Courseiva
AI Security →easyMultiple Choice

AI0-001 AI Security Practice Question

An organization wants to train a machine learning model on sensitive patient data without exposing individual records. Which privacy-preserving technique allows the model to learn from data distributed across multiple hospitals without raw data leaving each site?

⚠ Common exam trap

The trap is choosing differential privacy or homomorphic encryption because both are privacy-preserving and sound sophisticated; the question's key phrase 'data distributed across multiple hospitals without raw data leaving each site' points specifically to the federated architecture, not to a noise-addition or encryption technique.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Federated learning

Federated learning trains a shared global model by sending model updates (gradients or weights) — not raw data — from each participating site to a central aggregator, which combines them (e.g., via FedAvg) and redistributes the updated model. Because patient records never leave each hospital, it directly satisfies the requirement of learning from distributed data without exposing individual records. This is the canonical privacy-preserving distributed training technique.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Homomorphic encryption

    Why it's wrong here

    Homomorphic encryption lets computation run on encrypted values, but the participating hospitals would still need to pool ciphertexts or share keys, and it does not orchestrate distributed training. It suits outsourced computation on a single encrypted dataset.

  • ✓

    Federated learning

    Why this is correct

    Federated learning trains a shared model locally at each hospital, exchanging only model updates rather than raw records. This satisfies the constraint that patient data never leaves each site, unlike centralised training or differential privacy applied to pooled datasets.

  • ✗

    k-anonymity

    Why it's wrong here

    k-anonymity generalises quasi-identifiers so no record is distinguishable from at least k−1 others, but it requires pooling data into one dataset, so records must leave each hospital. It suits publishing or releasing tabular datasets, not training a model across sites that must retain raw data locally.

  • ✗

    Differential privacy

    Why it's wrong here

    Differential privacy adds calibrated noise to query outputs or gradients to protect individuals within one dataset; it does not coordinate training across separate sites holding raw records. It suits publishing aggregate statistics with a formal privacy budget.

About these practice questions

Courseiva writes every AI0-001 question from scratch — 962 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.