Courseiva
AI Security →easyMultiple Select

AI0-001 AI Security Practice Question

An organization is planning to fine-tune an open-source LLM for internal use. To secure the supply chain, which TWO steps should they take before using the base model? (Select two.)

⚠ Common exam trap

CompTIA often tests the distinction between pre-deployment supply chain security (verification and vetting) and post-deployment operational controls (logging, fine-tuning), tricking candidates into selecting runtime measures for a supply chain question.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Verify the model's provenance and checksums

Option B is correct because verifying the model's provenance and checksums confirms that the base model was obtained from a trusted source and has not been tampered with or substituted during download, which is a foundational supply-chain control. Option C is correct because pre-trained models can contain hidden backdoors or malicious behaviors (e.g., triggered outputs or poisoned weights), so vetting the model before fine-tuning helps detect such threats prior to integrating it into internal systems. Option A is not appropriate because retraining from scratch is prohibitively expensive and unnecessary for supply-chain security. Option D is a runtime monitoring control that occurs after deployment, not a pre-use supply-chain step. Option E is incorrect because fine-tuning on sensitive internal data increases risk and does not secure the base model's supply chain.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Retrain the model from scratch

    Why it's wrong here

    Retraining from scratch neither verifies the downloaded weights nor removes embedded backdoors, so it leaves the supply-chain risk untouched while discarding the base model's value. It is tempting because training data provenance feels controllable, but this option would be correct only where no trustworthy pretrained checkpoint exists and full control of the corpus is required.

  • ✓

    Verify the model's provenance and checksums

    Why this is correct

    Verifying provenance and checksums confirms the downloaded base model genuinely originates from the trusted publisher and has not been altered in transit or tampered with in the repository, directly addressing supply chain integrity before fine-tuning begins.

  • ✓

    Vet the pre-trained model for potential backdoors

    Why this is correct

    Vetting the pre-trained model for backdoors directly addresses the supply-chain constraint: a tampered base model can embed hidden triggers that survive fine-tuning. Inspecting weights, provenance and publisher reputation before fine-tuning detects malicious modifications that would otherwise propagate into the deployed internal model.

  • ✗

    Set up audit logging of all interactions

    Why it's wrong here

    Audit logging records interactions after deployment; it cannot validate model provenance or detect tampering in the downloaded weights before fine-tuning begins. It is tempting because logging underpins AI governance, but this option would be correct only for post-deployment monitoring and accountability rather than pre-use supply-chain verification.

  • ✗

    Fine-tune the model on sensitive internal data

    Why it's wrong here

    Fine-tuning on sensitive internal data embeds confidential material into weights and increases leakage risk; it does not secure the supply chain before use. It is tempting because fine-tuning is the project's goal, but this option would be correct only where the objective is task adaptation, not provenance and integrity verification of the base model.

About these practice questions

One of 962 original AI0-001 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.