AI0-001 AI Security Practice Question
A team is designing a secure API for an AI model. They want to prevent data leakage through overly detailed error messages. Which principle should they follow?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use generic error messages
Least-privilege API access and minimal error information reduce the attack surface. Specifically, returning generic error messages prevents leaking internal details.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Return detailed error codes for debugging
Why it's wrong here
Detailed error codes expose internal schema, stack traces or model internals, enabling attackers to map the system and craft targeted inputs. It is tempting because verbose codes speed debugging, but that belongs in server-side logs; clients should receive generic messages with a correlation identifier instead.
- ✓
Use generic error messages
Why this is correct
Generic error messages return only high-level failure codes, withholding stack traces, query fragments and internal paths that verbose errors expose. This satisfies the stem's constraint of preventing data leakage through API error responses, since attackers cannot harvest implementation details from diagnostic output.
- ✗
Log errors to the client side
Why it's wrong here
Client-side logging places error detail in the browser or caller's environment, where attackers can read it directly, worsening the leakage the team wants to prevent. It is tempting because client logs aid front-end debugging, but sensitive diagnostics must stay in server-side logs inaccessible to callers.
- ✗
Disable all error messages
Why it's wrong here
Disabling all error messages removes diagnostic feedback entirely, breaking legitimate troubleshooting and masking failures without preventing leakage. It is tempting as an absolute lockdown, but the correct approach returns generic client-facing messages while logging specifics server-side, preserving both security and operability.
About these practice questions
This AI0-001 question is part of Courseiva's 962-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.