AI0-001 AI Governance and Ethics Practice Question
A hospital is implementing an AI system to analyze patient X-rays for potential fractures. The hospital must comply with HIPAA regulations. Which privacy-preserving technique allows the model to be trained on data from multiple hospitals without sharing raw patient data?
⚠ Common exam trap
AI0-001 often tests privacy-preserving techniques; candidates may confuse federated learning (no raw data sharing) with differential privacy (noise addition) or anonymisation (data sharing after de-identification).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Federated learning
Federated learning allows multiple hospitals to collaboratively train a model without sharing raw patient data. Each hospital trains a local model on its own data, and only model updates (e.g., gradients or weights) are shared with a central server, which aggregates them. This preserves privacy and helps comply with HIPAA by keeping patient data on-premises.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Federated learning
Why this is correct
Federated learning trains a shared model locally at each hospital, exchanging only model updates such as gradients rather than raw X-ray images. This satisfies HIPAA by keeping patient data within each hospital's boundary while still producing a model trained across multiple sites.
- ✗
Differential privacy
Why it's wrong here
Differential privacy adds calibrated noise to query outputs or gradients, protecting individual records, but it does not let separate hospitals train a shared model without pooling data. Federated learning is the technique for that. Differential privacy is tempting because it is a recognised HIPAA-aligned privacy control for published statistics and analytics.
- ✗
Data anonymisation
Why it's wrong here
Anonymisation strips identifiers before training, but the model still needs pooled raw records, which HIPAA-covered hospitals cannot export. It fits publishing or analysing a dataset where no cross-site model training and no re-identification need exist.
- ✗
Data pseudonymisation
Why it's wrong here
Pseudonymisation replaces identifiers with tokens while raw records still leave each hospital, and re-identification remains possible via the mapping. It suits internal analytics where a trusted holder retains the key and data never crosses organisational boundaries.
About these practice questions
One of 962 original AI0-001 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.