Courseiva

AI0-001 AI Implementation and Operations Practice Question

An operations team is preparing to deploy a new AI inference service. Security leadership requires that all data in transit between the application and the model endpoint be encrypted and that clients be authenticated before they can submit inference requests. Which combination of controls should the team implement?

⚠ Common exam trap

The trap here is treating network-level protections such as firewalls or IP allowlists as equivalent to transport encryption and cryptographic client authentication.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

TLS for transport encryption and API keys or OAuth tokens for client authentication

The requirement has two distinct parts: confidentiality of data in transit and verification of client identity. TLS provides the former by encrypting the connection, while API keys or OAuth tokens provide the latter by proving the caller is authorized. Controls that protect stored weights, filter traffic, or restrict network ranges address other risks and do not deliver both required properties.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Network segmentation of the inference subnet and IP allowlisting of known clients

    Why it's wrong here

    Segmentation and IP allowlisting reduce the attack surface, but IP addresses can be spoofed or shared and do not cryptographically authenticate a client. They also do nothing to encrypt the payload in transit, so traffic could still be read on the wire, leaving both stated security requirements unmet.

  • ✗

    A web application firewall and rate limiting on the inference endpoint

    Why it's wrong here

    A web application firewall and rate limiting mitigate abuse and some injection attacks, but neither encrypts the request payload nor establishes the identity of the calling client. They are complementary defensive controls, yet they fail to meet the explicit requirements for transport encryption and client authentication stated by security leadership.

  • ✓

    TLS for transport encryption and API keys or OAuth tokens for client authentication

    Why this is correct

    TLS encrypts data in transit between clients and the inference endpoint, and API keys or OAuth tokens verify client identity before requests are processed. Together they satisfy both the encryption-in-transit and authenticated-access requirements, and they are standard controls for exposing any AI inference API to internal or external consumers.

  • ✗

    AES-256 encryption of the model weights at rest and role-based access control on the model registry

    Why it's wrong here

    Encrypting model weights at rest and restricting registry access protect the stored artifact, not the network traffic or client identity for inference calls. These controls address confidentiality of the model file itself, but they leave data in transit unencrypted and do not authenticate the clients submitting requests to the endpoint.

About these practice questions

One of 962 original AI0-001 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.