Courseiva
AI Security →mediumMultiple Select

AI0-001 AI Security Practice Question

An organization is deploying a conversational AI that handles sensitive customer data. To prevent data leakage via the LLM, which TWO practices should be implemented? (Choose two.)

⚠ Common exam trap

CompTIA often tests the distinction between proactive security measures (like red teaming or encryption) and runtime controls that directly prevent data leakage during inference, causing candidates to confuse training-time protections with inference-time safeguards.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Audit logging of all AI interactions

Option C is correct because audit logging of all AI interactions creates a tamper-evident record of prompts and responses, enabling detection, investigation, and forensic analysis of any data leakage or misuse involving sensitive customer data. Option D is correct because output filtering inspects the model's generated responses and blocks or redacts sensitive information (e.g., PII, credentials, regulated data) before it reaches the user, directly preventing leakage at the point of egress. Option A is not the best fit because differential privacy protects individuals in the training dataset by adding noise during training, but it does not prevent leakage of sensitive data supplied at inference time. Option B is not the best fit because red teaming is a proactive assurance activity that finds weaknesses but does not itself block data leakage in production. Option E is not the best fit because encrypting model weights at rest protects the model artifact from unauthorized access, not the sensitive customer data that may be exposed through prompts or outputs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Applying differential privacy to training data

    Why it's wrong here

    Differential privacy adds noise to training data to limit inference about individuals, but it does not stop a deployed LLM from echoing sensitive data supplied in prompts or memorised during fine-tuning. It is tempting because it is a genuine privacy-preserving training technique, and would be correct when publishing aggregate statistics or training models on sensitive datasets.

  • ✗

    Conducting regular red teaming exercises

    Why it's wrong here

    Red teaming identifies leakage weaknesses through adversarial probing but is a detection and assessment activity; it does not itself prevent sensitive data from being exposed during inference. It is tempting because it is a recognised AI security practise, and would be correct for validating guardrails and uncovering vulnerabilities before or after deployment.

  • ✓

    Audit logging of all AI interactions

    Why this is correct

    Audit logging records every prompt and response, creating traceability that satisfies the requirement to prevent data leakage by detecting and investigating unauthorised disclosure. It provides the accountability trail needed for sensitive customer data handled by the conversational AI, supporting forensic review and compliance monitoring across all interactions.

  • ✓

    Output filtering to detect and block sensitive information

    Why this is correct

    Output filtering inspects model responses before they reach the user, blocking sensitive data that the LLM might reproduce from prompts or training. This directly satisfies the stem's requirement to prevent leakage via the LLM, complementing input-side controls by catching disclosures at the egress point.

  • ✗

    Encrypting model weights at rest

    Why it's wrong here

    Encrypting model weights at rest protects stored parameters from storage-level compromise, but leakage occurs through inference outputs and prompts, where weights are decrypted in memory. It is tempting because encryption is a standard data-protection control, and would be correct for safeguarding model artefacts against theft of the underlying storage volume.

About these practice questions

Courseiva writes every AI0-001 question from scratch — 962 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.