AI0-001 AI Security Practice Question
A financial services company is deploying a text-generation model that drafts internal reports. To reduce the risk of the model memorizing and later reproducing personally identifiable information from its fine-tuning dataset, the security team wants to add noise to the training process in a way that provides a mathematical privacy guarantee. Which approach should they implement?
⚠ Common exam trap
The trap here is assuming that any privacy hygiene step, such as hashing identifiers or encrypting storage, provides the same mathematical guarantee as a formal differential privacy mechanism.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use differential privacy with a calibrated noise multiplier during training.
Differential privacy is the only listed technique that provides a formal, quantifiable guarantee that any single training record has limited influence on the model. By adding calibrated noise during training, the organization bounds memorization of PII in the report-drafting model, which directly mitigates the extraction risk. The other controls either reduce overfitting indirectly, obscure identifiers without a guarantee, or protect data only at rest.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Hash all personally identifiable information in the fine-tuning corpus before training.
Why it's wrong here
Hashing identifiers removes direct names but the model can still memorize surrounding context, and hashed tokens remain learnable patterns that can be reconstructed or correlated. Hashing is a data-preparation hygiene step, not a privacy mechanism with a formal guarantee, so it cannot bound how much the fine-tuned report generator leaks about any individual record.
- ✗
Encrypt the fine-tuning dataset at rest and enforce role-based access to the storage bucket.
Why it's wrong here
Encryption at rest and access control protect the dataset while stored, but they do nothing about memorization inside the trained weights. Once the model is trained, the parameters themselves can encode PII and be extracted through inference, so storage-layer controls fail to address the privacy risk described in the scenario.
- ✓
Use differential privacy with a calibrated noise multiplier during training.
Why this is correct
Differential privacy injects calibrated noise (for example, via DP-SGD) into the training process and yields a formal epsilon-delta privacy guarantee bounding how much any single training record can influence the model. For a model fine-tuned on internal reports containing PII, this directly limits memorization and extraction risk while preserving utility within the chosen privacy budget.
- ✗
Apply L2 regularization to the model weights during fine-tuning.
Why it's wrong here
L2 regularization penalizes large weights to reduce overfitting, which can indirectly lower memorization, but it offers no formal, quantifiable privacy guarantee and no calibrated noise mechanism. An attacker with query access can still extract training examples through targeted prompting, so it does not satisfy the requirement of a mathematical privacy bound for this report-drafting model.
About these practice questions
One of 962 original AI0-001 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.