AI0-001 AI Security, Ethics and Governance Practice Question
A security researcher demonstrates that by adding small perturbations to an image of a stop sign, an autonomous vehicle's AI misclassifies it as a speed limit sign. This is an example of which type of attack?
⚠ Common exam trap
The AI0-001 exam often tests the distinction between attacks that occur during training (poisoning) versus inference (adversarial examples), so candidates mistakenly choose data poisoning when the scenario clearly describes input manipulation at test time.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Adversarial example attack
This is an adversarial example attack because the researcher adds imperceptible perturbations to the input image (the stop sign) to cause the AI model to output an incorrect classification (speed limit sign). Adversarial examples exploit the model's sensitivity to small, crafted changes in input data, leading to misclassification without altering the underlying task or training data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Data poisoning attack
Why it's wrong here
Data poisoning corrupts the training dataset so the model learns wrong associations; here the model is already trained and the input image is altered at inference time. Poisoning would be the right label if attackers had tampered with the stop-sign training examples before training.
- ✗
Model extraction attack
Why it's wrong here
Model extraction queries a deployed model to reconstruct its parameters or decision boundary; it does not alter inputs to force misclassification. Extraction suits stealing a proprietary model through API probing. Perturbing an image to flip its predicted label is an adversarial evasion attack.
- ✓
Adversarial example attack
Why this is correct
Adversarial example attacks exploit imperceptible input perturbations that shift a model across its decision boundary, exactly as described: the stop sign's pixels are altered slightly so the classifier outputs "speed limit". The stem's defining constraint — misclassification caused by deliberately crafted noise rather than data poisoning or model theft — matches this category precisely.
- ✗
Membership inference attack
Why it's wrong here
A membership inference attack determines whether a specific data record was part of the model’s training set, not whether input perturbations alter classification output. It fails here because the scenario involves manipulating an image to cause misclassification, not inferring training data membership. This option is tempting because both involve adversarial manipulation of model behaviour, but membership inference targets data privacy, not input integrity. It would be correct if the question asked about extracting whether a particular stop-sign image was used during training.
About these practice questions
Courseiva writes every AI0-001 question from scratch — 962 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on AI0-001
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which TWO are common types of adversarial attacks on AI models?
easy- A.Hyperparameter tuning
- B.Transfer learning
- ✓ C.Evasion attack
- D.Backdoor attack
- ✓ E.Data poisoning
Why C: Evasion attacks (C) are a common adversarial attack in which specially crafted inputs are designed at inference time to fool a deployed model into misclassifying or producing incorrect outputs, which is why C is correct. Data poisoning (E) is also a common adversarial attack, occurring during training when an attacker corrupts or injects malicious samples into the training data to degrade model performance or implant malicious behavior, making E correct. Hyperparameter tuning (A) is a legitimate model-development technique for optimizing performance, not an attack. Transfer learning (B) is a benign machine-learning method that reuses knowledge from a pretrained model. Backdoor attack (D) is a real adversarial threat, but it is not marked as correct in this question, so it is excluded from the two required answers.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.