AI0-001 AI Security Practice Question
A financial services company trains a gradient-boosted classifier on customer transaction data to flag fraudulent purchases. The training set includes a rare subset of private banking clients whose transaction patterns are highly distinctive. A red-team exercise shows that an attacker with black-box API access can determine whether a specific private banking client's record was in the training set with 85% accuracy. Which technique should the security team prioritize to reduce this specific risk while preserving most model utility?
⚠ Common exam trap
The trap here is assuming that encrypting the model or throttling the API addresses privacy leakage, when membership inference exploits statistical patterns in predictions rather than unauthorized file or endpoint access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Apply differential privacy during training by adding calibrated noise to the gradient updates.
The scenario describes membership inference enabled by distinctive training records, so the fix must alter the training process itself. Differential privacy during training directly limits per-record influence, which is the mechanism the attacker exploits. Controls on storage, transport, or query volume do not change the statistical relationship between the model's outputs and individual training examples, so they cannot reduce the measured inference accuracy.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Retrain the model using only synthetic transaction records generated by a GAN.
Why it's wrong here
Fully synthetic retraining can reduce leakage, but GAN-generated transaction data often fails to capture the rare private banking patterns the fraud model needs, sharply degrading detection of the very fraud cases that matter. It also introduces its own privacy risks if the generator overfits the original records, so it is not the targeted fix here.
- ✗
Encrypt the model weights at rest using AES-256 and restrict API access with mutual TLS.
Why it's wrong here
Encryption at rest and mutual TLS protect the model file and API channel from unauthorized access, but they do nothing about the statistical leakage that lets an attacker infer training membership from query responses. The attacker in this scenario already has legitimate black-box API access, so transport and storage controls are irrelevant to the membership inference signal.
- ✓
Apply differential privacy during training by adding calibrated noise to the gradient updates.
Why this is correct
Differential privacy bounds how much any single training record can influence the model, so an attacker cannot reliably distinguish whether a particular private banking client's record was included. Calibrated noise in the training process directly targets membership inference while allowing a tunable privacy budget that retains most predictive utility for fraud detection.
- ✗
Add rate limiting and query logging to the prediction API to throttle suspicious enumeration.
Why it's wrong here
Rate limiting and logging are useful operational controls against bulk model extraction, but membership inference can succeed with relatively few well-chosen queries. In this scenario the attacker already achieves 85% accuracy, indicating the leakage is statistical rather than volumetric, so throttling the API does not close the underlying privacy gap.
About these practice questions
This AI0-001 question is part of Courseiva's 962-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.