Courseiva
AI Security →mediumMultiple Choice

AI0-001 AI Security Practice Question

A company uses a third-party AI model for sentiment analysis. They want to create a software bill of materials (SBOM) for this AI system. What is the PRIMARY purpose of an SBOM in this context?

⚠ Common exam trap

CompTIA often tests the distinction between an SBOM (software inventory for security and compliance) and model documentation (like model cards or datasheets) that cover performance, training, or usage details.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

To list all software components and dependencies used in the AI system

The primary purpose of an SBOM for an AI system is to provide a complete inventory of all software components, libraries, and dependencies that make up the system. This is critical for vulnerability management, license compliance, and supply chain risk assessment, especially when third-party AI models are integrated. It does not track performance metrics, training details, or user instructions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    To record the model's accuracy on benchmark datasets

    Why it's wrong here

    An SBOM inventories components, dependencies and licences, not performance metrics, so it cannot capture benchmark accuracy. It is tempting because accuracy evidence matters for model assurance, and benchmark results would belong in a model card or evaluation report — the correct artefact when the requirement is documenting measured performance rather than supply-chain composition.

  • ✓

    To list all software components and dependencies used in the AI system

    Why this is correct

    An SBOM enumerates every software component, library and dependency bundled into the AI system, giving the company visibility into what the third-party model contains. This inventory underpins vulnerability tracking and licence compliance across the sentiment analysis supply chain.

  • ✗

    To document the model's training hyperparameters

    Why it's wrong here

    An SBOM inventories components and dependencies, not training hyperparameters such as learning rate or batch size. Those belong in model cards or experiment-tracking tools, which suit reproducibility and audit of training runs. Here the requirement is component transparency, so hyperparameter documentation addresses a different artefact entirely.

  • ✗

    To provide a user manual for the AI model

    Why it's wrong here

    An SBOM enumerates components and dependencies, not usage instructions, so it cannot serve as a user manual. Documentation of operation is tempting because AI systems need guidance, but that belongs in model cards or user documentation, not the SBOM's component inventory.

About these practice questions

Courseiva writes every AI0-001 question from scratch — 962 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.