AI0-001 AI Security Practice Question
A company is integrating a third-party pre-trained model into its product. To address supply chain security, which THREE actions are most important? (Choose three.)
⚠ Common exam trap
CompTIA often tests the distinction between supply chain security (provenance, SBOM, backdoor checks) and operational security (encryption, federated learning), so candidates mistakenly pick options that sound security-related but address different threat models.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Checking the model for backdoors using validation techniques
Option A is correct because validating a third-party pre-trained model for backdoors (e.g., via trigger-pattern scanning, anomaly detection, or red-team testing) directly mitigates the risk that a maliciously tampered model contains hidden behaviors that activate on specific inputs. Option C is correct because an SBOM for AI components enumerates the model's dependencies, libraries, weights, and versions, giving the organization the transparency needed to track and remediate vulnerabilities across the supply chain. Option E is correct because vetting the model's provenance and dataset lineage verifies where the model and its training data came from, ensuring they originate from trusted sources and have not been poisoned or tampered with. Option B is not appropriate here because homomorphic encryption protects data during inference but does not address supply chain integrity of the model itself. Option D is also not appropriate because federated learning is a training architecture for future updates and does not secure the initial integration of a third-party pre-trained model.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Checking the model for backdoors using validation techniques
Why this is correct
Validating the pre-trained model for backdoors detects trojaned weights or triggers that activate malicious behaviour after integration. This addresses supply chain security by verifying the third-party artefact before deployment, since provenance alone cannot guarantee the model is free of implanted malicious functionality.
- ✗
Using homomorphic encryption for model inference
Why it's wrong here
Homomorphic encryption protects data during inference, not the model artefact itself; supply chain security requires verifying model provenance, integrity and scanning for embedded threats. It is tempting because it addresses inference privacy, and would be correct when processing sensitive inputs without exposing plaintext to the model host.
- ✓
Creating a software bill of materials (SBOM) for AI components
Why this is correct
An SBOM inventories every AI component, including the third-party pre-trained model, its dependencies and licences. This directly satisfies the supply chain security constraint by giving the company visibility into what it is importing, enabling vulnerability tracking and provenance verification for the externally sourced model.
- ✗
Implementing federated learning for future updates
Why it's wrong here
Federated learning governs how future updates are trained across distributed data, not how a third-party pre-trained model is vetted before integration. It is tempting because it strengthens update privacy, and would be correct when training collaboratively on decentralised sensitive datasets without centralising raw data.
- ✓
Vetting the model's provenance and dataset lineage
Why this is correct
Vetting provenance and dataset lineage directly addresses supply chain security by verifying the model's origin, training data sources, and any embedded artefacts before integration. This satisfies the stem's requirement to assess third-party risk, exposing tampering, poisoned data, or licence issues that blind deployment would miss.
About these practice questions
This AI0-001 question is part of Courseiva's 962-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.