Courseiva
AI Security →mediumMultiple Choice

AI0-001 AI Security Practice Question

An AI security team is mapping threats specific to their ML pipeline using the STRIDE framework. Which threat category is primarily addressed by ensuring that training data is not tampered with?

⚠ Common exam trap

CompTIA AI exams often test the distinction between Tampering (data integrity) and Spoofing (identity deception), so candidates may confuse 'tampering with data' with 'spoofing a data source' and incorrectly choose Spoofing.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Tampering

Ensuring that training data is not tampered with directly addresses the Tampering threat category in the STRIDE framework. Tampering involves the unauthorized modification of data, and in an ML pipeline, corrupted training data can lead to model poisoning, where the model learns incorrect patterns or backdoors. By protecting the integrity of the training dataset, the team mitigates the risk of adversarial manipulation that could degrade model performance or introduce vulnerabilities.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Spoofing

    Why it's wrong here

    Spoofing concerns impersonating a legitimate identity or entity, countered by authentication, not by protecting training data from modification. It would be the correct category when an attacker impersonates a user, service account, or model endpoint to gain pipeline access.

  • ✓

    Tampering

    Why this is correct

    Tampering covers unauthorised modification of data or artefacts, so protecting training data integrity maps directly onto this STRIDE category. It satisfies the stem's constraint by naming the threat addressed when tampering with the ML pipeline's training set is prevented.

  • ✗

    Repudiation

    Why it's wrong here

    Repudiation concerns denying that an action occurred, addressed through logging and non-repudiation controls, not data tampering. It would be the correct category when the threat is a user or process denying having submitted training data or triggered a pipeline action.

  • ✗

    Information disclosure

    Why it's wrong here

    Tampering with training data corrupts model integrity, which STRIDE classes as Tampering, not Information disclosure. Information disclosure covers unauthorised exposure of data or model details; it would be the right category when the concern is confidentiality of training data or model outputs.

About these practice questions

One of 962 original AI0-001 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.