AI0-001 Implementing AI Solutions Practice Question
A media company is deploying a generative AI assistant that drafts marketing copy for regional campaigns. Legal requires that no customer personal data, unreleased product names, or internal pricing appear in generated output, and that every draft be attributable to a source. The team plans to use retrieval-augmented generation over an approved content repository. Which TWO controls should be implemented to satisfy these requirements? (Choose two.)
⚠ Common exam trap
The trap here is reaching for output-side filters or model tuning when the decisive control is preventing unauthorized documents from being retrieved into the prompt in the first place.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Apply document-level access control and metadata filtering in the retrieval index so the assistant can only retrieve content the requesting user is authorized to see.
Both requirements are met at the retrieval layer. Permission-aware retrieval with metadata filtering stops sensitive documents from entering the prompt at all, which is the strongest form of prevention. Inline citations then make every generated claim traceable to an approved source chunk, enabling review and exposing hallucinations. Raising temperature, storing raw prompt logs insecurely, or fine-tuning on the whole corpus each either increases leakage risk or removes the ability to control and attribute content.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Fine-tune the base model on the entire approved content repository so it memorizes the brand voice and product catalog.
Why it's wrong here
Fine-tuning bakes repository content into weights, making it impossible to enforce per-user access control and impossible to cite which source supported a claim. Memorized pricing or unreleased names could resurface even for users who should not see them. It also requires retraining whenever content changes, whereas retrieval reflects updates immediately; it fails both requirements.
- ✗
Raise the model's temperature setting so the assistant produces more varied and creative marketing phrasing.
Why it's wrong here
Higher temperature increases sampling randomness, which raises the chance of hallucinated product names and invented prices, directly working against the legal constraints. Creativity is not the compliance problem here; leakage and attribution are. Temperature is a stylistic parameter and provides no access control, filtering, or traceability, so it cannot satisfy any of the stated requirements.
- ✓
Apply document-level access control and metadata filtering in the retrieval index so the assistant can only retrieve content the requesting user is authorized to see.
Why this is correct
Retrieval is the point where sensitive documents enter the prompt, so enforcing the same permissions as the source repository prevents personal data, unreleased names, and pricing from ever reaching the model. Metadata filtering also restricts retrieval to approved campaign assets. This is the primary control because it blocks leakage at the source rather than trying to scrub output afterward.
- ✓
Require the assistant to return inline citations that map each generated claim back to the specific retrieved chunk and its source document.
Why this is correct
Inline citations make each draft attributable, letting reviewers verify that statements trace to approved repository content rather than model memory. They also expose cases where the model hallucinated a product name or price, because the claim has no supporting chunk. This directly satisfies the attribution requirement and complements access control by making retrieval usage auditable.
- ✗
Store the full prompt and completion pairs in an unencrypted analytics bucket so the marketing team can review trends.
Why it's wrong here
Prompts and completions may themselves contain retrieved personal data or internal pricing, so copying them unencrypted into a broadly accessible analytics store creates a new leakage path and likely violates the same policy. Reviewing trends is not a stated requirement. This control increases risk and provides no authorization enforcement or attribution mechanism.
About these practice questions
Courseiva writes every AI0-001 question from scratch — 962 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.