Courseiva
AI Security →easyMultiple Choice

AI0-001 AI Security Practice Question

An AI security team is conducting a threat model for a new document summarization service. They want to identify threats related to spoofing of the AI's identity. Which STRIDE category should they consider?

⚠ Common exam trap

The trap is that candidates might confuse Spoofing with Repudiation or Tampering, especially if they focus on the word 'identity' and think of authentication vs. authorization; Spoofing is specifically about impersonation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Spoofing

Spoofing is the STRIDE category that covers threats related to impersonating the AI's identity, such as an attacker pretending to be the AI service to gain unauthorized access or deceive users. The question explicitly asks about spoofing of the AI's identity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Repudiation

    Why it's wrong here

    Repudiation covers denying that an action occurred, so it addresses logging and non-attributable events rather than impersonation of the summarization service's identity. It is tempting because AI systems can produce unattributable outputs, and repudiation would be the correct STRIDE category when the threat is an agent denying having submitted a prompt.

  • ✗

    Tampering

    Why it's wrong here

    Spoofing concerns illegitimate impersonation of an identity, which STRIDE maps to the Spoofing category, not Tampering. Tampering covers unauthorised modification of data or code in transit or at rest, so it would be the right choice when the threat is altering the summarisation model's inputs or outputs rather than impersonating the service.

  • ✗

    Information disclosure

    Why it's wrong here

    Information disclosure covers exposure of data to unauthorised parties, such as leaking document contents or model outputs. Spoofing concerns impersonating the AI's identity, addressed by authentication of the model or service, so this category misdirects the threat model.

  • ✓

    Spoofing

    Why this is correct

    Spoofing covers impersonating a legitimate entity, so threats where an attacker or component masquerades as the AI service's identity fall squarely here. Mapping this to the summarisation service's authentication and identity claims satisfies the team's goal of identifying AI identity spoofing threats.

About these practice questions

One of 962 original AI0-001 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.