AI0-001 AI Security Practice Question
A team is developing a threat model for an AI system that processes user uploads. Using STRIDE, which threat involves an attacker modifying the model's training data to cause misclassification?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Tampering
Tampering is the STRIDE category for unauthorized modification of data. Data poisoning is a form of tampering with training data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Tampering
Why this is correct
Tampering covers unauthorised modification of data or systems, which directly matches an attacker altering training data to skew model outputs. Unlike Spoofing (identity falsification) or Information Disclosure (data exposure), Tampering addresses integrity attacks on the training pipeline, satisfying the stem's misclassification constraint.
- ✗
Spoofing
Why it's wrong here
Spoofing covers impersonating a user, service or system component, not altering training data. It is tempting because uploads involve identity, but tampering with data to change model behaviour maps to Tampering, which addresses modification of data or artefacts in the pipeline.
- ✗
Repudiation
Why it's wrong here
Repudiation concerns denying that an action occurred, typically lacking audit trails proving who did what. It is tempting because training pipelines need logging, but modifying training data to cause misclassification is Tampering, which covers unauthorised alteration of data or model artefacts.
- ✗
Information disclosure
Why it's wrong here
Information disclosure covers exposure of confidential data to unauthorised parties, not integrity of training data. It is tempting because uploads carry sensitive content, but the scenario describes alteration causing misclassification, which maps to Tampering rather than disclosure.
About these practice questions
This AI0-001 question is part of Courseiva's 962-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.