Courseiva

AI0-001 AI Security, Ethics and Governance Practice Question

An organization implements AI governance following the NIST AI Risk Management Framework. They need to ensure that all model decisions are logged with sufficient detail for later audit. Which logging requirement is most critical for traceability?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Timestamp, input data, output, and model version

Timestamp, input data, output, and model version together provide full traceability for audit. Option A is wrong because logging only input data and model name misses outputs, timestamp, and version, which are essential for traceability. Option B is wrong because source code and training dataset hash are not part of the inference audit trail; they are more relevant to model development. Option C is wrong because logging only model outputs and confidence scores misses inputs and model version, making it impossible to fully trace decisions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Input data and model name only

    Why it's wrong here

    Logging only the input data and model name omits the output, confidence, model version and decision timestamp, so an auditor cannot reconstruct why a specific decision was produced. It tempts because inputs identify the request, and would suffice for data lineage, but traceability under the NIST AI RMF requires the full decision record.

  • ✗

    Source code and training dataset hash

    Why it's wrong here

    Source code and training dataset hashes evidence the model's provenance, not the individual inference: they cannot show which inputs produced a given output at a given time. They tempt because hashing supports reproducibility and integrity, and would be correct for verifying a training pipeline rather than auditing decisions.

  • ✗

    Model outputs and confidence scores only

    Why it's wrong here

    Recording outputs and confidence scores alone omits the inputs, model version and parameters that produced them, so a decision cannot be reproduced or attributed during audit. It tempts because outputs are the visible decision, and would support monitoring for drift, but traceability requires the inputs and model identity too.

  • ✓

    Timestamp, input data, output, and model version

    Why this is correct

    Traceability requires reconstructing each decision, so logs must capture the timestamp, the exact input data, the produced output, and the model version that generated it. Without the model version, an auditor cannot attribute behaviour to a specific deployed artefact.

About these practice questions

One of 962 original AI0-001 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.