AI0-001 AI Implementation and Operations Practice Question
An organization is implementing an AI-powered chatbot for customer service. The chatbot must comply with GDPR and handle data subject access requests (DSARs). Which design approach best ensures compliance?
⚠ Common exam trap
CompTIA often tests the misconception that GDPR requires complete data minimization (Option A) or indefinite encryption (Option D), when in fact the regulation mandates a balance between data utility and privacy rights, including the ability to delete data upon request.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement an audit trail that logs interactions with a unique user identifier, and provide a mechanism to delete logs upon user request.
GDPR requires that personal data be stored only as long as necessary and that data subjects have the right to erasure. By logging interactions with a unique user identifier and providing a deletion mechanism, the chatbot can fulfill DSARs while maintaining an audit trail for compliance monitoring. This approach balances operational needs with regulatory obligations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Minimize data collection by not logging any user interactions.
Why it's wrong here
Refusing to log interactions removes the records needed to locate and fulfil a DSAR, so the organisation cannot search, correct or erase a data subject's data. Logging with defined retention and purpose limitation is what GDPR expects; total non-collection is not a compliance strategy.
- ✗
Anonymize all user data before logging interactions.
Why it's wrong here
Anonymising everything destroys the link between a data subject and their records, so the organisation cannot retrieve, amend or erase that individual's data to answer a DSAR. Pseudonymisation with a controlled key preserves re-identification for DSAR fulfilment while limiting exposure; full anonymisation is for analytics.
- ✓
Implement an audit trail that logs interactions with a unique user identifier, and provide a mechanism to delete logs upon user request.
Why this is correct
Logging each interaction against a unique identifier makes records retrievable for DSAR fulfilment, while the deletion mechanism enforces the right to erasure. Together they satisfy GDPR's access and erasure obligations, which the stem's compliance constraint specifically demands.
- ✗
Encrypt all chat logs and store them indefinitely for audit purposes.
Why it's wrong here
Indefinite retention breaches the GDPR storage limitation principle, which requires data be kept no longer than necessary, and encryption does not cure that. Encrypted long-term archives suit regulated retention mandates with a defined lawful basis and period, not open-ended audit hoarding.
About these practice questions
Courseiva writes every AI0-001 question from scratch — 962 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.