks unstable convergence. Tuning the learning rate belongs to model-training optimisation, not to the data-provenance and output-review controls fairness auditing requires.

  • ✓

    Implementing access controls on the training dataset

    Why this is correct

    Access controls restrict who can read or modify the training dataset, satisfying the audit requirement by preserving data provenance and preventing unauthorised tampering that could introduce bias. Combined with output logging, this enables traceable review of which data influenced model behaviour.

  • ✗

    Using a larger batch size

    Why it's wrong here

    Batch size governs how many samples pass through per gradient update, affecting throughput and convergence stability, not data inspection or output auditing. Larger batches suit accelerating training on parallel hardware; they contribute nothing to documenting dataset composition or detecting biased predictions.

About these practice questions

One of 962 original AI0-001 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.