AI0-001 AI Security Practice Question
A security engineer is threat modeling an AI-based recommendation system using STRIDE. Which threat corresponds to an attacker extracting the model's training data by querying the system?
⚠ Common exam trap
The AI0-001 exam often tests the distinction between Information Disclosure and Tampering, where candidates mistakenly classify data extraction as Tampering because they confuse 'accessing data' with 'modifying data'.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Information disclosure
In the STRIDE threat model, Information Disclosure occurs when an attacker gains unauthorized access to sensitive data. Extracting training data by querying the AI recommendation system (e.g., via a model inversion or membership inference attack) directly violates the confidentiality of the training dataset, which is a classic Information Disclosure threat.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Information disclosure
Why this is correct
Information disclosure covers data exposure to unauthorised parties, matching the stem's constraint of training data extraction through repeated queries. Model inversion and membership inference attacks exploit prediction outputs to reconstruct training records, which STRIDE classifies as information disclosure rather than tampering or spoofing.
- ✗
Spoofing
Why it's wrong here
Spoofing concerns impersonating a user, service or system to gain illegitimate access. Querying the model to reconstruct training data involves no identity forgery; the attacker uses legitimate access. Spoofing would be correct if someone impersonated a privileged API client to reach the model at all.
- ✗
Denial of service
Why it's wrong here
Denial of service covers exhausting or degrading availability so legitimate users cannot query the system. Here the attacker's queries succeed and return data, so availability is untouched. Denial of service would be correct if the query volume overwhelmed the inference endpoint, making the recommendation system unresponsive.
- ✗
Tampering
Why it's wrong here
Tampering covers modifying data or model artefacts, not reading them out. Extracting training data through repeated queries is an information-disclosure concern, which STRIDE classifies under Information Disclosure. Tampering would fit an attacker altering the recommendation model's weights or poisoning its stored training records.
About these practice questions
This AI0-001 question is part of Courseiva's 962-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.