Courseiva
AI Security →mediumMultiple Select

AI0-001 AI Security Practice Question

A security engineer is implementing defenses against membership inference attacks on a classification model. Which TWO techniques are most effective? (Select TWO.)

⚠ Common exam trap

CompTIA often tests the misconception that data augmentation or encryption directly prevent inference attacks, when in fact they address different threat models (data diversity and confidentiality, respectively) and do not limit the model's output leakage.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Differential privacy

Option C (Differential privacy) is correct because it bounds the influence any single training record can have on the model's output by adding calibrated noise (e.g., via DP-SGD with a privacy budget ε), which directly limits the confidence signal an attacker can exploit to infer whether a specific individual was in the training set. Option E (Model regularization) is correct because techniques such as L2 weight decay, dropout, and early stopping reduce overfitting, and overfitting is the primary cause of the train-test performance gap that membership inference attacks detect. Option A (Data augmentation) is not among the marked answers; while it can reduce overfitting incidentally, it does not provide a formal privacy guarantee against membership inference. Option B (Homomorphic encryption) protects data during computation but does not prevent inference about training-set membership from model outputs. Option D (Increasing model size) is counterproductive, as larger models tend to overfit more and thus become more vulnerable to membership inference.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Data augmentation

    Why it's wrong here

    Data augmentation enlarges the training set but does not directly reduce the overfitting that membership inference exploits; memorisation of original records persists. Augmentation suits improving generalisation and robustness. Effective defences target overfitting and prediction confidence, such as regularisation, dropout or differential privacy.

  • ✗

    Homomorphic encryption

    Why it's wrong here

    Homomorphic encryption protects data during computation, addressing confidentiality of processed values, not the inference signal leaking through model outputs. It suits privacy-preserving outsourced computation. Membership inference defence requires limiting how much the model reveals about individual training records.

  • ✓

    Differential privacy

    Why this is correct

    Differential privacy injects calibrated noise during training, bounding any single record's influence on the model's outputs. This obscures the confidence differences membership inference exploits, directly defending against determining whether a specific example was in the training set.

  • ✗

    Increasing model size

    Why it's wrong here

    Larger models tend to memorise training data more readily, which strengthens membership inference signals rather than suppressing them. Capacity increases suit accuracy or complexity goals. Effective defences reduce overfitting and output confidence, for example regularisation, dropout or differential privacy.

  • ✓

    Model regularization

    Why this is correct

    Model regularisation penalises complexity, preventing the model from memorising individual training examples. Reduced overfitting shrinks the confidence gap between members and non-members, directly undermining the signal membership inference attacks rely on to distinguish training records.

About these practice questions

Courseiva writes every AI0-001 question from scratch — 962 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.