Courseiva
AI Security →mediumMultiple Choice

AI0-001 AI Security Practice Question

A team is designing a secure API for an AI model. They want to prevent data leakage through overly detailed error messages. Which principle should they follow?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use generic error messages

Least-privilege API access and minimal error information reduce the attack surface. Specifically, returning generic error messages prevents leaking internal details.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Return detailed error codes for debugging

    Why it's wrong here

    Detailed error codes expose internal schema, stack traces or model internals, enabling attackers to map the system and craft targeted inputs. It is tempting because verbose codes speed debugging, but that belongs in server-side logs; clients should receive generic messages with a correlation identifier instead.

  • ✓

    Use generic error messages

    Why this is correct

    Generic error messages return only high-level failure codes, withholding stack traces, query fragments and internal paths that verbose errors expose. This satisfies the stem's constraint of preventing data leakage through API error responses, since attackers cannot harvest implementation details from diagnostic output.

  • ✗

    Log errors to the client side

    Why it's wrong here

    Client-side logging places error detail in the browser or caller's environment, where attackers can read it directly, worsening the leakage the team wants to prevent. It is tempting because client logs aid front-end debugging, but sensitive diagnostics must stay in server-side logs inaccessible to callers.

  • ✗

    Disable all error messages

    Why it's wrong here

    Disabling all error messages removes diagnostic feedback entirely, breaking legitimate troubleshooting and masking failures without preventing leakage. It is tempting as an absolute lockdown, but the correct approach returns generic client-facing messages while logging specifics server-side, preserving both security and operability.

About these practice questions

This AI0-001 question is part of Courseiva's 962-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.