AI0-001 AI Security Practice Question
A developer is deploying an AI service API. To protect against data leakage through API responses, which access control principle should be applied to API keys?
⚠ Common exam trap
CompTIA often tests the misconception that simplifying management (Option C) or using IP whitelisting (Option A) is sufficient for security, but the trap is that these approaches ignore the fundamental need for granular access control to prevent data leakage in multi-tenant AI API environments.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement least-privilege API access with scoped permissions
The least-privilege principle ensures that each API key is scoped to only the specific permissions required for its intended function, such as read-only access to a single endpoint. This minimizes the blast radius in case the key is compromised, preventing unauthorized access to other services or data. In AI service deployments, scoped permissions are often enforced via OAuth 2.0 scopes or IAM roles tied to the API key.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disable API keys and rely on IP whitelisting only
Why it's wrong here
IP whitelisting restricts callers by network origin, so a leaked key still returns full responses to any host inside the allowed range — it never scopes what data a key can read. Whitelisting suits fixed-egress backends, but the stem asks which principle limits response content, so least privilege on each key is required.
- ✗
Use a single shared API key for all services
Why it's wrong here
A single shared key grants every service identical access, so a compromised or over-scoped caller can retrieve data beyond its remit, defeating least privilege. Shared keys suit internal, low-sensitivity tooling where all consumers legitimately need the same scope; here, per-service keys with minimal permissions are required.
- ✗
Grant all API keys full access to simplify management
Why it's wrong here
Granting every key full access removes the per-key scoping that limits a compromised credential to specific operations or data, so a leaked key exposes the whole service. It is tempting because a single unrestricted key genuinely simplifies rotation and onboarding, and would suit a single-tenant internal prototype where every caller is trusted equally.
- ✓
Implement least-privilege API access with scoped permissions
Why this is correct
Scoped, least-privilege API keys limit each key to the specific resources and operations it needs, so a compromised key cannot retrieve unrelated sensitive data. This satisfies the stem's data leakage constraint by containing the blast radius of any single key exposure.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
About these practice questions
One of 962 original AI0-001 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.