AI0-001 AI Security Practice Question
An organization wants to train a machine learning model on sensitive patient data without exposing individual records. Which privacy-preserving technique allows the model to learn from data distributed across multiple hospitals without raw data leaving each site?
⚠ Common exam trap
The trap is choosing differential privacy or homomorphic encryption because both are privacy-preserving and sound sophisticated; the question's key phrase 'data distributed across multiple hospitals without raw data leaving each site' points specifically to the federated architecture, not to a noise-addition or encryption technique.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Federated learning
Federated learning trains a shared global model by sending model updates (gradients or weights) — not raw data — from each participating site to a central aggregator, which combines them (e.g., via FedAvg) and redistributes the updated model. Because patient records never leave each hospital, it directly satisfies the requirement of learning from distributed data without exposing individual records. This is the canonical privacy-preserving distributed training technique.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Homomorphic encryption
Why it's wrong here
Homomorphic encryption lets computation run on encrypted values, but the participating hospitals would still need to pool ciphertexts or share keys, and it does not orchestrate distributed training. It suits outsourced computation on a single encrypted dataset.
- ✓
Federated learning
Why this is correct
Federated learning trains a shared model locally at each hospital, exchanging only model updates rather than raw records. This satisfies the constraint that patient data never leaves each site, unlike centralised training or differential privacy applied to pooled datasets.
- ✗
k-anonymity
Why it's wrong here
k-anonymity generalises quasi-identifiers so no record is distinguishable from at least k−1 others, but it requires pooling data into one dataset, so records must leave each hospital. It suits publishing or releasing tabular datasets, not training a model across sites that must retain raw data locally.
- ✗
Differential privacy
Why it's wrong here
Differential privacy adds calibrated noise to query outputs or gradients to protect individuals within one dataset; it does not coordinate training across separate sites holding raw records. It suits publishing aggregate statistics with a formal privacy budget.
About these practice questions
Courseiva writes every AI0-001 question from scratch — 962 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.