AI0-001 AI Security Practice Question
A healthcare analytics team deploys a federated learning system across three hospitals to train a diagnostic model without centralizing patient records. A security researcher demonstrates that the shared gradient updates can still be inverted to reconstruct individual patient images. Which additional protection should the team implement on the client updates before aggregation?
⚠ Common exam trap
The trap here is believing that secure aggregation alone hides individual updates, when the aggregate in a small cohort can still be inverted to reconstruct patient data.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add local differential privacy by clipping and noising each hospital's gradient update before transmission.
The demonstrated attack reconstructs patient images from shared gradient updates, so the fix must alter the gradients before they leave each hospital. Local differential privacy, applied by clipping and noising each client update at the source, ensures no recoverable raw gradient is ever transmitted. Transport encryption, secure aggregation, and additional rounds leave the underlying gradient content exploitable by inversion techniques.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Require mutual TLS between the aggregation server and each hospital client.
Why it's wrong here
Mutual TLS authenticates the endpoints and encrypts gradients in transit, but the aggregation server still receives and processes plaintext updates. Once decrypted on the server, those updates remain vulnerable to gradient inversion. Transport security addresses interception, not the reconstruction risk that arises from the mathematical content of the shared gradients themselves.
- ✓
Add local differential privacy by clipping and noising each hospital's gradient update before transmission.
Why this is correct
Local differential privacy perturbs each client's update at the source, so even a curious aggregator or an attacker who intercepts updates cannot invert them to recover patient images. Because noise is added before the update leaves the hospital, the raw gradient never exists in a recoverable form outside the client, directly countering the demonstrated reconstruction attack.
- ✗
Increase the number of federated rounds so that gradients converge more slowly.
Why it's wrong here
More rounds may change convergence behavior, but each round still transmits an update derived from patient data. A reconstruction attack can be mounted on any single round's update, so adding rounds does not remove the vulnerability and may even provide more snapshots for an attacker to combine. It does not add privacy protection to the shared gradients.
- ✗
Apply secure aggregation with pairwise masking so the server only sees the summed update.
Why it's wrong here
Secure aggregation prevents the server from inspecting any individual client's update by cryptographically masking each contribution, but it does not change what an attacker can learn if they obtain the aggregate or participate in the protocol. Gradient inversion can still occur from the aggregate in small cohorts, so secure aggregation alone is not sufficient for this reconstruction threat.
About these practice questions
This AI0-001 question is part of Courseiva's 962-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.