AI0-001 AI Security Practice Question
A hospital's AI team is training a diagnostic imaging model on chest X-rays. The dataset is small and contains sensitive patient information. The security team wants to ensure that even if the trained model is stolen, individual patients cannot be identified from it. Which technique should the team apply during training to provide a formal, quantifiable privacy guarantee?
⚠ Common exam trap
The trap here is assuming that any privacy-enhancing technology like federated learning or homomorphic encryption automatically protects against membership inference in a stolen model.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Differential privacy with a calibrated noise mechanism
Differential privacy is the only technique listed that offers a formal, quantifiable privacy guarantee by mathematically bounding the influence of any single training record. This ensures that even if the model is compromised, individual patients cannot be reliably identified, which is critical for sensitive medical data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Data augmentation with synthetic X-ray images
Why it's wrong here
Data augmentation expands the training set with modified copies, which can improve generalization but does not provide any formal privacy protection. A stolen model could still contain information about original patients. Synthetic images may even introduce artifacts that leak information. This approach fails to deliver the quantifiable privacy guarantee needed.
- ✗
Homomorphic encryption of the training data
Why it's wrong here
Homomorphic encryption allows computations on encrypted data, protecting data during processing, but it does not provide a privacy guarantee for the trained model itself. If the model is stolen, it may still leak information about the training data. The scenario requires protection even after model theft, which homomorphic encryption alone does not ensure.
- ✓
Differential privacy with a calibrated noise mechanism
Why this is correct
Differential privacy adds calibrated noise to the training process, providing a mathematical guarantee that the inclusion or exclusion of any single patient's record has a bounded effect on the model's output. This makes it extremely difficult for an attacker with the stolen model to determine whether a specific patient was in the training set, directly addressing the requirement for a formal privacy guarantee.
- ✗
Federated learning across hospital sites
Why it's wrong here
Federated learning keeps data local and shares only model updates, reducing data movement, but it does not inherently prevent a stolen model from leaking patient information. Without additional privacy mechanisms like differential privacy, the model can still memorize and expose sensitive details. Thus, it does not meet the requirement for a formal privacy guarantee.
About these practice questions
Courseiva writes every AI0-001 question from scratch — 962 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.