Courseiva
AI Security →easyMultiple Select

AI0-001 AI Security Practice Question

A data scientist is training a customer churn prediction model using sensitive customer data. To comply with data privacy regulations, they want to minimize the risk of membership inference attacks. Which TWO techniques should they consider?

⚠ Common exam trap

AI0-001 often tests the misconception that any privacy-adjacent technique (cross-validation, black-box APIs, data augmentation) mitigates membership inference, when only overfitting reduction and differential privacy address the underlying leakage.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use techniques to reduce overfitting, such as regularization or simpler models

Option C is correct because membership inference attacks exploit a model's tendency to overfit to its training data: an overfit model behaves very differently on training versus non-training samples, making it easier for an attacker to determine whether a specific record was in the training set. Reducing overfitting via L1/L2 regularization, dropout, early stopping, or simpler model architectures shrinks this generalization gap and thus lowers membership leakage. Option D is correct because differential privacy during training (e.g., DP-SGD with gradient clipping and calibrated noise) provides a formal, quantifiable guarantee that any single individual's presence or absence in the training set has only a bounded effect on the model's output, which directly limits what a membership inference attack can infer. Option A is not correct because k-fold cross-validation is a model-evaluation and hyperparameter-tuning technique; it does not by itself reduce the information a released model leaks about its training records. Option B is not correct because hiding confidence scores only removes one attack signal while the model still exposes predictions and gradients/behaviors that can be exploited; it is not a principled privacy defense. Option E is not correct because adding augmented or synthetic data does not provide any privacy guarantee and can even increase memorization of the original sensitive records.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use k-fold cross-validation to improve model accuracy

    Why it's wrong here

    Cross-validation partitions data to estimate generalisation error; it neither perturbs outputs nor bounds how much a trained model reveals about any single training record, so membership inference risk is unchanged. It is tempting because it is the standard technique for tuning hyperparameters and detecting overfitting, which is its actual purpose.

  • ✗

    Deploy the model as a black-box API with no confidence scores

    Why it's wrong here

    Hiding confidence scores reduces one attack signal, yet the model still memorises training records internally, so membership inference via shadow models or label-only queries persists. Black-box APIs are tempting because they limit information exposure generally, and suit scenarios where only hard predictions are contractually permitted.

  • ✓

    Use techniques to reduce overfitting, such as regularization or simpler models

    Why this is correct

    Reducing overfitting directly limits how much the model memorises individual training records, which is the mechanism membership inference attacks exploit. Regularisation and simpler models flatten the confidence gap between training and unseen data, satisfying the stem's requirement to minimise inference risk while preserving the churn model's predictive utility.

  • ✓

    Apply differential privacy during training

    Why this is correct

    Differential privacy adds calibrated noise during training, bounding any single record's influence on the model. This provides a formal guarantee limiting membership inference advantage, satisfying the regulatory requirement to minimise privacy risk for the churn model.

  • ✗

    Increase training data size through data augmentation

    Why it's wrong here

    Adding synthetic or duplicated records changes the training distribution but does not alter the model's per-record output sensitivity, so an adversary can still infer membership. Augmentation is tempting because it genuinely improves generalisation and mitigates overfitting on small datasets, which is the scenario where it belongs.

Visual reference

Client DHCP Server 1 Discover (broadcast) 2 Offer (IP: 192.168.1.10) 3 Request (I accept) 4 Acknowledge (lease confirmed) DORA — the four-step DHCP lease process

About these practice questions

One of 962 original AI0-001 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.