Courseiva

AI0-001 AI Security, Ethics and Governance Practice Question

An image classification model misclassifies a stop sign as a speed limit sign after a few pixels are altered. What is the most effective defense against such attacks?

⚠ Common exam trap

The AI0-001 exam often tests the misconception that increasing dataset size or model complexity improves security, when in fact adversarial training is the only listed option that directly hardens the model against input perturbations.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Adversarial training

Adversarial training is the most effective defense because it explicitly incorporates adversarial examples—like the perturbed stop sign—into the model's training data. By training on both clean and adversarially altered images, the model learns to be robust against small, malicious perturbations that cause misclassification. This directly addresses the root cause of the vulnerability, unlike other options that only mitigate symptoms or ignore the attack vector.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use a larger validation dataset

    Why it's wrong here

    A larger validation dataset only improves measurement of existing accuracy; it changes no weights and leaves the model's decision boundary equally vulnerable to perturbed inputs. It is tempting because more data usually helps generalisation, and would be correct for reducing overfitting or variance in reported metrics.

  • ✗

    Reduce the input image resolution

    Why it's wrong here

    Reducing resolution may remove subtle perturbations but also degrades overall accuracy.

  • ✗

    Increase the model's complexity

    Why it's wrong here

    Increasing model complexity does not counter adversarial perturbations; it often amplifies vulnerability by creating a larger attack surface for gradient-based manipulation. The temptation arises because complexity generally improves accuracy on clean data, so in a scenario requiring better generalisation on unaltered inputs, a deeper or wider architecture would be the correct choice. Here, the defence must specifically harden against pixel-level perturbations, which complexity alone cannot achieve.

  • ✓

    Adversarial training

    Why this is correct

    Adversarial training augments the training set with perturbed examples, such as stop signs with altered pixels, so the model learns to classify them correctly. This directly hardens the decision boundary against the small, deliberate pixel-level perturbations described in the stem, unlike input sanitisation, which cannot anticipate every crafted variant.

About these practice questions

One of 962 original AI0-001 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.