AI0-001 AI Security, Ethics and Governance Practice Question
An organization implements AI governance following the NIST AI Risk Management Framework. They need to ensure that all model decisions are logged with sufficient detail for later audit. Which logging requirement is most critical for traceability?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Timestamp, input data, output, and model version
Timestamp, input data, output, and model version together provide full traceability for audit. Option A is wrong because logging only input data and model name misses outputs, timestamp, and version, which are essential for traceability. Option B is wrong because source code and training dataset hash are not part of the inference audit trail; they are more relevant to model development. Option C is wrong because logging only model outputs and confidence scores misses inputs and model version, making it impossible to fully trace decisions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Input data and model name only
Why it's wrong here
Logging only the input data and model name omits the output, confidence, model version and decision timestamp, so an auditor cannot reconstruct why a specific decision was produced. It tempts because inputs identify the request, and would suffice for data lineage, but traceability under the NIST AI RMF requires the full decision record.
- ✗
Source code and training dataset hash
Why it's wrong here
Source code and training dataset hashes evidence the model's provenance, not the individual inference: they cannot show which inputs produced a given output at a given time. They tempt because hashing supports reproducibility and integrity, and would be correct for verifying a training pipeline rather than auditing decisions.
- ✗
Model outputs and confidence scores only
Why it's wrong here
Recording outputs and confidence scores alone omits the inputs, model version and parameters that produced them, so a decision cannot be reproduced or attributed during audit. It tempts because outputs are the visible decision, and would support monitoring for drift, but traceability requires the inputs and model identity too.
- ✓
Timestamp, input data, output, and model version
Why this is correct
Traceability requires reconstructing each decision, so logs must capture the timestamp, the exact input data, the produced output, and the model version that generated it. Without the model version, an auditor cannot attribute behaviour to a specific deployed artefact.
About these practice questions
One of 962 original AI0-001 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.