AI0-001 AI Security Practice Question
A software vendor ships an on-device ML model that performs optical character recognition on scanned contracts. The model file is distributed inside the installer. A security architect worries that an attacker could replace the model file with a trojaned version that subtly alters recognized text. Which control best ensures the device only loads a model that the vendor actually produced?
⚠ Common exam trap
The trap here is treating a locally stored hash as proof of authenticity, when an attacker who can replace the model can also replace the stored hash.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Verify a vendor-signed detached signature over the model file using a public key pinned in the application before loading it.
Ensuring the loaded model was produced by the vendor requires cryptographic authenticity, not just change detection or obscurity. A detached signature verified with a public key pinned in the application proves origin and integrity, so a substituted model fails verification. Local hashes, obfuscation, and disk encryption do not establish that the vendor authored the file and cannot reliably block a trojaned replacement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Obfuscate the model file with a proprietary packer so its internal structure is harder to reverse engineer.
Why it's wrong here
Obfuscation raises the effort to inspect the model but does not verify its origin. An attacker can still replace the entire obfuscated file with their own packed payload, and the application has no way to distinguish it. Obfuscation is not an integrity or authenticity mechanism, so it does not ensure the loaded model came from the vendor.
- ✗
Enable full-disk encryption on the device so the model file cannot be modified while at rest.
Why it's wrong here
Full-disk encryption protects data confidentiality when the device is powered off or stolen, but it does not prevent an attacker with runtime access from replacing a file. Encryption at rest also does not establish who authored the model. It leaves the authenticity question unanswered and cannot stop a trojaned model from being loaded by the application.
- ✗
Compute the model file's SHA-256 hash at install time and store it in a local text file for later comparison.
Why it's wrong here
A stored hash can detect changes only if the stored value itself is trustworthy. An attacker who can replace the model file can also replace the local hash file, defeating the comparison. Without a signature or a trusted external reference, the hash provides no assurance of vendor authenticity and does not prevent loading a trojaned model.
- ✓
Verify a vendor-signed detached signature over the model file using a public key pinned in the application before loading it.
Why this is correct
A detached signature created with the vendor's private key and verified with a pinned public key proves the model file was produced by the vendor and has not been altered. Pinning the public key in the application prevents an attacker from substituting their own key. This directly addresses the integrity and authenticity concern, ensuring a trojaned model fails verification and is not loaded.
About these practice questions
One of 962 original AI0-001 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.