AI0-001 AI Security Practice Question
An AI security team is conducting a threat model for a new document summarization service. They want to identify threats related to spoofing of the AI's identity. Which STRIDE category should they consider?
⚠ Common exam trap
The trap is that candidates might confuse Spoofing with Repudiation or Tampering, especially if they focus on the word 'identity' and think of authentication vs. authorization; Spoofing is specifically about impersonation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Spoofing
Spoofing is the STRIDE category that covers threats related to impersonating the AI's identity, such as an attacker pretending to be the AI service to gain unauthorized access or deceive users. The question explicitly asks about spoofing of the AI's identity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Repudiation
Why it's wrong here
Repudiation covers denying that an action occurred, so it addresses logging and non-attributable events rather than impersonation of the summarization service's identity. It is tempting because AI systems can produce unattributable outputs, and repudiation would be the correct STRIDE category when the threat is an agent denying having submitted a prompt.
- ✗
Tampering
Why it's wrong here
Spoofing concerns illegitimate impersonation of an identity, which STRIDE maps to the Spoofing category, not Tampering. Tampering covers unauthorised modification of data or code in transit or at rest, so it would be the right choice when the threat is altering the summarisation model's inputs or outputs rather than impersonating the service.
- ✗
Information disclosure
Why it's wrong here
Information disclosure covers exposure of data to unauthorised parties, such as leaking document contents or model outputs. Spoofing concerns impersonating the AI's identity, addressed by authentication of the model or service, so this category misdirects the threat model.
- ✓
Spoofing
Why this is correct
Spoofing covers impersonating a legitimate entity, so threats where an attacker or component masquerades as the AI service's identity fall squarely here. Mapping this to the summarisation service's authentication and identity claims satisfies the team's goal of identifying AI identity spoofing threats.
About these practice questions
One of 962 original AI0-001 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.