AI0-001 AI Security Practice Question
A company is fine-tuning a pre-trained open-source model for a sensitive application. They want to detect if the model contains a backdoor inserted by the original developers. Which supply chain security measure is most directly applicable?
⚠ Common exam trap
The exam often tests the distinction between runtime security controls (like input validation) and supply chain provenance measures (like SBOM), so the trap here is that candidates confuse operational defenses with the static analysis needed to detect pre-installed backdoors.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a software bill of materials (SBOM) for the model and its dependencies
A Software Bill of Materials (SBOM) for the model and its dependencies provides a formal, machine-readable inventory of all components, including the base model, training data sources, and third-party libraries. This allows the security team to trace the provenance of each component and identify known vulnerabilities or suspicious artifacts that could indicate a backdoor inserted by the original developers. SBOMs are a key supply chain security measure recommended by frameworks like NIST SP 800-161 and are directly applicable to detecting unauthorized modifications in pre-trained models.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Apply input validation and sanitization techniques
Why it's wrong here
Input validation defends against injection, not supply chain backdoors.
- ✗
Use homomorphic encryption for model weights
Why it's wrong here
Homomorphic encryption protects data in use but does not detect backdoors.
- ✗
Implement differential privacy during fine-tuning
Why it's wrong here
Differential privacy protects training data privacy, not detect backdoors.
- ✓
Create a software bill of materials (SBOM) for the model and its dependencies
Why this is correct
An SBOM provides transparency into the model's origin and components, helping identify tampered or backdoored parts.
About these practice questions
This AI0-001 question is part of Courseiva's 962-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.