AI0-001 AI Security Practice Question
An ML team wants to prevent attackers from stealing a proprietary model by repeatedly querying the public API. Which defense is most effective?
⚠ Common exam trap
CompTIA often tests the misconception that encryption or obfuscation of model artifacts is sufficient to prevent extraction attacks, when in fact the primary threat is from live API queries that bypass those protections.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Rate limiting on the API endpoint
Rate limiting restricts the number of API requests a single client can make within a given time window, directly impeding an attacker's ability to collect enough query-response pairs to reconstruct or steal the model. This defense targets the attack vector itself—repeated queries—without degrading model performance for legitimate users. Techniques like token bucket or sliding window rate limiting are commonly implemented at the API gateway level.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Using a smaller model to reduce query cost
Why it's wrong here
Reducing model size lowers computational cost per query but does not prevent an attacker from extracting the model’s weights or decision boundaries through repeated API calls; the attack vector is information leakage via query responses, not operational expense. This option is tempting because smaller models are genuinely effective for reducing latency and inference budget in high-throughput production deployments, where the goal is cost optimisation rather than security against extraction.
- ✗
Encrypting model weights at rest
Why it's wrong here
Encryption at rest protects stored weights from disk theft, but the API still returns predictions, so repeated queries extract the model through its outputs. It is tempting because it is a genuine control for data-at-rest breaches, yet rate limiting and query monitoring address extraction via the public endpoint.
- ✗
Adding random noise to all outputs
Why it's wrong here
Noise degrades output fidelity for every user while leaving the query-to-output mapping learnable, so model extraction proceeds with reduced accuracy. It tempts as a privacy technique for aggregate statistics, where differential privacy genuinely applies, but a per-query API returning predictions is not that setting.
- ✓
Rate limiting on the API endpoint
Why this is correct
Rate limiting caps the number of queries a client can make in a given window, which directly throttles the high-volume repeated querying that model-extraction attacks depend on. By restricting query throughput, attackers cannot gather enough input-output pairs to reconstruct the proprietary model, satisfying the stem's requirement to prevent theft via the public API.
About these practice questions
One of 962 original AI0-001 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.