Courseiva
AI Security →easyMultiple Choice

AI0-001 AI Security Practice Question

A machine learning engineer wants to prevent unauthorized users from querying a deployed AI model. Which access control measure is MOST appropriate to secure the API?

⚠ Common exam trap

Candidates often confuse rate limiting with access control. Rate limiting only restricts the number of requests, not who can make them. API key authentication is the correct method to ensure only authorized users can query the model.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

API key authentication

API key authentication is the most appropriate access control measure because it requires each request to include a unique key that identifies and authorizes the caller. This directly prevents unauthorized users from querying the model by validating the key against a pre-approved list before processing the request. Unlike other options, API keys provide a dedicated authentication layer for API access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Rate limiting

    Why it's wrong here

    Rate limiting caps request volume per client to protect availability and cost; it does not verify caller identity, so an unauthenticated attacker still queries the model within the allowed quota. It is the correct control when the requirement is throttling abuse or preventing denial-of-service, not authorisation.

  • ✓

    API key authentication

    Why this is correct

    API key authentication binds each request to a unique credential, so the API gateway rejects unauthenticated callers before they reach the model. This directly satisfies the stem's constraint of preventing unauthorised users from querying the deployed model endpoint.

  • ✗

    Input sanitization

    Why it's wrong here

    Input sanitisation validates and cleans payloads to block injection or malformed requests, but it grants any caller access once the input passes validation. It is the right control when the requirement is protecting the model from adversarial or malicious input rather than restricting who may call it.

  • ✗

    IP whitelisting

    Why it's wrong here

    IP whitelisting restricts callers by network origin, yet addresses can be spoofed or shared behind NAT, and it cannot identify individual users or revoke a single compromised client. It suits locking an API to known infrastructure, not authenticating distinct authorised users.

About these practice questions

This AI0-001 question is part of Courseiva's 962-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.