Courseiva
AI Security →mediumMultiple Choice

AI0-001 AI Security Practice Question

A company uses a third-party pre-trained language model for a sentiment analysis API. They want to ensure the model has not been backdoored. Which supply chain security practice is MOST effective?

⚠ Common exam trap

AI0-001 often tests the confusion between runtime monitoring controls (which detect attacks after deployment) and supply chain provenance controls (which verify the artifact before use) — candidates pick 'monitor API usage' because it sounds proactive.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Obtain and verify a Software Bill of Materials (SBOM) for the model

An SBOM provides a formal, verifiable inventory of the model's components, dependencies, versions, and provenance, which is the foundation for detecting tampering or unauthorized modifications in the AI supply chain. Verifying the SBOM against trusted hashes or signatures lets the company confirm the model artifact they received matches what the vendor published, catching backdoors injected during development or distribution. This is the recognized supply chain security control for third-party AI artifacts.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Monitor API usage for anomalous patterns

    Why it's wrong here

    Usage monitoring detects anomalous inference behaviour after deployment, but cannot verify whether malicious weights or triggers were embedded in the pre-trained artefact itself. It is tempting because runtime anomaly detection genuinely suits detecting compromised credentials or abuse of a live API, yet backdoor assurance requires scanning or attestation of the model supply chain before use.

  • ✗

    Use federated learning to train the model

    Why it's wrong here

    Federated learning distributes training across clients to keep data local; it neither detects nor removes malicious triggers embedded in third-party weights. It is tempting because it addresses supply chain privacy concerns, and it would be the right choice when the requirement is training on decentralised sensitive data rather than verifying model integrity.

  • ✗

    Implement differential privacy during training

    Why it's wrong here

    Differential privacy adds noise to training data to limit memorisation and membership inference, so it neither detects nor removes an intentionally implanted trigger. It is tempting because it genuinely protects individual records in sensitive training sets, but backdoor assurance demands provenance verification or scanning of the supplied weights instead.

  • ✓

    Obtain and verify a Software Bill of Materials (SBOM) for the model

    Why this is correct

    An SBOM enumerates every component and dependency in the model artefact, letting the company detect tampered or unauthorised layers before deployment. Verifying it against the supplier's signed manifest directly addresses the backdoor concern, which runtime monitoring or prompt filtering cannot detect in a pre-trained model.

About these practice questions

Courseiva writes every AI0-001 question from scratch — 962 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.