Courseiva
AI Security →mediumMultiple Choice

AI0-001 AI Security Practice Question

A financial services company trains a gradient-boosted classification model on a dataset that includes customer account balances. The security team wants to limit how much any single customer's balance can influence the model's learned parameters, because an attacker who obtains the trained model could otherwise probe it to recover specific training values. Which technique should they apply during training to cap the influence of individual records?

⚠ Common exam trap

The trap here is assuming that any privacy-preserving preprocessing step, such as hashing or encryption, limits how much a training record influences the model, when only differential privacy provides that formal bound.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Apply differential privacy with a bounded per-record gradient clipping norm and calibrated noise.

Differential privacy with per-record gradient clipping and calibrated noise is the only listed technique that formally bounds how much any single training record can change the model's parameters. That bound is what prevents an attacker with access to the trained model from reliably reconstructing or confirming individual customer balances, whereas hashing, regularization, and at-rest encryption leave the influence of individual records unbounded.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Increase the model's L2 regularization coefficient until training accuracy drops significantly.

    Why it's wrong here

    L2 regularization penalizes large weights across all features and can reduce overfitting, but it does not provide a per-record influence bound. A single outlier record can still dominate the gradient update and be memorized within the remaining weight budget. Without per-example clipping and noise, there is no formal privacy guarantee against a probing attacker.

  • ✓

    Apply differential privacy with a bounded per-record gradient clipping norm and calibrated noise.

    Why this is correct

    Differential privacy bounds each training record's contribution by clipping per-example gradients to a fixed norm, then adds calibrated noise to the aggregate update. This mathematically limits how much any one account balance can shift the learned parameters, so an attacker probing the released model cannot reliably infer whether a specific customer's record was present or recover its exact value.

  • ✗

    Hash each customer account balance with SHA-256 before feeding it to the training pipeline.

    Why it's wrong here

    Hashing is a one-way transformation, but the model still trains on the hashed value and can memorize it. Because the same balance always produces the same hash, an attacker probing the model could still link repeated values and infer information. Hashing provides no formal bound on per-record influence and does not add the calibrated noise that privacy guarantees require.

  • ✗

    Encrypt the model artifacts at rest with a customer-managed key in the cloud KMS.

    Why it's wrong here

    Encryption at rest protects the stored model file from unauthorized disk access, but it does nothing once the model is loaded into memory or exposed through an inference API. An attacker who can query the running model gains the same probing ability regardless of how the artifact was encrypted. It does not constrain how individual training records influenced the parameters.

About these practice questions

One of 962 original AI0-001 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.