AI0-001 AI Security, Ethics and Governance Practice Question
A retail bank's fraud model was trained on customer transaction data that included account holders in the EU. An internal audit finds the training pipeline copied raw transaction records, including names and card numbers, into an unencrypted research bucket for model retraining. Which action best aligns the remediation with data-protection obligations for that pipeline?
⚠ Common exam trap
The trap here is treating encryption of the research bucket as a complete privacy fix, when the governing issue is that identifiable data was copied outside its original purpose and kept without a retention limit.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Delete the research bucket and retrain using pseudonymized or tokenized transaction records with documented retention limits.
The finding combines excessive identifiability with a purpose and retention failure. Removing the exposed copy stops ongoing risk, while pseudonymization or tokenization plus documented retention limits lets the fraud model keep learning from transaction behavior without carrying direct identifiers into a research environment. Encryption, monitoring, and new consent each address part of the problem but leave the core data-minimization defect unresolved.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Add the research bucket to the data-loss-prevention watchlist and require monthly access reviews.
Why it's wrong here
Monitoring and access review improve oversight of a bad practice rather than eliminating it. The raw records remain in an environment with a broader audience than the original purpose allowed, so the minimization and purpose-limitation problems persist. Detection controls are valuable, but they do not substitute for removing unnecessary identifiers or constraining retention.
- ✗
Apply column-level encryption to the research bucket and continue retraining on the same raw records.
Why it's wrong here
Encrypting the bucket addresses confidentiality at rest but does not cure the underlying purpose-limitation and minimization failures, because the pipeline still processes identifiable data beyond its original collection purpose. Analysts with decryption rights still see names and card numbers, and retention remains unbounded. The audit finding is about lawful processing scope, not only about storage protection.
- ✓
Delete the research bucket and retrain using pseudonymized or tokenized transaction records with documented retention limits.
Why this is correct
The violation is storing identifiable personal data outside its lawful purpose and controls. Pseudonymizing or tokenizing before the data reaches the research environment, plus defined retention limits, reduces identifiability while preserving the statistical signal the fraud model needs. Deleting the exposed copy ends the ongoing exposure, and the documented retention schedule satisfies accountability and minimization expectations for the pipeline.
- ✗
Obtain a new consent notice from all account holders before the next retraining cycle.
Why it's wrong here
Retroactive consent is slow, incomplete because not all holders will respond, and does not fix the exposure that already occurred or the engineering practice that created it. Consent is one lawful basis among several and must be paired with minimization. The pipeline would still copy full identifiers into a low-control environment, so the audit finding would recur.
Visual reference
About these practice questions
This AI0-001 question is part of Courseiva's 962-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.