Courseiva

AI0-001 · domain

AI Security, Ethics and Governance

This domain covers how AI systems are secured, governed, and kept ethical across their lifecycle. For AI0-001 you must reason about bias, adversarial robustness, privacy-preserving training, and regulatory compliance, then choose the best mitigation or governance control for a described scenario. Questions are scenario-based, asking you to identify causes, trade-offs, and appropriate safeguards.

82 questions26 easy30 medium26 hard

Focused practice

Practice AI Security, Ethics and Governance questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about AI Security, Ethics and Governance

Be able to diagnose why an AI system is unfair, insecure, or non-compliant, then select the correct control: bias mitigation, adversarial defense, or privacy-preserving training. The key is matching the control to the stated risk and acknowledging its trade-offs, especially accuracy loss from differential privacy.

Detecting and mitigating bias in model outputs, such as unfair product or hiring recommendations

Hardening models against adversarial inputs, including input validation and adversarial training

Applying privacy techniques like differential privacy, anonymization, and data minimization in training

Aligning AI use with governance, transparency, and regulatory requirements such as patient privacy rules

Watch out for

Common AI Security, Ethics and Governance exam traps

  • ▸Treating a biased model as only a data-quality bug, missing that objective functions and proxy labels can encode profit or historical bias.
  • ▸Confusing privacy and security controls, for example assuming encryption alone satisfies differential privacy or anonymization requirements.
  • ▸Ignoring the accuracy-versus-privacy trade-off, claiming differential privacy improves model performance instead of adding noise and reducing utility.

Question index

All AI Security, Ethics and Governance questions (82)

Click any question to see the full explanation, or start a practice session above.

1

A healthcare organization uses an AI model to recommend treatment plans. The model was trained on data from a single hospital, and now treats patients from multiple demographics. Which ethical concern is most critical?

Easy
2

An organization deploys an AI system that processes personal data of EU citizens. Which regulatory framework imposes strict requirements on automated decision-making and profiling?

Easy
3

A financial institution uses an AI model to approve loans. The model uses features including credit score and ZIP code. During an audit, it is discovered that the model has a high false positive rate for loan default predictions in certain ZIP codes. What should the institution do to address this?

Hard
4

An image classification model misclassifies a stop sign as a speed limit sign after a few pixels are altered. What is the most effective defense against such attacks?

Medium
5

A social media company's AI recommendation system pushes extreme content to users, causing harm. Which ethical principle is most violated?

Easy
6

Which TWO are key requirements for AI governance under the EU AI Act for high-risk AI systems? (Choose two.)

Medium
7

An AI system used for autonomous driving is found to have a lower accuracy in detecting pedestrians with darker skin tones. The development team wants to address this ethical issue. Which action is most effective?

Hard
8

What is the primary function of an AI ethics board within an organization?

Easy
9

A healthcare AI system misdiagnosed patients due to adversarial inputs. What security measure should be prioritized?

Medium
10

You are a security engineer at a large e-commerce company that uses an AI-based recommendation system. The system is deployed on a Kubernetes cluster and uses a TensorFlow model served via REST API. Recently, the security team detected unusual API calls that caused the model to return incorrect recommendations. Analysis shows that the inputs were crafted to maximize prediction error. The team suspects an adversarial attack. You need to implement a solution that detects and mitigates such attacks in real-time without requiring model retraining. Which approach should you take?

Hard
11

A financial institution uses a deep learning model for loan approvals. Under the EU AI Act, this is considered a high-risk AI system. Which mandatory requirement must the institution fulfill before deployment?

Hard
12

Which THREE are effective methods for ensuring data privacy in AI training? (Choose three.)

Hard
13

A marketing team wants to use a third-party generative AI service to create ad copy. The service provider states that submitted prompts and outputs may be used to improve its models. The company's legal team is concerned about confidential product launch details being entered into the tool. Which of the following is the MOST appropriate first step?

Easy
14

A bank uses an AI model to approve loans. During an audit, it is found that the model denies loans at a higher rate for a certain ethnic group. Which governance principle is primarily violated?

Easy
15

A hospital deploys an AI diagnostic assistant that analyzes medical images. The system has been in use for six months, and radiologists have reported that the AI is increasingly confident in its predictions, but sometimes misses rare conditions. The AI ethics board is concerned about overreliance and potential harm from false negatives. They want to implement a governance framework that ensures appropriate human oversight. The hospital has a limited IT budget. What is the best approach?

Medium
16

A financial institution uses an AI model to approve loan applications. The model was trained on historical data that included biased lending practices. The bank's ethics committee wants to mitigate bias without removing protected attributes. Which approach best balances fairness and model performance?

Hard
17

Which THREE are key principles of trustworthy AI according to the OECD?

Medium
18

A manufacturing company uses a predictive maintenance AI system to schedule equipment repairs. The system was trained on sensor data from machinery. Recently, the system has been missing failures, leading to unexpected downtime. An investigation reveals that the sensor data from one plant has been corrupted due to a sensor malfunction. The corrupted data was used in retraining. The company needs to restore system accuracy quickly. The data science team can access the training logs. What is the best course of action?

Medium
19

Which TWO of the following are common methods for mitigating bias in AI models?

Medium
20

Which THREE of the following are key components of an AI governance framework?

Medium
21

A financial institution uses an AI model to approve small business loans. The model has a high approval rate for women-owned businesses but low for minority-owned businesses. The compliance officer is concerned about disparate impact. Which governance process should be implemented first?

Medium
22

A company's AI governance board requires each model to have a model card documenting intended use, performance metrics, and limitations. What is the primary purpose of a model card?

Hard
23

A large e-commerce company uses a recommendation engine trained on millions of user interactions. Recently, the marketing team noticed a sharp increase in click-through rates for a particular product category. Upon investigation, an engineer found that a competitor had injected fake user profiles that consistently clicked on their products, skewing the training data. The company needs to remediate the attack and prevent future occurrences. The team has limited time and budget. Which course of action should the company take first?

Hard
24

Refer to the exhibit. A security auditor identifies a critical vulnerability that could allow an attacker to manipulate model inputs to cause misclassification. Which configuration setting is most directly responsible for this vulnerability?

Easy
25

An AI development team is building a system to detect fraudulent transactions. They want to ensure the model complies with regulations requiring that individuals can question automated decisions. Which governance element is most relevant?

Easy
26

A multinational bank operates AI models in several countries with different privacy laws. The governance team wants a single control that demonstrates accountability across all jurisdictions. Which approach is most effective?

Medium
27

A financial institution is implementing an AI-based fraud detection system. The compliance officer is concerned about potential bias in the model that could lead to unfair treatment of certain customer groups. Which governance practice should be prioritized to address this concern?

Easy
28

A government agency uses an AI system to prioritize emergency response calls. An auditor finds that the model's decisions cannot be explained to citizens. Which governance mechanism is most appropriate to address this?

Hard
29

A retail company wants to ensure its AI-driven pricing algorithm does not discriminate against customers in protected groups. Which governance practice should be implemented first?

Easy
30

A security researcher demonstrates that by adding small perturbations to an image of a stop sign, an autonomous vehicle's AI misclassifies it as a speed limit sign. This is an example of which type of attack?

Hard
31

Which principle ensures that AI decisions can be traced back and understood by humans?

Easy
32

Which TWO of the following are effective techniques for detecting bias in an AI model?

Medium
33

A bank deploys an AI system to approve loan applications. During testing, the model denies a disproportionate number of applicants from a particular demographic group, even after controlling for credit history. Which ethical principle is being violated?

Easy
34

A hospital deploys an AI model to predict patient readmission risk. The compliance team asks which TWO technical controls help comply with data minimization principles under AI governance frameworks. (Choose two.)

Medium
35

A financial services firm uses an AI model to detect fraudulent transactions. The model's decisions must be explainable to regulators. The data science team proposes using a complex deep neural network with high accuracy. Which of the following approaches best balances accuracy and explainability?

Hard
36

A hospital wants to deploy an AI triage model that recommends which emergency department patients should be seen first. The clinical governance committee is defining controls to ensure the system remains accountable and safe after go-live. Which TWO controls BEST support ongoing accountability for this AI system? (Choose two.)

Medium
37

A retail bank's fraud model was trained on customer transaction data that included account holders in the EU. An internal audit finds the training pipeline copied raw transaction records, including names and card numbers, into an unencrypted research bucket for model retraining. Which action best aligns the remediation with data-protection obligations for that pipeline?

Hard
38

Which TWO of the following are common techniques to improve the transparency and interpretability of an AI model?

Easy
39

A healthcare startup deploys an AI model to predict patient readmission rates. An internal audit reveals that the model consistently underestimates readmission risk for non-native English speakers. According to AI ethics principles, what is the most appropriate course of action?

Medium
40

A security analyst is reviewing logs from an AI-powered recommendation system and notices an unusually high number of requests for products from a specific vendor. The analyst suspects data poisoning. Which mitigation strategy should be implemented first?

Easy
41

A large hospital system deploys an AI triage system for emergency rooms. The system uses patient vitals and symptoms to recommend treatment priority. Six months after deployment, complaints arise that the system frequently underestimates the severity of symptoms for patients from certain ethnic backgrounds. A data scientist runs a bias audit and finds that the model's false negative rate is 20% higher for the minority group. The hospital's AI governance board requires immediate corrective action. The data science team has limited resources and cannot retrain the entire model from scratch. They have access to the training data, which is imbalanced. The model is a gradient boosted tree. Which course of action best addresses the bias while minimizing operational impact?

Hard
42

An AI model's performance drops significantly in production compared to testing. The data shows distribution shift. What is the best first step?

Medium
43

A healthcare analytics company has trained an AI model to predict patient readmission risk using a dataset that includes ZIP code, race, and historical healthcare costs. Before deployment, the compliance team runs a fairness audit and finds that the model's predictions correlate strongly with race even though race was not used as a direct input feature. Which of the following BEST describes this phenomenon?

Medium
44

A research lab trains a language model using DP-SGD. What primary privacy risk does this technique mitigate?

Hard
45

You are an AI governance officer at a bank that uses a machine learning model to predict credit risk. The model was developed by an external vendor and uses a proprietary algorithm. The bank's compliance team has determined that the model must be explainable to meet regulatory requirements. However, the vendor claims the model is a 'black box' and cannot provide explanations. You need to ensure compliance while maintaining the model's performance. What is the best course of action?

Medium
46

Which AI governance framework is specifically designed by the U.S. National Institute of Standards and Technology (NIST) to help organizations manage AI risks?

Medium
47

Which TWO of the following are effective defenses against adversarial examples in AI systems?

Medium
48

A retail company uses an AI system to detect shoplifting from surveillance footage. The system has been criticized for disproportionately flagging customers from certain ethnic groups. The company wants to address this ethical concern. Which of the following should be the first step?

Easy
49

A company uses a machine learning model to recommend products to customers. The marketing team notices that the model is recommending high-profit items more frequently than low-profit items, even when customers are likely to prefer the latter. This behavior is causing customer dissatisfaction. Which approach would best align the model with customer preferences while maintaining profitability?

Hard
50

An AI system in a self-driving car misinterprets a stop sign due to a small sticker placed on it. This is an example of which security vulnerability?

Easy
51

Which TWO are common attack vectors against AI systems? (Choose two.)

Easy
52

A company deployed an AI chatbot that started generating offensive responses after a data update. The security team needs to quickly mitigate the issue. What should they do first?

Medium
53

A multinational corporation is developing an AI system that will be deployed in multiple countries with varying data protection laws. The legal team wants to ensure compliance with regulations such as the GDPR. Which of the following is the most appropriate action to take during the design phase?

Medium
54

A healthcare AI system used for diagnosis shows a significant accuracy difference between demographic groups. Which technique should be applied to directly reduce this bias during model training?

Medium
55

An organization wants to ensure its AI systems comply with new regulations requiring explanations for automated decisions. Which governance practice is most directly relevant?

Easy
56

A logistics company is preparing an AI governance program for a route-optimization model that influences driver schedules. The compliance team must demonstrate accountability to regulators. Which two practices best establish documented accountability for this system? (Choose two.)

Hard
57

An organization uses an AI-based hiring tool. To prevent bias, they want to ensure the model's decisions are explainable. Which approach is most suitable?

Hard
58

Which THREE of the following are key principles of AI ethics as defined by major frameworks?

Medium
59

Which practice best ensures AI systems comply with regulations like GDPR?

Easy
60

An AI team is developing a model that will make hiring recommendations. Which ethical principle requires that candidates be informed about how their data is used and have a way to challenge decisions?

Easy
61

A social media company uses an AI content moderation system to filter hate speech. The system uses a natural language processing model trained on user reports. Recently, the model's false positive rate has increased, blocking legitimate posts. An internal audit reveals that a coordinated group of users has been falsely reporting harmless posts, causing the model to learn incorrect patterns. The company needs to address the attack and restore accuracy. The engineering team can modify the training pipeline. What is the most effective first step?

Hard
62

Which TWO of the following are common threats to AI model security?

Easy
63

A cybersecurity analyst monitors an AI chatbot that frequently produces offensive responses when given specific prompts. The development team suspects an adversarial attack. Which mitigation strategy is most effective against such prompt injection attacks?

Easy
64

A financial services firm deploys an AI system to screen loan applications. The model was trained on historical data that reflected biased lending practices. After deployment, a regulatory body investigates and finds that the model denies loans at a disproportionately higher rate to a protected demographic group. The firm must address this issue while maintaining compliance with fair lending laws. The Chief AI Officer proposes four possible actions. Which action is the most appropriate first step?

Hard
65

An AI system used for resume screening is found to consistently rank male candidates higher than female candidates with similar qualifications. The HR director wants to remediate this bias without significantly reducing model accuracy. Which technique should be applied?

Medium
66

A startup develops an AI recruiting tool that screens resumes. After deployment, they receive a complaint from a candidate who claims the system rejected them due to age discrimination. The startup has no formal AI governance process. They want to quickly assess and remediate the issue. The dataset includes age as a feature. What should they do first?

Easy
67

During a penetration test, a security engineer discovers that an AI-powered chatbot can be tricked into revealing sensitive customer data by using specially crafted prompts. What type of attack is this, and what is the best mitigation?

Hard
68

A global bank deploys a generative AI assistant that summarizes internal policy documents for loan officers across the European Union and the United States. The compliance team must ensure the system respects regional AI regulations. Which of the following actions is MOST appropriate for aligning the deployment with these requirements?

Hard
69

A data scientist trains a sentiment analysis model on user reviews. To ensure transparency, they want to explain why the model classified a particular review as negative. Which explainability technique should they use?

Medium
70

A media company uses a generative AI service to draft marketing copy. Legal asks the AI governance team to reduce the risk that outputs reproduce copyrighted passages from the training corpus. Which control most directly addresses that specific risk?

Easy
71

Which THREE of the following are key principles of trustworthy AI as defined by major regulatory bodies?

Medium
72

An organization implements AI governance following the NIST AI Risk Management Framework. They need to ensure that all model decisions are logged with sufficient detail for later audit. Which logging requirement is most critical for traceability?

Hard
73

A company implements an AI-based chatbot for customer service. After deployment, customers report that the chatbot sometimes uses offensive language. The development team reviews the training data and finds no explicit offensive content. What is the most likely explanation?

Medium
74

A hospital's AI triage model was trained on five years of historical admissions. A governance review finds that patients over 75 are systematically assigned lower acuity scores than clinically equivalent younger patients, even though age is not an input feature. Which governance control most directly addresses this finding?

Medium
75

Which TWO of the following are essential components of a responsible AI governance framework?

Easy
76

A healthcare organization uses an AI model to predict patient readmission risk. To comply with patient privacy regulations, they apply differential privacy during training. What is the primary trade-off of using differential privacy?

Medium
77

A national security agency uses AI to analyze surveillance data for threat detection. The system is deployed in a high-stakes environment where false negatives could lead to missed threats, and false positives waste analyst time. Recently, a known hacker group attempted to evade detection by subtly modifying their communication patterns over time, a form of adversarial evasion. The agency wants to harden the system while maintaining performance. The system uses a deep neural network. Which mitigation strategy is most appropriate?

Hard
78

During a red-team exercise on an AI model, testers successfully extracted training data. Which vulnerability is this?

Hard
79

Which TWO of the following are best practices for securing an AI model against adversarial attacks?

Easy
80

An organization wants to implement an AI ethics board. Which composition best ensures independence and expertise?

Hard
81

A city agency deploys an AI system that scores permit applications. The vendor refuses to disclose model weights or feature importance, citing trade secrets. The agency's oversight board must still meet its obligation to explain adverse decisions to applicants. Which approach best satisfies that obligation?

Medium
82

A company is deploying an AI-based resume screening tool. The security team is concerned about adversarial attacks that could manipulate the tool's rankings. Which TWO of the following are effective defenses against such attacks? (Choose two.)

Hard

Frequently asked questions

What does the AI Security, Ethics and Governance domain cover on the AI0-001 exam?
Be able to diagnose why an AI system is unfair, insecure, or non-compliant, then select the correct control: bias mitigation, adversarial defense, or privacy-preserving training. The key is matching the control to the stated risk and acknowledging its trade-offs, especially accuracy loss from differential privacy.
How many questions are in this domain?
This page lists all 82 AI Security, Ethics and Governance questions in the AI0-001 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only AI Security, Ethics and Governance questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
comptia-ai COMPTIA-AI ai security ethics governance Practice Questions