Courseiva
AI Security →mediumMultiple Choice

AI0-001 AI Security Practice Question

A developer is deploying an AI service API. To protect against data leakage through API responses, which access control principle should be applied to API keys?

⚠ Common exam trap

CompTIA often tests the misconception that simplifying management (Option C) or using IP whitelisting (Option A) is sufficient for security, but the trap is that these approaches ignore the fundamental need for granular access control to prevent data leakage in multi-tenant AI API environments.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement least-privilege API access with scoped permissions

The least-privilege principle ensures that each API key is scoped to only the specific permissions required for its intended function, such as read-only access to a single endpoint. This minimizes the blast radius in case the key is compromised, preventing unauthorized access to other services or data. In AI service deployments, scoped permissions are often enforced via OAuth 2.0 scopes or IAM roles tied to the API key.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Disable API keys and rely on IP whitelisting only

    Why it's wrong here

    IP whitelisting restricts callers by network origin, so a leaked key still returns full responses to any host inside the allowed range — it never scopes what data a key can read. Whitelisting suits fixed-egress backends, but the stem asks which principle limits response content, so least privilege on each key is required.

  • ✗

    Use a single shared API key for all services

    Why it's wrong here

    A single shared key grants every service identical access, so a compromised or over-scoped caller can retrieve data beyond its remit, defeating least privilege. Shared keys suit internal, low-sensitivity tooling where all consumers legitimately need the same scope; here, per-service keys with minimal permissions are required.

  • ✗

    Grant all API keys full access to simplify management

    Why it's wrong here

    Granting every key full access removes the per-key scoping that limits a compromised credential to specific operations or data, so a leaked key exposes the whole service. It is tempting because a single unrestricted key genuinely simplifies rotation and onboarding, and would suit a single-tenant internal prototype where every caller is trusted equally.

  • ✓

    Implement least-privilege API access with scoped permissions

    Why this is correct

    Scoped, least-privilege API keys limit each key to the specific resources and operations it needs, so a compromised key cannot retrieve unrelated sensitive data. This satisfies the stem's data leakage constraint by containing the blast radius of any single key exposure.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

One of 962 original AI0-001 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.