AI0-001 AI Security Practice Question
A data scientist is training a model to detect fraudulent transactions. To protect customer privacy, the team wants to ensure that the model does not inadvertently memorize and reveal sensitive information about individuals in the training set. Which technique should be applied during training?
⚠ Common exam trap
The AI0-001 exam often tests the misconception that federated learning alone guarantees privacy, when in fact it only addresses data locality and must be combined with differential privacy to prevent model inversion or membership inference attacks.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Differential privacy
Differential privacy is the correct technique because it adds calibrated noise to the training process or output, ensuring that the model cannot infer whether any specific individual's data was included in the training set. This directly addresses the goal of preventing memorization and leakage of sensitive information while still allowing the model to learn useful patterns for fraud detection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Differential privacy
Why this is correct
Differential privacy adds calibrated noise to training gradients or outputs, mathematically bounding any single individual's influence on the model. This directly satisfies the stem's requirement that the model cannot memorise and reveal sensitive customer details, providing a provable privacy guarantee rather than relying on heuristic anonymisation of the transaction data.
- ✗
Federated learning
Why it's wrong here
Federated learning keeps raw data on distributed clients and shares only model updates, so it addresses data locality, not memorisation within a centrally trained model. It is tempting because it genuinely protects privacy when data cannot be pooled, but it does nothing to stop the trained model revealing training records.
- ✗
Homomorphic encryption
Why it's wrong here
Homomorphic encryption lets computation run on encrypted data, protecting data in use, but it does not alter the training objective or prevent a model from memorising and later leaking training records. It is tempting because it is a genuine privacy-enhancing technology, yet it addresses confidentiality during processing, not memorisation.
- ✗
Model quantization
Why it's wrong here
Quantization reduces numeric precision of weights and activations to shrink model size and speed inference; it does not constrain what the model learns, so memorisation of training records persists. It is tempting because it is a common optimisation step, but it targets efficiency, not the privacy requirement in the stem.
About these practice questions
This AI0-001 question is part of Courseiva's 962-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.