Courseiva

CCNA AI Security, Ethics and Governance Questions

75 of 82 questions · Page 1/2 · AI Security, Ethics and Governance · Answers revealed

1
MCQeasy

A healthcare organization uses an AI model to recommend treatment plans. The model was trained on data from a single hospital, and now treats patients from multiple demographics. Which ethical concern is most critical?

A.Accountability for treatment outcomes
B.Lack of transparency in model decisions
C.Privacy violations in training data
D.Fairness and bias in predictions
AnswerD

Training on a single hospital's data embeds that population's demographics, so predictions for other groups inherit skewed patterns. This directly creates disparate performance across demographics, making fairness and bias the critical ethical concern the multi-demographic scenario raises.

Why this answer

The model was trained on data from a single hospital, which likely has a homogeneous demographic profile. When deployed across multiple demographics, the model may produce biased or unfair predictions for underrepresented groups, making fairness and bias the most critical ethical concern. This directly violates the principle of distributive justice in AI ethics.

Exam trap

The AI0-001 exam often tests the distinction between general ethical principles (like accountability or transparency) and the specific, root-cause ethical violation triggered by the scenario, which here is fairness and bias due to demographic mismatch in training data.

How to eliminate wrong answers

Option A is wrong because accountability for treatment outcomes is a general ethical concern but not the most critical here; the primary issue is that the model's training data lacks demographic diversity, which leads to biased predictions before accountability can even be assessed. Option B is wrong because lack of transparency (black-box nature) is a separate concern; while it can exacerbate bias, the core problem is that the model's training data does not represent the target population, not that the model's decisions are opaque. Option C is wrong because privacy violations in training data are a valid concern but not directly triggered by the scenario; the scenario describes using data from a single hospital, which does not inherently imply privacy breaches, whereas the demographic shift introduces bias.

2
MCQeasy

An organization deploys an AI system that processes personal data of EU citizens. Which regulatory framework imposes strict requirements on automated decision-making and profiling?

A.Payment Card Industry Data Security Standard (PCI DSS)
B.General Data Protection Regulation (GDPR)
C.Health Insurance Portability and Accountability Act (HIPAA)
D.Sarbanes-Oxley Act (SOX)
AnswerB

The GDPR governs processing of EU citizens' personal data and, under Article 22, restricts solely automated decisions and profiling that produce legal or similarly significant effects, demanding safeguards such as human intervention and the right to contest. That directly satisfies the stem's constraint of strict automated decision-making requirements.

Why this answer

The General Data Protection Regulation (GDPR) is the correct regulatory framework because it specifically governs the processing of personal data of EU citizens and imposes strict requirements on automated decision-making and profiling under Article 22. This article grants individuals the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects or similarly significant effects. The GDPR also mandates data protection impact assessments and transparency obligations for such AI-driven processing.

Exam trap

The AI0-001 exam often tests candidates' ability to distinguish between data privacy regulations (GDPR) and industry-specific security standards (PCI DSS, HIPAA, SOX), trapping those who confuse data security with data protection governance for AI systems.

How to eliminate wrong answers

Option A is wrong because PCI DSS is a security standard for protecting payment card data, not a framework for regulating automated decision-making or profiling of EU citizens' personal data. Option C is wrong because HIPAA applies to protected health information in the United States and does not address automated decision-making or profiling under EU law. Option D is wrong because SOX is a US federal law focused on financial reporting and corporate governance, with no provisions for personal data processing or AI-driven profiling.

3
MCQhard

A financial institution uses an AI model to approve loans. The model uses features including credit score and ZIP code. During an audit, it is discovered that the model has a high false positive rate for loan default predictions in certain ZIP codes. What should the institution do to address this?

A.Remove the ZIP code feature from the model
B.Increase the decision threshold for those ZIP codes
C.Discontinue use of the model for those ZIP codes
D.Retrain the model with fairness constraints
AnswerD

Retraining with fairness constraints directly targets the ZIP-code disparity by adding a regularisation term that penalises disparate false positive rates across protected groups during optimisation. This satisfies the audit finding: the model's error rates vary by geography, so the constraint forces the learner to equalise them.

Why this answer

Retraining the model with fairness constraints directly addresses the root cause of the bias—the model's learned correlations between ZIP code and default risk. Fairness constraints, such as demographic parity or equalized odds, are applied during training to ensure the model's predictions are not systematically skewed against certain groups. This approach preserves the predictive power of legitimate features while mitigating discriminatory outcomes, aligning with AI governance principles.

Exam trap

The AI0-001 exam often tests the misconception that removing a sensitive feature (like ZIP code) is sufficient to eliminate bias, when in reality correlated proxy features can perpetuate discrimination—a concept known as 'fairness through unawareness' being a flawed approach.

How to eliminate wrong answers

Option A is wrong because removing the ZIP code feature may not eliminate bias if other features (e.g., income, credit history) are correlated with ZIP code, and it could reduce model accuracy by discarding legitimate predictive information. Option B is wrong because increasing the decision threshold for those ZIP codes is a post-hoc adjustment that treats the symptom (high false positives) without fixing the underlying bias, and it may introduce new disparities or violate regulatory requirements for consistent lending standards. Option C is wrong because discontinuing use of the model for those ZIP codes abandons the model's utility entirely for those areas, which is operationally impractical and does not address the bias—it simply avoids the problem rather than correcting it.

4
MCQmedium

An image classification model misclassifies a stop sign as a speed limit sign after a few pixels are altered. What is the most effective defense against such attacks?

A.Use a larger validation dataset
B.Reduce the input image resolution
C.Increase the model's complexity
D.Adversarial training
AnswerD

Adversarial training augments the training set with perturbed examples, such as stop signs with altered pixels, so the model learns to classify them correctly. This directly hardens the decision boundary against the small, deliberate pixel-level perturbations described in the stem, unlike input sanitisation, which cannot anticipate every crafted variant.

Why this answer

Adversarial training is the most effective defense because it explicitly incorporates adversarial examples—like the perturbed stop sign—into the model's training data. By training on both clean and adversarially altered images, the model learns to be robust against small, malicious perturbations that cause misclassification. This directly addresses the root cause of the vulnerability, unlike other options that only mitigate symptoms or ignore the attack vector.

Exam trap

The AI0-001 exam often tests the misconception that increasing dataset size or model complexity improves security, when in fact adversarial training is the only listed option that directly hardens the model against input perturbations.

How to eliminate wrong answers

Option A is wrong because a larger validation dataset does not protect against adversarial perturbations; it only improves the statistical estimate of model performance on clean data, not robustness to crafted attacks. Option B is wrong because reducing input resolution may actually increase vulnerability by discarding fine-grained features that help distinguish objects, and it does not prevent pixel-level manipulations from fooling the model. Option C is wrong because increasing model complexity often makes the model more susceptible to overfitting and adversarial examples, as deeper networks can have larger linear regions that attackers exploit.

5
MCQeasy

A social media company's AI recommendation system pushes extreme content to users, causing harm. Which ethical principle is most violated?

A.Autonomy
B.Justice
C.Beneficence
D.Non-maleficence
AnswerD

Non-maleficence obliges developers to avoid causing harm, and the recommender's amplification of extreme content inflicts direct user harm. This principle is violated more precisely than beneficence, which concerns actively promoting wellbeing rather than refraining from damage.

Why this answer

Non-maleficence (do no harm) is the principle most directly violated because the AI system actively causes harm by pushing extreme content that damages users' mental health or incites harmful behavior. Unlike beneficence (doing good), non-maleficence focuses on avoiding harm, and the system's design fails to prevent foreseeable negative outcomes.

Exam trap

CompTIA often tests the distinction between beneficence and non-maleficence, where candidates mistakenly choose beneficence because they think the system failed to do good, but the actual violation is causing direct harm.

How to eliminate wrong answers

Option A is wrong because autonomy concerns user self-determination and informed consent, not the direct harm from content amplification. Option B is wrong because justice relates to fairness and equitable treatment across user groups, not the specific harm caused by extreme content. Option C is wrong because beneficence requires actively doing good, whereas the core violation here is causing harm, not failing to provide a benefit.

6
Multi-Selectmedium

Which TWO are key requirements for AI governance under the EU AI Act for high-risk AI systems? (Choose two.)

Select 2 answers
A.Regular performance benchmarks
B.Human oversight
C.Open-source licensing
D.Transparency and documentation
E.Mandatory use of cloud
AnswersB, D

Human oversight requires that natural persons monitor high-risk systems, intervene or halt operation, and review outputs. This satisfies the EU AI Act's governance requirement by ensuring meaningful human control over consequential automated decisions, mitigating risks to health, safety and fundamental rights.

Why this answer

Option B (Human oversight) is correct because the EU AI Act explicitly requires that high-risk AI systems be designed and developed with appropriate human oversight mechanisms, allowing humans to effectively monitor, intervene, and override the system to prevent or minimize risks to health, safety, and fundamental rights. Option D (Transparency and documentation) is correct because high-risk AI systems must be accompanied by technical documentation, instructions for use, and logging capabilities that ensure traceability and enable users and authorities to understand the system's functioning and compliance. Options A, C, and E are not key requirements under the Act: regular performance benchmarks are not a mandated governance requirement per se, open-source licensing is not a condition for high-risk compliance (though open-source models have some accommodations), and there is no mandatory use of cloud infrastructure for high-risk AI systems.

Exam trap

The AI0-001 exam often tests the distinction between general best practices (like performance benchmarks) and specific regulatory mandates (like human oversight and transparency), leading candidates to select familiar but non-required options such as regular performance benchmarks.

7
MCQhard

An AI system used for autonomous driving is found to have a lower accuracy in detecting pedestrians with darker skin tones. The development team wants to address this ethical issue. Which action is most effective?

A.Conduct additional testing to measure the disparity
B.Augment the training dataset with more images of pedestrians with darker skin
C.Replace the object detection algorithm with a different one
D.Adjust the model's decision threshold for pedestrian detection
AnswerB

Adding more darker-skinned pedestrian images directly corrects the class imbalance in the training distribution, which is the root cause of the disparate accuracy. The model learns underrepresented features only when sufficient examples exist, so dataset augmentation reduces the bias more effectively than post-hoc threshold tuning or documentation.

Why this answer

Augmenting the training dataset with more images of pedestrians with darker skin directly addresses the root cause of the bias: underrepresentation in the training data. By providing a more balanced and diverse dataset, the model can learn more robust features for all skin tones, reducing accuracy disparity without altering the algorithm's core logic or introducing arbitrary thresholds.

Exam trap

CompTIA often tests the misconception that bias can be fixed by simply changing the algorithm or threshold, when in reality the most effective first step is to address data imbalance through targeted augmentation.

How to eliminate wrong answers

Option A is wrong because additional testing only measures the disparity but does not fix it; it is a diagnostic step, not a corrective action. Option C is wrong because replacing the object detection algorithm does not guarantee improved fairness—bias often stems from training data distribution, not the algorithm itself, and a different algorithm may still exhibit similar biases if trained on the same skewed data. Option D is wrong because adjusting the decision threshold can trade off precision and recall but does not address the underlying data imbalance; it may reduce false negatives for one group at the expense of increased false positives for another, without resolving the root cause.

8
MCQeasy

What is the primary function of an AI ethics board within an organization?

A.Developing algorithms
B.Managing cloud infrastructure
C.Marketing AI products
D.Reviewing AI projects for ethical compliance
AnswerD

An AI ethics board's core remit is governance: examining proposed and live AI projects against ethical principles, flagging risks such as bias or privacy harm, and advising on remediation. It reviews for compliance rather than building models or owning day-to-day operations.

Why this answer

The primary function of an AI ethics board is to review AI projects for ethical compliance, ensuring that the organization's AI systems adhere to established ethical principles, legal standards, and governance frameworks. This board typically assesses risks related to bias, fairness, transparency, and accountability before deployment, rather than engaging in technical development or operational tasks.

Exam trap

The AI0-001 exam often tests the distinction between operational roles (e.g., development, infrastructure, marketing) and governance roles (e.g., ethics review), so the trap here is confusing a technical or business function with the oversight responsibility of an ethics board.

How to eliminate wrong answers

Option A is wrong because developing algorithms is a technical function performed by data scientists and engineers, not by an ethics board, which focuses on governance and oversight. Option B is wrong because managing cloud infrastructure is an IT operations role involving platforms like AWS or Azure, unrelated to ethical review processes. Option C is wrong because marketing AI products is a business development activity that promotes AI solutions, whereas an ethics board provides independent scrutiny to prevent unethical practices.

9
MCQmedium

A healthcare AI system misdiagnosed patients due to adversarial inputs. What security measure should be prioritized?

A.Encrypt all patient data
B.Use stronger authentication
C.Regular software updates
D.Implement adversarial training
AnswerD

Adversarial training augments the training set with perturbed examples, hardening the model's decision boundaries against the malicious inputs that caused misdiagnosis. This directly satisfies the healthcare scenario's requirement to withstand adversarial manipulation, unlike filtering or monitoring, which detect but do not immunise the model.

Why this answer

(Implement adversarial training) is correct because adversarial training makes the model robust to input manipulation. Option A (Encrypt all patient data) protects data privacy but not model integrity. Option B (Use stronger authentication) is for access control.

Option C (Regular software updates) is general maintenance and does not specifically address adversarial inputs.

10
MCQhard

You are a security engineer at a large e-commerce company that uses an AI-based recommendation system. The system is deployed on a Kubernetes cluster and uses a TensorFlow model served via REST API. Recently, the security team detected unusual API calls that caused the model to return incorrect recommendations. Analysis shows that the inputs were crafted to maximize prediction error. The team suspects an adversarial attack. You need to implement a solution that detects and mitigates such attacks in real-time without requiring model retraining. Which approach should you take?

A.Implement an input validation filter to detect and block anomalous inputs
B.Increase the number of model replicas to distribute the load
C.Retrain the model with adversarial examples
D.Roll back the model to a previous version that was not attacked
AnswerA

An input validation filter inspects incoming REST payloads against learned feature distributions, flagging perturbations that maximise prediction error before inference. This satisfies the real-time constraint without retraining, since detection operates on the input manifold rather than model weights. Blocking anomalous vectors prevents crafted adversarial examples from reaching the TensorFlow serving endpoint.

Why this answer

An input validation filter can detect and block adversarial inputs in real-time by analyzing statistical properties (e.g., outlier detection, perturbation magnitude) without modifying the model. This approach is lightweight, operates at the API gateway level, and does not require retraining, making it suitable for immediate deployment against crafted inputs that maximize prediction error.

Exam trap

CompTIA often tests the misconception that retraining or scaling can solve security issues, but the key constraint here is 'real-time detection without retraining,' which eliminates options that require model modification or do not address the attack vector.

How to eliminate wrong answers

Option B is wrong because increasing model replicas only distributes load and improves throughput, but does not detect or block malicious inputs; adversarial attacks exploit model vulnerabilities, not resource exhaustion. Option C is wrong because retraining with adversarial examples requires model retraining, which violates the constraint of 'without requiring model retraining' and is a longer-term solution, not real-time mitigation. Option D is wrong because rolling back to a previous version does not address the root cause; the same adversarial inputs would still be effective against the older model, and the attack vector remains unmitigated.

11
MCQhard

A financial institution uses a deep learning model for loan approvals. Under the EU AI Act, this is considered a high-risk AI system. Which mandatory requirement must the institution fulfill before deployment?

A.Obtain certification from an ISO 27001 auditor
B.Publish the model's source code publicly
C.Register the AI system with the national data protection authority
D.Conduct a risk assessment and bias testing
AnswerD

High-risk classification under the EU AI Act obliges providers to establish a risk management system and test for biased outcomes before deployment. This satisfies the stem's pre-deployment constraint, unlike post-market monitoring or voluntary transparency disclosures.

Why this answer

Under the EU AI Act, high-risk AI systems must undergo a conformity assessment that includes a risk assessment and bias testing to ensure fairness, transparency, and non-discrimination before deployment. This requirement is mandated by Articles 9 and 10 of the Act, which specifically address risk management and data governance for high-risk systems. Option D correctly identifies this mandatory step, as the institution must demonstrate that the model does not produce biased outcomes that could lead to discriminatory lending practices.

Exam trap

The AI0-001 exam often tests the misconception that all AI systems require public transparency or external certification, but the EU AI Act specifically mandates internal risk and bias assessments for high-risk systems, not broad publication or ISO standards.

How to eliminate wrong answers

Option A is wrong because ISO 27001 certification pertains to information security management systems, not to AI-specific risk or bias compliance under the EU AI Act; the Act does not require ISO 27001 certification for high-risk AI systems. Option B is wrong because the EU AI Act does not mandate public disclosure of source code; doing so could violate trade secrets and intellectual property rights, and transparency requirements are limited to documentation and logging, not open-source publication. Option C is wrong because registration with a national data protection authority is not a pre-deployment requirement for high-risk AI systems under the EU AI Act; instead, the Act requires registration in an EU-wide database managed by the European Commission, not individual national authorities.

12
Multi-Selecthard

Which THREE are effective methods for ensuring data privacy in AI training? (Choose three.)

Select 3 answers
A.Data encryption at rest
B.Data anonymization
C.Differential privacy
D.Data replication
E.Federated learning
AnswersB, C, E

Data anonymisation removes or alters personally identifiable information before it enters the training set, so the model never learns identifiers tied to real individuals. This directly satisfies the stem's data privacy requirement by preventing re-identification from model outputs or memorised training data, a stronger safeguard than post-training access controls alone.

Why this answer

Data anonymization (B) is correct because removing or masking personally identifiable information (PII) such as names, addresses, and identifiers before training prevents the model from learning or exposing individual identities. Differential privacy (C) is correct because it adds calibrated statistical noise (e.g., via mechanisms like Laplace or Gaussian noise with a privacy budget epsilon) so that the inclusion or exclusion of any single record has a negligible effect on outputs, providing a formal privacy guarantee. Federated learning (E) is correct because it trains models locally on each device or silo and shares only model updates (e.g., gradients or weights) rather than raw data, keeping sensitive data on the originating endpoint.

Data encryption at rest (A) protects stored data against unauthorized access but does not prevent privacy leakage during training or inference, so it is not one of the three methods for ensuring privacy in AI training. Data replication (D) merely copies data to additional locations, which increases exposure and does nothing to protect privacy, so it is not a valid method.

Exam trap

The AI0-001 exam often tests the distinction between security controls (like encryption) and privacy-preserving techniques, trapping candidates who confuse data protection at rest with privacy during model training.

13
MCQeasy

A marketing team wants to use a third-party generative AI service to create ad copy. The service provider states that submitted prompts and outputs may be used to improve its models. The company's legal team is concerned about confidential product launch details being entered into the tool. Which of the following is the MOST appropriate first step?

A.Prohibit entering confidential information into the tool until a data processing agreement and enterprise configuration that excludes data from training are in place.
B.Allow the team to proceed because the provider's public privacy policy already covers all customer data handling.
C.Instruct the team to paraphrase confidential details before submitting prompts so the information is no longer recognizable.
D.Require the team to delete the chat history after each session to remove the provider's copy of the data.
AnswerA

The provider's default terms allow submitted content to be used for model improvement, which conflicts with protecting confidential launch details. The immediate control is to stop sensitive input while negotiating contractual protections such as a data processing agreement and enabling an enterprise setting that disables training on submitted data. This addresses the risk at its source before any ad copy is generated.

Why this answer

When a provider's terms permit using inputs for model improvement, confidential material should not be entered until contractual and technical safeguards exist. A data processing agreement plus an enterprise configuration that excludes submissions from training reduces the exposure directly. Privacy policies, paraphrasing, and chat deletion do not create enforceable confidentiality protections, so they fail to address the identified risk.

Exam trap

The trap here is assuming that deleting chat history or paraphrasing prompts removes the provider's ability to retain or learn from submitted content.

14
MCQeasy

A bank uses an AI model to approve loans. During an audit, it is found that the model denies loans at a higher rate for a certain ethnic group. Which governance principle is primarily violated?

A.Accountability
B.Fairness
C.Transparency
D.Privacy
AnswerB

Fairness is violated because the model produces disparate denial rates across ethnic groups, breaching equitable treatment. This directly addresses the stem's constraint: audit-detected bias in loan approvals. Fairness in AI governance requires identifying and mitigating such discriminatory outcomes, ensuring decisions are not systematically disadvantageous to protected groups.

Why this answer

The model's disparate impact on a specific ethnic group directly violates the principle of Fairness, which requires that AI systems do not discriminate based on protected attributes such as race, ethnicity, or gender. In lending, fairness is often assessed using metrics like demographic parity or equal opportunity, and a higher denial rate for one group indicates a lack of algorithmic fairness.

Exam trap

The AI0-001 exam often tests the distinction between Fairness and Transparency, where candidates mistakenly choose Transparency because they think 'explaining the bias' is the primary issue, but the question asks which principle is violated by the biased outcome itself.

How to eliminate wrong answers

Option A is wrong because Accountability refers to the assignment of responsibility for the model's decisions and outcomes, not the presence of bias itself; while the bank must be accountable for the bias, the primary violation here is the discriminatory outcome. Option C is wrong because Transparency concerns the ability to explain and understand how the model makes decisions (e.g., through interpretability or documentation), but the core issue is the biased result, not a lack of explanation. Option D is wrong because Privacy involves the protection of personal data and compliance with regulations like GDPR or CCPA; the scenario does not describe unauthorized data use or exposure, only discriminatory lending decisions.

15
MCQmedium

A hospital deploys an AI diagnostic assistant that analyzes medical images. The system has been in use for six months, and radiologists have reported that the AI is increasingly confident in its predictions, but sometimes misses rare conditions. The AI ethics board is concerned about overreliance and potential harm from false negatives. They want to implement a governance framework that ensures appropriate human oversight. The hospital has a limited IT budget. What is the best approach?

A.Implement a human-in-the-loop process where the AI flags low-confidence or rare condition predictions for mandatory radiologist review
B.Add a warning to the AI interface that says 'This tool may miss rare conditions'
C.Require all AI predictions to be reviewed by a radiologist before final diagnosis
D.Increase the AI's false positive threshold to reduce missed cases
AnswerA

Routing low-confidence and rare-condition predictions to mandatory radiologist review directly counters false negatives and overreliance, satisfying the ethics board's oversight requirement while respecting the limited budget, since it adds a triage workflow rather than expensive new infrastructure.

Why this answer

A human-in-the-loop process that triggers mandatory radiologist review only for low-confidence or rare-condition predictions directly addresses the risk of overreliance and false negatives without overwhelming the limited IT budget. This targeted oversight ensures that the AI's increasing confidence does not lead to missed rare conditions, while still allowing routine high-confidence predictions to proceed efficiently. The approach balances safety and resource constraints by focusing human attention where the AI is most likely to err.

Exam trap

CompTIA AI often tests the distinction between passive warnings (like option B) and active workflow controls (like option A), where candidates mistakenly believe that a simple disclaimer is sufficient for governance when actual process enforcement is required.

How to eliminate wrong answers

Option B is wrong because adding a static warning does not enforce any change in workflow or guarantee that radiologists will actually catch missed rare conditions; it merely shifts liability without reducing the risk of false negatives. Option C is wrong because requiring all AI predictions to be reviewed by a radiologist before final diagnosis would be prohibitively expensive and slow, defeating the purpose of using AI to improve throughput and contradicting the limited IT budget constraint. Option D is wrong because increasing the false positive threshold would reduce false negatives but would also increase false positives, potentially overwhelming radiologists with unnecessary alerts and degrading trust in the system, while not addressing the core issue of overreliance on the AI's confidence.

16
MCQhard

A financial institution uses an AI model to approve loan applications. The model was trained on historical data that included biased lending practices. The bank's ethics committee wants to mitigate bias without removing protected attributes. Which approach best balances fairness and model performance?

A.Retrain the model using a balanced dataset
B.Remove all protected attributes from the training data
C.Post-process model outputs to adjust for demographic parity
D.Apply adversarial debiasing during training
AnswerD

Adversarial debiasing trains a predictor alongside an adversary that tries to infer protected attributes from predictions, penalising reliance on them. This reduces disparate impact while retaining protected attributes in the data, preserving predictive performance better than attribute removal.

Why this answer

Adversarial debiasing is the best approach because it directly optimizes the model to reduce bias during training while preserving predictive accuracy. It uses an adversarial network that tries to predict the protected attribute from the model's predictions, forcing the main model to learn representations that are less correlated with that attribute. This allows the bank to keep protected attributes in the data (as required by the ethics committee) while actively mitigating bias.

Exam trap

CompTIA often tests the misconception that simply removing protected attributes (Option B) is sufficient to eliminate bias, when in reality proxy features and correlated variables can perpetuate discrimination.

How to eliminate wrong answers

Option A is wrong because retraining on a balanced dataset only addresses representation bias (e.g., equal numbers of approved/rejected loans across groups) but does not remove the underlying biased correlations learned from historical lending practices; it may also reduce model performance by discarding real-world data distributions. Option B is wrong because removing all protected attributes does not eliminate bias—correlated features (e.g., zip code, income) can act as proxies for race or gender, leading to indirect discrimination, and the ethics committee explicitly wants to keep protected attributes. Option C is wrong because post-processing adjusts outputs after the model is trained, which can improve demographic parity but often at the cost of significant accuracy loss and does not address bias embedded in the model's internal representations.

17
Multi-Selectmedium

Which THREE are key principles of trustworthy AI according to the OECD?

Select 3 answers
A.Profitability
B.Robustness
C.Transparency
D.Scalability
E.Accountability
AnswersB, C, E

Robustness is one of the OECD's five principles for trustworthy AI, requiring systems to withstand adversarial conditions and errors without causing harm. It satisfies the stem's demand for an OECD-recognised principle, alongside human-centred values, fairness, transparency and accountability.

Why this answer

The OECD's Recommendation on Artificial Intelligence defines trustworthy AI around principles including robustness, transparency, and accountability, so options B, C, and E are correct. Robustness (B) is required because AI systems must function reliably, safely, and securely throughout their lifecycle, including resilience to errors and adversarial manipulation. Transparency (C) is a core principle because AI systems should be understandable and disclose meaningful information about their capabilities, limitations, and decision-making so stakeholders can assess them.

Accountability (E) is also essential because organizations and individuals deploying or operating AI must remain answerable for the system's outcomes and provide redress where appropriate. Profitability (A) and scalability (D) are business or engineering goals, not OECD trustworthy-AI principles, so they do not belong.

Exam trap

The AI0-001 exam often tests candidates by including plausible-sounding business or operational terms like 'profitability' or 'scalability' as distractors, leading them to confuse general system attributes with the specific ethical and governance principles outlined by the OECD.

18
MCQmedium

A manufacturing company uses a predictive maintenance AI system to schedule equipment repairs. The system was trained on sensor data from machinery. Recently, the system has been missing failures, leading to unexpected downtime. An investigation reveals that the sensor data from one plant has been corrupted due to a sensor malfunction. The corrupted data was used in retraining. The company needs to restore system accuracy quickly. The data science team can access the training logs. What is the best course of action?

A.Roll back to the previous model version before the corrupt data was ingested, then clean the sensor data and retrain
B.Switch to a simpler linear regression model that is less sensitive to data quality issues
C.Retrain the model using all available data, including the corrupted sensor data
D.Apply a weight to sensor data from that plant to reduce its influence
AnswerA

Rolling back restores the last known-good weights immediately, since the corrupted sensor data only entered during retraining, so downtime stops while the team cleans the faulty plant's readings and retrains. This addresses the stem's need to restore accuracy quickly using accessible training logs.

Why this answer

Rolling back to the previous model version isolates the system from the corrupted sensor data that caused accuracy degradation. Cleaning the sensor data before retraining ensures the model learns from accurate patterns, restoring predictive maintenance reliability. This approach directly addresses the root cause—data corruption—without introducing new risks.

Exam trap

A common misconception is that simpler models are inherently more robust to data quality issues, but model complexity is not the root cause here—data integrity is. The correct fix is to revert to a clean model version and clean the data, not change the algorithm.

How to eliminate wrong answers

Option B is wrong because switching to a simpler linear regression model would reduce the model's capacity to capture complex sensor patterns, likely worsening failure detection rather than fixing the data corruption issue. Option C is wrong because retraining with corrupted data would perpetuate the errors, as the model would learn from faulty sensor readings and continue missing failures. Option D is wrong because applying a weight to reduce influence does not remove the corrupted data's harmful patterns; the model would still learn from inaccurate sensor values, leading to degraded performance.

19
Multi-Selectmedium

Which TWO of the following are common methods for mitigating bias in AI models?

Select 2 answers
A.Using adversarial training
B.Reweighting training samples based on sensitive attributes
C.Applying L1 regularization
D.Adding fairness constraints during training
E.Performing k-fold cross-validation
AnswersB, D

Reweighting assigns higher weights to under-represented samples during training, directly countering the skewed class distributions that produce biased predictions. This satisfies the stem's mitigation requirement by adjusting the model's learned decision boundary rather than merely auditing outcomes post hoc, making it a recognised pre-processing bias mitigation technique.

Why this answer

Option B (Reweighting training samples based on sensitive attributes) is correct because it is a standard pre-processing bias-mitigation technique: by assigning higher weights to underrepresented or historically disadvantaged groups, the model's loss function is adjusted so those samples contribute more to the learned parameters, reducing disparate impact across sensitive attributes. Option D (Adding fairness constraints during training) is correct because it is a standard in-processing technique: fairness metrics such as demographic parity, equalized odds, or disparate impact are encoded as constraints or penalty terms in the objective function, forcing the optimizer to trade off accuracy against a quantified fairness criterion. The other options do not belong: A (adversarial training) is primarily used to improve robustness against adversarial examples, not to mitigate bias; C (L1 regularization) induces sparsity in weights for feature selection and generalization, not fairness; and E (k-fold cross-validation) is a model-evaluation/resampling method for estimating generalization performance, not a bias-mitigation method.

Exam trap

CompTIA often tests the distinction between bias mitigation techniques (pre-processing, in-processing, post-processing) and general ML best practices like regularization or cross-validation, leading candidates to confuse L1 regularization or k-fold cross-validation with fairness methods.

20
Multi-Selectmedium

Which THREE of the following are key components of an AI governance framework?

Select 3 answers
A.Regular auditing and monitoring for compliance.
B.Cloud-based deployment for scalability.
C.Ethical guidelines for AI development and deployment.
D.Explainability mechanisms for model decisions.
E.Model accuracy thresholds for production deployment.
AnswersA, C, D

Regular auditing and monitoring verify that AI systems continue to comply with policies and regulations after deployment, detecting drift, bias and misuse. This provides the ongoing assurance and accountability that an AI governance framework requires.

Why this answer

A is correct because regular auditing and monitoring for compliance is a core governance control that provides ongoing assurance that AI systems adhere to policies, regulations, and internal standards, enabling detection and remediation of drift or violations. C is correct because ethical guidelines for AI development and deployment establish the principles (e.g., fairness, transparency, accountability, privacy) that direct how AI is designed and used, forming the normative backbone of any governance framework. D is correct because explainability mechanisms for model decisions support accountability and oversight by making model behavior interpretable to stakeholders, auditors, and regulators, which is essential for contestability and trust.

B does not belong because cloud-based deployment for scalability is an infrastructure/architecture choice, not a governance component, and governance applies regardless of hosting model. E does not belong because model accuracy thresholds for production deployment are a performance/quality gate, not a governance framework component, and accuracy alone does not address compliance, ethics, or explainability.

Exam trap

CompTIA often tests the distinction between governance components (policies, ethics, oversight) and operational or technical metrics (deployment, accuracy thresholds), leading candidates to confuse performance requirements with governance pillars.

21
MCQmedium

A financial institution uses an AI model to approve small business loans. The model has a high approval rate for women-owned businesses but low for minority-owned businesses. The compliance officer is concerned about disparate impact. Which governance process should be implemented first?

A.Remove gender and ethnicity features from the model
B.Conduct a bias audit and fairness assessment using relevant metrics
C.Publish the model's decision-making criteria to the public
D.Immediately adjust the approval threshold to equalize rates
AnswerB

A bias audit quantifies approval-rate disparities across protected groups using fairness metrics such as disparate impact ratio, establishing the evidence base the compliance officer needs. It must precede mitigation, since remediation choices depend on which specific metrics breach acceptable thresholds.

Why this answer

A bias audit and fairness assessment should be conducted first to quantify the disparate impact and identify root causes. Option A is wrong because simply removing sensitive features does not guarantee fairness and may be insufficient or illegal. Option C is wrong because publishing decision-making criteria without first addressing bias could expose the institution to liability and undermine trust.

Option D is wrong because adjusting the approval threshold without thorough analysis can be arbitrary, may not address underlying bias, and could lead to reverse discrimination or mask systemic issues.

22
MCQhard

A company's AI governance board requires each model to have a model card documenting intended use, performance metrics, and limitations. What is the primary purpose of a model card?

A.To provide transparent documentation of model capabilities and limitations
B.To specify the exact training algorithm and hyperparameters
C.To outline a complete risk assessment framework
D.To serve as a legal contract between developers and users
AnswerA

A model card records intended use, performance metrics and known limitations, giving governance boards and downstream consumers the documentation needed to judge whether a model suits a given context. This transparency artefact directly fulfils the governance board's requirement for documented capabilities and constraints.

Why this answer

A model card is a standardized documentation framework that provides transparent, concise information about a machine learning model's intended use, performance metrics, and limitations. This transparency enables stakeholders to understand the model's capabilities and potential biases, ensuring responsible deployment and governance as required by AI ethics and governance frameworks.

Exam trap

The AI0-001 exam often tests the distinction between documentation for transparency (model card) and detailed technical specifications (hyperparameters) or legal instruments, so candidates mistakenly choose B or D because they confuse 'documentation' with exhaustive technical detail or binding agreements.

How to eliminate wrong answers

Option B is wrong because specifying the exact training algorithm and hyperparameters is a detail of model development documentation, not the primary purpose of a model card, which focuses on high-level transparency for governance and end-users. Option C is wrong because a complete risk assessment framework is a broader governance artifact (e.g., an AI risk register) that may reference model cards but is not the primary purpose of the card itself. Option D is wrong because a model card is not a legal contract; it is a technical documentation tool for transparency, and legal agreements are separate documents governed by terms of service or licensing.

23
MCQhard

A large e-commerce company uses a recommendation engine trained on millions of user interactions. Recently, the marketing team noticed a sharp increase in click-through rates for a particular product category. Upon investigation, an engineer found that a competitor had injected fake user profiles that consistently clicked on their products, skewing the training data. The company needs to remediate the attack and prevent future occurrences. The team has limited time and budget. Which course of action should the company take first?

A.Identify and remove the fake user profiles from the training dataset, then retrain the model
B.Implement adversarial training to make the model robust to future poisoning attempts
C.Decrease the frequency of model retraining to limit exposure to new data
D.Add differential privacy noise to the training data to mask the injected profiles
AnswerA

Data poisoning is remediated at its source: the injected fake profiles corrupt the training distribution, so removing them and retraining restores the model's integrity. This addresses the stem's constraint of limited time and budget, since it is a targeted dataset cleanse rather than a costly architectural overhaul or ongoing monitoring programme.

Why this answer

The immediate priority is to remove the poisoned data from the training set and retrain the model, as the fake profiles are actively skewing predictions and causing incorrect click-through rate spikes. This direct remediation addresses the root cause with minimal time and budget, aligning with the team's constraints. Without cleaning the data, any further training or defensive measures would still operate on corrupted inputs.

Exam trap

The AI0-001 exam often tests the principle that immediate incident response (clean and retrain) must precede long-term defenses, tempting candidates to choose sophisticated solutions like adversarial training or differential privacy that are premature without first removing the poisoned data.

How to eliminate wrong answers

Option B is wrong because adversarial training is a proactive defense that makes models robust to future attacks, but it does not remove existing poisoned data; the current model is already compromised and needs immediate cleanup first. Option C is wrong because decreasing retraining frequency would actually prolong exposure to the poisoned data, allowing the attack to continue influencing recommendations for longer. Option D is wrong because differential privacy adds noise to protect individual privacy, not to correct injected profiles; it would not remove the fake clicks and could degrade model accuracy without addressing the attack.

24
MCQeasy

Refer to the exhibit. A security auditor identifies a critical vulnerability that could allow an attacker to manipulate model inputs to cause misclassification. Which configuration setting is most directly responsible for this vulnerability?

A.enable_input_sanitization = true
B.audit_level = basic
C.enable_adversarial_defense = false
D.pii_detection = enabled
AnswerC

Disabling adversarial defence removes the input-perturbation filtering that detects and sanitises crafted samples before inference, so manipulated inputs reach the model unchecked and cause misclassification. This setting directly governs the vulnerability the auditor identified, whereas other options address access control or data handling rather than input integrity.

Why this answer

The vulnerability described is an adversarial attack on model inputs, which directly exploits the absence of adversarial defenses. Setting `enable_adversarial_defense = false` disables mechanisms like adversarial training or input perturbation detection that prevent misclassification from manipulated inputs. This configuration is the most direct root cause because it explicitly turns off the defense designed to counter such attacks.

Exam trap

The AI0-001 exam often tests the distinction between input sanitization (which handles malformed or malicious data) and adversarial defense (which specifically counters perturbation-based attacks), causing candidates to mistakenly choose input sanitization as the answer.

How to eliminate wrong answers

Option A is wrong because `enable_input_sanitization = true` would actually help prevent input manipulation by cleaning or validating inputs, so enabling it reduces vulnerability, not causes it. Option B is wrong because `audit_level = basic` controls the granularity of logging and monitoring, not the security posture against adversarial inputs; it affects visibility, not defense. Option D is wrong because `pii_detection = enabled` focuses on identifying personally identifiable information for compliance, not on defending against adversarial perturbations that cause misclassification.

25
MCQeasy

An AI development team is building a system to detect fraudulent transactions. They want to ensure the model complies with regulations requiring that individuals can question automated decisions. Which governance element is most relevant?

A.Right to explanation
B.Model versioning
C.Differential privacy
D.Data minimization
AnswerA

The right to explanation gives individuals meaningful information about the logic and factors behind an automated decision, letting them question and contest outcomes. It directly satisfies the stem's regulatory requirement that people can challenge automated fraud determinations, unlike accuracy or latency governance elements.

Why this answer

The right to explanation is a governance principle that requires automated decision-making systems to provide individuals with meaningful information about how decisions are made. In the context of fraudulent transaction detection, this regulation ensures that a customer can question why a transaction was flagged, and the model must be able to provide an interpretable rationale. This directly aligns with the scenario's requirement for compliance with regulations allowing individuals to question automated decisions.

Exam trap

The trap here is that candidates often confuse governance principles like data minimization or differential privacy (which deal with data handling and privacy) with the specific regulatory requirement for transparency and contestability of automated decisions, which is the right to explanation.

How to eliminate wrong answers

Option B (Model versioning) is wrong because it refers to tracking and managing different iterations of a model for reproducibility and rollback, not to providing explanations to end-users about specific decisions. Option C (Differential privacy) is wrong because it is a technique for adding noise to data to protect individual privacy during training, not a mechanism for explaining or justifying individual automated decisions. Option D (Data minimization) is wrong because it is a principle of collecting only the necessary data for a task, which relates to privacy and storage, not to the transparency or contestability of automated decisions.

26
MCQmedium

A multinational bank operates AI models in several countries with different privacy laws. The governance team wants a single control that demonstrates accountability across all jurisdictions. Which approach is most effective?

A.Adopt a unified AI governance framework with region-specific controls.
B.Outsource all AI compliance to a third-party auditor.
C.Apply the strictest privacy law to all regions.
D.Let each country's team create its own AI policy.
AnswerA

A unified framework provides consistent principles, roles, and documentation, while region-specific controls address local legal requirements. This demonstrates accountability across jurisdictions by showing a coherent governance structure that adapts to local rules. It is more effective than fragmented policies because it enables oversight, auditing, and consistent risk management globally.

Why this answer

A unified AI governance framework with region-specific controls balances consistent principles with local legal compliance, which is the most effective way to demonstrate accountability across jurisdictions. Applying one law globally, decentralizing policy, or outsourcing compliance do not provide the same coherent, auditable structure.

Exam trap

The trap here is believing that accountability can be delegated or that one strict law can uniformly apply across all regions.

27
MCQeasy

A financial institution is implementing an AI-based fraud detection system. The compliance officer is concerned about potential bias in the model that could lead to unfair treatment of certain customer groups. Which governance practice should be prioritized to address this concern?

A.Increase the diversity of the training data by collecting more samples from underrepresented groups.
B.Schedule regular bias audits using fairness metrics.
C.Retrain the model every month with the latest transaction data.
D.Use SHAP values to provide explanations for each prediction.
AnswerB

Regular bias audits measure outcomes across protected customer groups using fairness metrics, exposing disparate treatment before it harms applicants or breaches regulation. This ongoing monitoring gives the compliance officer evidence-based oversight, satisfying the governance requirement more directly than one-off reviews.

Why this answer

Regular bias audits using fairness metrics (Option B) are the correct governance practice because they provide a systematic, quantitative method to detect and measure disparate impact across protected groups. Unlike simply collecting more data, audits directly evaluate model outputs for statistical parity, equal opportunity, or other fairness definitions, enabling the institution to identify and remediate bias proactively. This aligns with regulatory expectations for ongoing monitoring and accountability in AI governance.

Exam trap

CompTIA often tests the distinction between interpretability (explaining a single prediction) and fairness (systematic bias across groups), leading candidates to mistakenly choose SHAP values (Option D) as a bias mitigation technique when it is only an explanation tool.

How to eliminate wrong answers

Option A is wrong because merely increasing training data diversity does not guarantee fairness; the model can still learn biased correlations from the data or amplify existing societal biases, and without fairness metrics, there is no way to measure whether the outcome is equitable. Option C is wrong because retraining monthly with the latest transaction data addresses model drift and concept drift, not bias; bias can persist or even worsen with new data if the underlying data generation process remains biased. Option D is wrong because SHAP values provide local interpretability for individual predictions but do not measure or mitigate systemic bias across groups; they explain why a specific decision was made, not whether the model treats groups fairly overall.

28
MCQhard

A government agency uses an AI system to prioritize emergency response calls. An auditor finds that the model's decisions cannot be explained to citizens. Which governance mechanism is most appropriate to address this?

A.Publish the model's full training dataset.
B.Replace the model with a simpler linear regression.
C.Add a disclaimer that decisions are final and not subject to review.
D.Implement a right-to-explanation process with model-agnostic explanation tools.
AnswerD

A right-to-explanation process gives affected individuals understandable reasons for automated decisions, satisfying due process and ethical governance. Model-agnostic tools such as LIME or SHAP can approximate feature contributions even for complex models. This directly addresses the auditor's finding by making decisions contestable and transparent without requiring a full model rebuild.

Why this answer

A right-to-explanation process with model-agnostic tools directly provides understandable reasons for automated decisions, which is the governance mechanism the auditor's finding requires. Replacing the model, publishing data, or disclaiming review do not satisfy the need for contestable, explainable decisions.

Exam trap

The trap here is assuming that explainability requires sacrificing model performance or that publishing data equals explaining decisions.

29
MCQeasy

A retail company wants to ensure its AI-driven pricing algorithm does not discriminate against customers in protected groups. Which governance practice should be implemented first?

A.Increase the model's training data volume.
B.Deploy the model and monitor complaints.
C.Conduct a bias impact assessment before deployment.
D.Publish the algorithm's source code publicly.
AnswerC

A bias impact assessment is a proactive governance step that identifies and mitigates discriminatory effects before the model affects customers. It examines training data, features, and outcomes for disparate impact, aligning with ethical AI principles. Performing it first prevents harm and provides documentation for regulators, making it the foundational practice for fair pricing.

Why this answer

A bias impact assessment is the proactive governance practice that systematically evaluates whether the pricing algorithm disadvantages protected groups. It informs mitigation before deployment, whereas code publication, more data, or reactive monitoring do not directly prevent discriminatory outcomes.

Exam trap

The trap here is equating transparency or larger datasets with fairness, when the first required step is a structured bias assessment.

30
MCQhard

A security researcher demonstrates that by adding small perturbations to an image of a stop sign, an autonomous vehicle's AI misclassifies it as a speed limit sign. This is an example of which type of attack?

A.Data poisoning attack
B.Model extraction attack
C.Adversarial example attack
D.Membership inference attack
AnswerC

Adversarial example attacks exploit imperceptible input perturbations that shift a model across its decision boundary, exactly as described: the stop sign's pixels are altered slightly so the classifier outputs "speed limit". The stem's defining constraint — misclassification caused by deliberately crafted noise rather than data poisoning or model theft — matches this category precisely.

Why this answer

This is an adversarial example attack because the researcher adds imperceptible perturbations to the input image (the stop sign) to cause the AI model to output an incorrect classification (speed limit sign). Adversarial examples exploit the model's sensitivity to small, crafted changes in input data, leading to misclassification without altering the underlying task or training data.

Exam trap

The AI0-001 exam often tests the distinction between attacks that occur during training (poisoning) versus inference (adversarial examples), so candidates mistakenly choose data poisoning when the scenario clearly describes input manipulation at test time.

How to eliminate wrong answers

Option A is wrong because data poisoning attacks involve corrupting the training data (e.g., injecting malicious samples) to manipulate the model's learned behavior, not perturbing inputs at inference time. Option B is wrong because model extraction attacks aim to steal a model's architecture or parameters by querying it (e.g., via API calls), not by modifying inputs to cause misclassification. Option D is wrong because membership inference attacks determine whether a specific data point was used in the model's training set, not by perturbing inputs to cause misclassification.

31
MCQeasy

Which principle ensures that AI decisions can be traced back and understood by humans?

A.Transparency
B.Privacy
C.Robustness
D.Accountability
AnswerA

Transparency requires documenting data sources, model logic and decision pathways, so each AI output can be traced and explained to auditors, regulators or affected users. It directly satisfies the stem's demand for traceability and human comprehension, unlike accountability, which assigns responsibility without necessarily exposing how a decision was reached.

Why this answer

Transparency is the principle that ensures AI decisions can be traced back and understood by humans. It requires that the internal workings of an AI model, including its inputs, decision paths, and outputs, are documented and interpretable, enabling auditability and trust. Without transparency, stakeholders cannot verify whether the AI system is behaving as intended or complying with ethical and regulatory standards.

Exam trap

The AI0-001 exam often tests the confusion between Accountability and Transparency, where candidates mistakenly think that assigning responsibility (Accountability) automatically ensures the decision path is visible, but in reality, Accountability can exist without full Transparency if the system is a black box.

How to eliminate wrong answers

Option B is wrong because Privacy focuses on protecting personal data and controlling its collection, use, and sharing, not on making AI decisions traceable or understandable. Option C is wrong because Robustness concerns the system's ability to maintain performance under adversarial conditions or unexpected inputs, not the traceability of its decision-making process. Option D is wrong because Accountability refers to assigning responsibility for AI outcomes and ensuring there are mechanisms for redress, but it does not inherently require that the decision-making process itself be transparent or understandable.

32
Multi-Selectmedium

Which TWO of the following are effective techniques for detecting bias in an AI model?

Select 2 answers
A.Fairness metrics such as equal opportunity difference
B.Feature importance scores
C.Confusion matrix on the entire dataset
D.Cross-validation accuracy
E.Disparate impact analysis
AnswersA, E

Equal opportunity difference compares true positive rates across protected groups, revealing whether a model misses positive cases disproportionately for one group. This group-fairness metric directly quantifies disparate error rates, making it an effective bias detection technique.

Why this answer

Option A, fairness metrics such as equal opportunity difference, is correct because it quantitatively compares true positive rates across protected groups, directly exposing unequal model performance that indicates bias. Option E, disparate impact analysis, is correct because it applies the four-fifths (80%) rule to compare selection or approval rates between groups, a standard legal and statistical method for detecting discriminatory outcomes. Options B, C, and D are not marked correct: feature importance scores only show which inputs influence predictions and do not by themselves reveal bias against a group; a confusion matrix on the entire dataset aggregates all groups and hides per-group disparities unless disaggregated; and cross-validation accuracy measures overall generalization performance, not fairness across subgroups.

Exam trap

The AI0-001 exam often tests the distinction between model performance metrics (accuracy, confusion matrix) and fairness-specific metrics, leading candidates to mistakenly select cross-validation accuracy or feature importance as bias detection tools.

33
MCQeasy

A bank deploys an AI system to approve loan applications. During testing, the model denies a disproportionate number of applicants from a particular demographic group, even after controlling for credit history. Which ethical principle is being violated?

A.Transparency
B.Privacy
C.Accountability
D.Fairness
AnswerD

Fairness requires that outcomes not disadvantage protected groups after legitimate factors are controlled. Denying one demographic disproportionately despite equivalent credit history breaches this principle, indicating bias embedded in training data or features rather than genuine creditworthiness differences.

Why this answer

The AI system's disparate impact on a demographic group, even after controlling for credit history, directly violates the principle of fairness. Fairness in AI requires that models do not produce biased outcomes that systematically disadvantage protected groups, regardless of whether the bias stems from training data, feature selection, or algorithmic design. This scenario describes a clear case of algorithmic bias, which fairness principles aim to prevent.

Exam trap

The AI0-001 exam often tests the distinction between fairness and transparency, where candidates mistakenly choose transparency because they confuse 'explaining why the model denied loans' with 'the model being biased against a group.'

How to eliminate wrong answers

Option A is wrong because transparency refers to the openness and explainability of AI decisions, not the presence of biased outcomes; a model can be fully transparent yet still unfair. Option B is wrong because privacy concerns the protection of personal data and consent, not the equitable treatment of groups in decision-making. Option C is wrong because accountability involves assigning responsibility for AI outcomes, but the core ethical breach here is the biased result itself, not the lack of a responsible party.

34
Multi-Selectmedium

A hospital deploys an AI model to predict patient readmission risk. The compliance team asks which TWO technical controls help comply with data minimization principles under AI governance frameworks. (Choose two.)

Select 2 answers
A.Use federated learning to keep raw data on local devices.
B.Apply differential privacy during model training.
C.Anonymize data by removing patient names before training.
D.Store all training data in a single encrypted data lake.
E.Require users to consent to broad data usage terms.
AnswersA, B

Federated learning trains a shared model by exchanging only model updates, not raw patient records, so sensitive data never leaves the local environment. This reduces the volume of data centralized, satisfying data minimization by design. It is particularly relevant in healthcare, where moving patient data across systems increases regulatory and breach risk.

Why this answer

Differential privacy and federated learning both limit how much individual data influences the model or leaves its source, which is the core of data minimization. Encryption, consent, and simple de-identification do not reduce the scope of data collection or use, so they do not satisfy the principle as directly.

Exam trap

The trap here is assuming that any privacy-related measure, such as encryption or consent, automatically fulfills data minimization requirements.

35
MCQhard

A financial services firm uses an AI model to detect fraudulent transactions. The model's decisions must be explainable to regulators. The data science team proposes using a complex deep neural network with high accuracy. Which of the following approaches best balances accuracy and explainability?

A.Use the deep neural network without explanations but provide regulators with the model's overall accuracy metrics.
B.Train a surrogate decision tree to mimic the neural network's predictions and use that for explanations.
C.Replace the deep neural network with a simple logistic regression model to ensure full interpretability.
D.Use the deep neural network and apply post-hoc explanation techniques such as LIME or SHAP.
AnswerD

Post-hoc explanation methods like LIME and SHAP can provide local explanations for individual predictions without sacrificing the accuracy of the complex model. While they are approximations, they are widely accepted for regulatory purposes when combined with documentation. This approach allows the firm to leverage the high accuracy of deep learning while meeting explainability requirements.

Why this answer

Post-hoc explanation techniques such as LIME and SHAP offer a practical compromise: they explain individual predictions of complex models without requiring the model to be inherently interpretable. This allows the firm to maintain high fraud detection accuracy while providing the transparency regulators demand. Replacing the model with a simpler one may reduce accuracy, and providing only overall metrics is insufficient.

Exam trap

The trap here is assuming that high accuracy and explainability are mutually exclusive, leading to an unnecessary trade-off.

36
Multi-Selectmedium

A hospital wants to deploy an AI triage model that recommends which emergency department patients should be seen first. The clinical governance committee is defining controls to ensure the system remains accountable and safe after go-live. Which TWO controls BEST support ongoing accountability for this AI system? (Choose two.)

Select 2 answers
A.Retrain the model on the entire production dataset every night to keep it current with the latest patient cases.
B.Require clinicians to accept every model recommendation without modification to keep the workflow consistent.
C.Establish a scheduled monitoring process that tracks model performance and subgroup error rates, with defined thresholds that trigger review.
D.Publish the model's full source code and training weights publicly so external researchers can verify its behavior.
E.Maintain an audit log of model inputs, outputs, and clinician overrides that can be reviewed after adverse events.
AnswersC, E

Post-deployment monitoring detects performance degradation and emerging disparities across patient subgroups, which are common as case mix and clinical practice change. Predefined thresholds convert passive observation into an actionable control that triggers investigation, retraining, or suspension. This keeps the system accountable over time rather than certifying it once at deployment and assuming continued safety.

Why this answer

Ongoing accountability depends on being able to reconstruct what happened and detect when behavior changes. Audit logging preserves the decision trail including clinician overrides, while scheduled performance and subgroup monitoring with defined thresholds turns observation into action. Together they create a feedback loop that supports incident investigation, fairness oversight, and timely intervention, which pure transparency or forced compliance cannot provide.

Exam trap

The trap here is equating transparency, such as publishing source code, with accountability, when accountability actually requires reconstructable decisions and active post-deployment monitoring.

37
MCQhard

A retail bank's fraud model was trained on customer transaction data that included account holders in the EU. An internal audit finds the training pipeline copied raw transaction records, including names and card numbers, into an unencrypted research bucket for model retraining. Which action best aligns the remediation with data-protection obligations for that pipeline?

A.Add the research bucket to the data-loss-prevention watchlist and require monthly access reviews.
B.Apply column-level encryption to the research bucket and continue retraining on the same raw records.
C.Delete the research bucket and retrain using pseudonymized or tokenized transaction records with documented retention limits.
D.Obtain a new consent notice from all account holders before the next retraining cycle.
AnswerC

The violation is storing identifiable personal data outside its lawful purpose and controls. Pseudonymizing or tokenizing before the data reaches the research environment, plus defined retention limits, reduces identifiability while preserving the statistical signal the fraud model needs. Deleting the exposed copy ends the ongoing exposure, and the documented retention schedule satisfies accountability and minimization expectations for the pipeline.

Why this answer

The finding combines excessive identifiability with a purpose and retention failure. Removing the exposed copy stops ongoing risk, while pseudonymization or tokenization plus documented retention limits lets the fraud model keep learning from transaction behavior without carrying direct identifiers into a research environment. Encryption, monitoring, and new consent each address part of the problem but leave the core data-minimization defect unresolved.

Exam trap

The trap here is treating encryption of the research bucket as a complete privacy fix, when the governing issue is that identifiable data was copied outside its original purpose and kept without a retention limit.

38
Multi-Selecteasy

Which TWO of the following are common techniques to improve the transparency and interpretability of an AI model?

Select 2 answers
A.Generate SHAP (SHapley Additive exPlanations) values
B.Use differential privacy to add noise to training data
C.Implement a random forest algorithm
D.Use deep neural networks to increase model complexity
E.Apply LIME (Local Interpretable Model-agnostic Explanations)
AnswersA, E

SHAP values quantify each feature's contribution to a prediction using Shapley values from cooperative game theory, producing consistent local and global explanations. This directly satisfies the stem's requirement for a technique improving transparency and interpretability of an AI model.

Why this answer

Option A is correct because SHAP (SHapley Additive exPlanations) values, grounded in cooperative game theory, assign each feature a quantitative contribution to a prediction, providing both global and local interpretability for any model. Option E is correct because LIME (Local Interpretable Model-agnostic Explanations) approximates a complex model's behavior around a single prediction with a simple, interpretable surrogate model, exposing which features drove that decision. Both techniques are model-agnostic post-hoc explanation methods specifically designed to make AI outputs transparent and interpretable.

Option B is not a transparency technique: differential privacy adds calibrated noise to protect individual records, trading accuracy for privacy rather than explaining model behavior. Option C is not inherently an interpretability technique; random forests are ensembles whose many trees are typically less transparent than a single decision tree. Option D is incorrect because increasing complexity with deep neural networks generally reduces interpretability rather than improving it.

Exam trap

The AI0-001 exam often tests the distinction between techniques that improve model transparency (like SHAP and LIME) versus techniques that enhance privacy (like differential privacy) or model performance (like random forests or deep neural networks), leading candidates to confuse privacy-preserving methods with interpretability methods.

39
MCQmedium

A healthcare startup deploys an AI model to predict patient readmission rates. An internal audit reveals that the model consistently underestimates readmission risk for non-native English speakers. According to AI ethics principles, what is the most appropriate course of action?

A.Add a confidence score disclaimer to model outputs
B.Reduce the sample size of non-native English speakers to balance the dataset
C.Continue using the model as is, since overall accuracy is acceptable
D.Retrain the model with a more representative dataset that includes diverse language backgrounds
AnswerD

Retraining with a representative dataset addresses the root cause: the model's bias stems from training data lacking diverse language backgrounds. This satisfies the fairness principle of equitable performance across groups, rather than merely masking the disparity through post-hoc adjustments.

Why this answer

It directly addresses the root cause of the bias: the training data lacks sufficient representation from non-native English speakers, leading to systematic underestimation of readmission risk for that group. Retraining with a more representative dataset aligns with the AI ethics principle of fairness by ensuring the model learns patterns across all demographic groups equally, rather than masking the issue with disclaimers or manipulating sample sizes.

Exam trap

The AI0-001 exam often tests the misconception that adding a disclaimer or adjusting sample sizes post-hoc is sufficient to address bias, when in fact the ethical requirement is to fix the data or model at the training stage to ensure fairness.

How to eliminate wrong answers

Option A is wrong because adding a confidence score disclaimer does not fix the underlying algorithmic bias; it merely informs users of potential inaccuracy without correcting the model's systematic error. Option B is wrong because reducing the sample size of non-native English speakers would exacerbate the bias by further underrepresenting that group, violating the ethical principle of fairness and likely increasing model variance. Option C is wrong because continuing to use a model with known demographic bias, even if overall accuracy is acceptable, violates the AI ethics principle of non-maleficence and could lead to harmful disparities in patient care.

40
MCQeasy

A security analyst is reviewing logs from an AI-powered recommendation system and notices an unusually high number of requests for products from a specific vendor. The analyst suspects data poisoning. Which mitigation strategy should be implemented first?

A.Encrypt all training data at rest
B.Deploy an anomaly detection system on model outputs
C.Retrain the model with a smaller, curated dataset
D.Implement input validation and sanitization for training data
AnswerD

Input validation and sanitisation filters malicious or anomalous training samples before they enter the pipeline, preventing poisoned vendor-biased data from skewing the recommendation model. This directly addresses the suspected poisoning at its ingestion point, satisfying the stem's requirement for the first mitigation strategy.

Why this answer

Input validation and sanitization directly prevent malicious or anomalous data from entering the training pipeline, which is the root cause of data poisoning. In an AI-powered recommendation system, poisoned training data can cause the model to learn biased associations, such as favoring a specific vendor. By validating and sanitizing inputs before they are used for training, the attack vector is blocked at the earliest stage, making it the most effective first mitigation step.

Exam trap

The AI0-001 exam often tests the principle of defense in depth by making candidates choose a reactive or recovery measure (like retraining or monitoring outputs) instead of the proactive control that stops the attack at the input stage.

How to eliminate wrong answers

Option A is wrong because encrypting training data at rest protects confidentiality and integrity during storage, but it does not prevent malicious data from being ingested into the training set; data poisoning occurs before encryption is applied. Option B is wrong because deploying an anomaly detection system on model outputs is a reactive measure that detects poisoning after the model has already been compromised, rather than preventing the attack. Option C is wrong because retraining with a smaller, curated dataset may reduce the impact of poisoning but does not address the underlying vulnerability that allowed poisoned data to enter the system; it is a recovery step, not a first-line mitigation.

41
MCQhard

A large hospital system deploys an AI triage system for emergency rooms. The system uses patient vitals and symptoms to recommend treatment priority. Six months after deployment, complaints arise that the system frequently underestimates the severity of symptoms for patients from certain ethnic backgrounds. A data scientist runs a bias audit and finds that the model's false negative rate is 20% higher for the minority group. The hospital's AI governance board requires immediate corrective action. The data science team has limited resources and cannot retrain the entire model from scratch. They have access to the training data, which is imbalanced. The model is a gradient boosted tree. Which course of action best addresses the bias while minimizing operational impact?

A.Rebalance the training data using SMOTE and retrain the model
B.Use adversarial debiasing during training to remove protected attribute correlations
C.Post-process the model's predictions by adjusting thresholds for the minority group
D.Replace the model with a simpler logistic regression model to improve interpretability
AnswerC

Threshold adjustment is a post-processing intervention applied at inference, so it corrects the disparate false negative rate without retraining the gradient boosted tree. This satisfies the constraint of limited resources and minimal operational impact, equalising error rates across groups while leaving the existing model intact.

Why this answer

Post-processing by adjusting decision thresholds for the minority group directly compensates for the higher false negative rate without requiring retraining. Since the team has limited resources and cannot retrain the entire gradient boosted tree model, this approach minimizes operational impact while addressing the bias. The threshold adjustment effectively lowers the probability cutoff for the minority group, making the model more sensitive to their symptoms and reducing underestimation of severity.

Exam trap

CompTIA often tests the misconception that bias mitigation always requires retraining or complex algorithmic changes, when in fact post-processing threshold adjustments can be a quick, effective fix for deployed models with limited resources.

How to eliminate wrong answers

Option A is wrong because SMOTE rebalances the training data by oversampling the minority class, but retraining the entire gradient boosted tree model from scratch is resource-intensive and contradicts the constraint of limited resources; moreover, SMOTE may introduce synthetic noise that degrades model performance. Option B is wrong because adversarial debiasing is a training-time technique that requires modifying the model architecture and retraining, which is not feasible given the limited resources and the fact that the model is already deployed; it also does not directly address the false negative rate disparity without full retraining. Option D is wrong because replacing the model with a simpler logistic regression model would require retraining and likely reduce predictive performance, especially for complex interactions in patient vitals and symptoms, and does not guarantee bias reduction; interpretability alone does not correct the existing bias.

42
MCQmedium

An AI model's performance drops significantly in production compared to testing. The data shows distribution shift. What is the best first step?

A.Add more features
B.Retrain model with new data
C.Use a different algorithm
D.Reduce model complexity
AnswerB

Retraining on recent data is the first practical step because distribution shift means the learned mapping no longer matches current input statistics; refreshing training data realigns the model with production. Monitoring alone would not restore performance, and the stem already identifies shift as the cause.

Why this answer

When distribution shift occurs, the model's assumptions about the data distribution no longer hold, so the best first step is to retrain the model with new data that reflects the current distribution. This directly addresses the root cause by updating the model to learn the new patterns, rather than applying superficial fixes like adding features or changing algorithms.

Exam trap

AI0-001 often tests the tendency to jump to algorithmic solutions (different algorithm, more features) when the root cause is data distribution, and the correct first step is usually data-centric.

How to eliminate wrong answers

Option A is wrong because adding more features does not address distribution shift and may introduce noise or overfitting. Option C is wrong because using a different algorithm does not fix the underlying data distribution mismatch and may perform worse without proper retraining. Option D is wrong because reducing model complexity may help with overfitting but does not resolve distribution shift, which requires adapting to new data.

43
MCQmedium

A healthcare analytics company has trained an AI model to predict patient readmission risk using a dataset that includes ZIP code, race, and historical healthcare costs. Before deployment, the compliance team runs a fairness audit and finds that the model's predictions correlate strongly with race even though race was not used as a direct input feature. Which of the following BEST describes this phenomenon?

A.Overfitting, because the model memorized race-related patterns in the training set instead of generalizing.
B.Label leakage, because the target variable inadvertently encodes race information.
C.Proxy discrimination, where a seemingly neutral feature acts as a substitute for a protected attribute.
D.Data drift, because patient demographics changed after the model was trained.
AnswerC

ZIP code and historical cost are correlated with race due to historical segregation and unequal access to care, so the model learns race-associated patterns indirectly. This is proxy discrimination: a protected attribute is not an explicit input, yet its influence enters through correlated features. Detecting it requires disparate impact testing and feature-correlation analysis, not just removing the protected column.

Why this answer

The model never receives race directly, but ZIP code and historical cost encode race-related disparities from decades of unequal healthcare access and residential segregation. This is proxy discrimination, and it defeats naive fairness approaches that only drop the protected column. Effective mitigation requires measuring disparate impact and auditing correlated features, because removing the explicit attribute does not remove its statistical footprint.

Exam trap

The trap here is assuming that removing the protected attribute from the feature set makes a model fair, when correlated proxy variables can preserve the same bias.

44
MCQhard

A research lab trains a language model using DP-SGD. What primary privacy risk does this technique mitigate?

A.Data poisoning attacks
B.Membership inference attacks
C.Adversarial patch attacks
D.Model inversion attacks
AnswerB

DP-SGD adds calibrated noise to per-example gradients during training, bounding any single record's influence on the model. This directly limits an adversary's ability to determine whether a specific individual's data was in the training set, satisfying the stem's requirement to mitigate membership inference attacks.

Why this answer

DP-SGD (Differentially Private Stochastic Gradient Descent) mitigates membership inference attacks by adding calibrated noise to gradients during training, which bounds the influence any single training example can have on the final model. This differential privacy guarantee makes it difficult for an adversary to determine whether a specific data point was included in the training set, directly addressing the core risk of membership inference.

Exam trap

The AI0-001 exam often tests the distinction between privacy risks (membership inference, model inversion) and security risks (poisoning, adversarial examples), and the trap here is that candidates confuse 'privacy risk' with 'security risk' and pick data poisoning or adversarial attacks instead of recognizing that DP-SGD is specifically designed for differential privacy against membership inference.

How to eliminate wrong answers

Option A is wrong because data poisoning attacks involve injecting malicious data to corrupt model behavior, which DP-SGD does not specifically prevent—it only limits per-example influence but does not detect or filter poisoned inputs. Option C is wrong because adversarial patch attacks target image classifiers by placing physical patches on objects to cause misclassification, which is a computer vision robustness issue unrelated to the privacy guarantees of DP-SGD. Option D is wrong because model inversion attacks aim to reconstruct training data features or attributes from the model, and while DP-SGD provides some defense, its primary and most direct mitigation is against membership inference, not full inversion which requires stronger assumptions and additional techniques.

45
MCQmedium

You are an AI governance officer at a bank that uses a machine learning model to predict credit risk. The model was developed by an external vendor and uses a proprietary algorithm. The bank's compliance team has determined that the model must be explainable to meet regulatory requirements. However, the vendor claims the model is a 'black box' and cannot provide explanations. You need to ensure compliance while maintaining the model's performance. What is the best course of action?

A.Ignore the requirement as the model is proprietary
B.Ask the vendor to develop a custom explanation module
C.Replace the model with a simpler, interpretable model
D.Use a model-agnostic explanation technique like SHAP
AnswerD

SHAP is model-agnostic: it treats the vendor's proprietary model as a black box, approximating each feature's contribution to individual predictions from input-output behaviour alone. This delivers the per-decision explanations regulators require without retraining or replacing the model, preserving its performance.

Why this answer

D is correct because model-agnostic explanation techniques like SHAP (SHapley Additive exPlanations) can provide post-hoc interpretability for any black-box model without requiring access to its internal structure or proprietary algorithm. This allows the bank to meet regulatory explainability requirements while preserving the vendor's proprietary model and its predictive performance.

Exam trap

The trap here is that candidates may assume that a 'black box' model cannot be explained at all, leading them to choose replacement with a simpler model (Option C), when in fact model-agnostic techniques like SHAP or LIME can provide explanations without altering the model itself.

How to eliminate wrong answers

Option A is wrong because ignoring regulatory requirements is not a viable option for a financial institution; it would lead to non-compliance and potential penalties. Option B is wrong because asking the vendor to develop a custom explanation module would require the vendor to modify their proprietary algorithm, which they have stated is a 'black box' and cannot provide explanations, making this request impractical and likely impossible. Option C is wrong because replacing the model with a simpler, interpretable model would sacrifice the predictive performance that the current model provides, which may be critical for accurate credit risk assessment.

46
MCQmedium

Which AI governance framework is specifically designed by the U.S. National Institute of Standards and Technology (NIST) to help organizations manage AI risks?

A.ISO/IEC 27001
B.COBIT
C.NIST AI Risk Management Framework
D.GDPR
AnswerC

The NIST AI Risk Management Framework provides voluntary guidance structured around govern, map, measure and manage functions, specifically for managing AI risks. It is the NIST-published framework, unlike ISO/IEC 42001 or the EU AI Act, which originate elsewhere.

Why this answer

The NIST AI Risk Management Framework (AI RMF) is the specific governance framework developed by the U.S. National Institute of Standards and Technology to help organizations manage AI risks, including those related to trustworthiness, fairness, and robustness. It provides a structured approach for identifying, assessing, and mitigating risks throughout the AI lifecycle, aligning with NIST's role in setting standards for cybersecurity and risk management.

Exam trap

The AI0-001 exam often tests candidates by listing well-known frameworks or regulations (like ISO/IEC 27001 or GDPR) that are related to security or privacy but are not AI-specific, leading candidates to confuse general governance with the NIST AI RMF.

How to eliminate wrong answers

Option A is wrong because ISO/IEC 27001 is an international standard for information security management systems (ISMS), not an AI-specific risk management framework, and it focuses on general data security rather than AI risks. Option B is wrong because COBIT (Control Objectives for Information and Related Technologies) is a framework for IT governance and management, developed by ISACA, and does not address AI-specific risks or the NIST AI RMF. Option D is wrong because GDPR (General Data Protection Regulation) is a European Union regulation for data privacy and protection, not a risk management framework, and it is not designed by NIST.

47
Multi-Selectmedium

Which TWO of the following are effective defenses against adversarial examples in AI systems?

Select 2 answers
A.Train the model with adversarial examples (adversarial training)
B.Use an ensemble of models and majority voting
C.Increase the model's sensitivity to input changes
D.Implement input sanitization and feature squeezing
E.Reduce model complexity through pruning
AnswersA, D

Adversarial training augments the training set with perturbed examples labelled correctly, forcing the model to learn robust decision boundaries. This directly reduces sensitivity to the small input perturbations that adversarial attacks exploit, hardening the classifier against them.

Why this answer

Adversarial training (option A) is a correct defense because it augments the training set with adversarial examples generated by attacks such as FGSM or PGD, so the model learns to classify perturbed inputs correctly and its decision boundary becomes more robust. Input sanitization and feature squeezing (option D) are also correct because they preprocess inputs to remove or reduce the adversarial perturbation — for example, by quantizing pixel values, spatial smoothing, or reducing color bit depth — which shrinks the attacker's effective search space and can neutralize small perturbations. Option B is not marked correct because model ensembles with majority voting can sometimes improve robustness but are not a reliable standalone defense; attackers can craft transferable or ensemble-aware adversarial examples that fool all members.

Option C is wrong because increasing sensitivity to input changes is the opposite of what is wanted — it makes the model easier to fool with tiny perturbations. Option E is wrong because pruning reduces model complexity for efficiency and may slightly alter robustness, but it is not an established defense against adversarial examples and can even degrade robustness.

Exam trap

The AI0-001 exam often tests the misconception that ensemble methods or model simplification inherently improve adversarial robustness, when in fact they do not address the fundamental mechanism of adversarial perturbations and may even weaken defenses.

48
MCQeasy

A retail company uses an AI system to detect shoplifting from surveillance footage. The system has been criticized for disproportionately flagging customers from certain ethnic groups. The company wants to address this ethical concern. Which of the following should be the first step?

A.Conduct a bias audit to quantify disparities across demographic groups.
B.Immediately disable the AI system and revert to manual monitoring.
C.Retrain the model with a more diverse dataset without analyzing the current bias.
D.Publish a public apology and promise to fix the issue.
AnswerA

A bias audit systematically measures the system's performance across different groups, identifying the extent and nature of the disparity. This evidence-based approach is the necessary first step before deciding on mitigation strategies. It aligns with ethical AI governance and helps prioritize corrective actions.

Why this answer

The first step in addressing bias is to measure it. A bias audit provides data on how the system performs across different groups, which is essential for understanding the problem and designing effective mitigation. Without this assessment, any corrective action is likely to be guesswork.

This approach is consistent with responsible AI practices.

Exam trap

The trap here is jumping to solutions like retraining or disabling the system without first quantifying the bias.

49
MCQhard

A company uses a machine learning model to recommend products to customers. The marketing team notices that the model is recommending high-profit items more frequently than low-profit items, even when customers are likely to prefer the latter. This behavior is causing customer dissatisfaction. Which approach would best align the model with customer preferences while maintaining profitability?

A.Train the model with a loss function that weights profit more heavily than customer satisfaction.
B.Use a multi-objective optimization framework to balance profit and customer satisfaction.
C.Adjust the model's hyperparameters to reduce the influence of profit features.
D.Remove profit data from the training set and only use customer preference data.
AnswerB

Multi-objective optimisation explicitly optimises two competing objectives simultaneously, so profit and customer satisfaction are traded off rather than profit dominating. This directly addresses the stem's constraint: high-profit recommendations overriding genuine customer preference, restoring alignment without abandoning profitability.

Why this answer

A multi-objective optimization framework explicitly allows the model to balance multiple goals, such as profit and customer satisfaction, by optimizing both objectives simultaneously. Option A is incorrect because weighting profit more heavily would exacerbate the issue and further ignore customer preferences. Option C is incorrect because adjusting hyperparameters to reduce profit feature influence is not a principled way to balance objectives and may not effectively improve satisfaction.

Option D is incorrect because removing profit data entirely ignores legitimate business goals, potentially harming profitability.

50
MCQeasy

An AI system in a self-driving car misinterprets a stop sign due to a small sticker placed on it. This is an example of which security vulnerability?

A.Supply chain attack
B.Model inversion attack
C.Adversarial example attack
D.Data poisoning attack
AnswerC

A small sticker deliberately alters pixel patterns the model relies on, causing misclassification while appearing benign to humans. This is a crafted input perturbation, the defining characteristic of an adversarial example attack, distinct from data poisoning or model inversion.

Why this answer

The sticker on the stop sign creates a small perturbation that causes the AI model's image classifier to misclassify the sign (e.g., as a speed limit sign). This is the defining characteristic of an adversarial example attack, where crafted input perturbations exploit model vulnerabilities to cause incorrect predictions.

Exam trap

The AI0-001 exam often tests the distinction between attacks that occur during training (data poisoning) versus attacks that occur during inference (adversarial examples), and candidates mistakenly choose data poisoning because they think the sticker 'poisons' the input, but the key is that the model's training data is unaffected.

How to eliminate wrong answers

Option A is wrong because a supply chain attack involves compromising hardware or software during the manufacturing or distribution process, not manipulating physical inputs after deployment. Option B is wrong because a model inversion attack aims to reconstruct private training data from model outputs, not to cause misclassification of inputs. Option D is wrong because data poisoning attacks corrupt the training dataset to influence the model's learned behavior, whereas the sticker is applied to a real-world input at inference time, not during training.

51
Multi-Selecteasy

Which TWO are common attack vectors against AI systems? (Choose two.)

Select 2 answers
A.SQL injection
B.Cross-site scripting
C.Buffer overflow
D.Data poisoning
E.Adversarial examples
AnswersD, E

Data poisoning corrupts the training corpus, causing the model to learn manipulated patterns or backdoors. It targets the learning pipeline itself rather than inference, which is why it is a distinct attack vector against AI systems alongside adversarial inputs and prompt injection.

Why this answer

Data poisoning (D) is a correct answer because it is a canonical AI-specific attack vector: adversaries corrupt or inject malicious samples into the training data so the model learns skewed decision boundaries, degrading accuracy or implanting backdoors that trigger on specific inputs. Adversarial examples (E) are also correct because they are deliberately perturbed inputs (often imperceptible changes, e.g., small Lp-norm perturbations) crafted to cause misclassification or evasion at inference time, exploiting the model's learned gradients. By contrast, SQL injection (A) targets database query construction in web applications, cross-site scripting (B) injects client-side script into web pages to attack users' browsers, and buffer overflow (C) exploits memory-safety flaws in native code — all are classic application/software vulnerabilities, not attack vectors specific to AI systems.

Exam trap

The AI0-001 exam often tests the distinction between traditional cybersecurity attacks (SQL injection, XSS, buffer overflow) and AI-specific threats (data poisoning, adversarial examples), so the trap is that candidates mistakenly apply general security knowledge to AI systems without recognizing the unique attack surfaces.

52
MCQmedium

A company deployed an AI chatbot that started generating offensive responses after a data update. The security team needs to quickly mitigate the issue. What should they do first?

A.Delete the training data
B.Disable the chatbot and investigate
C.Roll back to previous model version
D.Add a content filter
AnswerB

Disabling the chatbot immediately halts the offensive output, containing harm while the data update is investigated. This satisfies the stem's requirement to mitigate quickly, since leaving it live risks further reputational damage and user exposure before root cause is established.

Why this answer

The first priority when an AI chatbot generates offensive responses is to stop the harm immediately. Disabling the chatbot (Option B) halts all user interactions, preventing further offensive outputs while the security team investigates the root cause. This aligns with the principle of containment before remediation in incident response.

Exam trap

The AI0-001 exam often tests the principle that immediate containment (disabling the system) must precede any corrective action like rolling back or adding filters, because candidates mistakenly think a technical fix (rollback or filter) is faster than shutting down the service.

How to eliminate wrong answers

Option A is wrong because deleting the training data is a destructive action that may destroy forensic evidence needed to understand why the model misbehaved; it also does not stop the chatbot from generating offensive responses in the meantime. Option C is wrong because rolling back to a previous model version assumes the issue is in the model weights, but the offensive behavior could stem from the data update itself or a configuration change, and rolling back might reintroduce other vulnerabilities or not address the root cause. Option D is wrong because adding a content filter is a reactive, post-hoc mitigation that does not stop the ongoing generation of offensive responses; filters can be bypassed and do not address the underlying model or data corruption.

53
MCQmedium

A multinational corporation is developing an AI system that will be deployed in multiple countries with varying data protection laws. The legal team wants to ensure compliance with regulations such as the GDPR. Which of the following is the most appropriate action to take during the design phase?

A.Implement data minimization and purpose limitation principles from the outset.
B.Use only synthetic data for training to avoid any privacy concerns.
C.Obtain blanket consent from all users for any future use of their data.
D.Store all data in a central repository to simplify management and auditing.
AnswerA

Data minimization and purpose limitation are core GDPR principles that require collecting only necessary data and using it only for specified purposes. Integrating these principles during design ensures compliance by default and reduces legal risks. This proactive approach is more effective than retrofitting compliance later.

Why this answer

Incorporating data minimization and purpose limitation during the design phase aligns with GDPR's principle of data protection by design and by default. It ensures that the AI system only processes necessary data for specified purposes, reducing compliance risks. Other options either violate regulations or are insufficient.

This approach is a best practice for multinational deployments.

Exam trap

The trap here is thinking that blanket consent or synthetic data alone can solve all compliance issues, when GDPR requires specific and proactive measures.

54
MCQmedium

A healthcare AI system used for diagnosis shows a significant accuracy difference between demographic groups. Which technique should be applied to directly reduce this bias during model training?

A.Ignore the disparity as long as overall accuracy is acceptable
B.Retrain the model with more data from the underperforming group
C.Apply adversarial debiasing during training
D.Remove demographic attributes from the training data
AnswerC

Adversarial debiasing trains a predictor alongside an adversary that tries to infer the protected attribute from its outputs, forcing representations that cannot distinguish demographic groups. This directly reduces the accuracy gap during training, satisfying the stem's requirement to cut bias between groups.

Why this answer

Adversarial debiasing directly reduces bias during model training by introducing an adversarial network that attempts to predict the protected attribute (e.g., demographic group) from the model's predictions. The primary model is trained to maximize accuracy while simultaneously minimizing the adversary's ability to infer the protected attribute, thereby forcing the model to learn representations that are invariant to that attribute. This technique directly addresses the accuracy disparity by encoding fairness as an optimization objective, unlike post-hoc or data-level approaches.

Exam trap

The AI0-001 exam often tests the misconception that 'fairness through unawareness' (removing demographic attributes) is sufficient to eliminate bias, but the trap here is that proxy variables and correlated features can still cause disparate impact, making adversarial debiasing a more robust in-processing technique.

How to eliminate wrong answers

Option A is wrong because ignoring the disparity violates ethical AI principles and regulatory requirements (e.g., HIPAA, FDA guidelines for clinical AI), and overall accuracy can mask significant subgroup performance drops that lead to misdiagnosis. Option B is wrong because simply adding more data from the underperforming group does not guarantee removal of spurious correlations or biased representations; it may even amplify existing biases if the data contains systematic label noise or confounding variables. Option D is wrong because removing demographic attributes (often called 'fairness through unawareness') is ineffective, as proxy variables (e.g., ZIP code, socioeconomic indicators) can still encode the protected attribute, and the model may learn biased correlations from remaining features.

55
MCQeasy

An organization wants to ensure its AI systems comply with new regulations requiring explanations for automated decisions. Which governance practice is most directly relevant?

A.Implementing differential privacy
B.Deploying explainability tools
C.Conducting bias audits
D.Establishing an AI ethics board
AnswerB

Explainability tools generate the feature attributions and decision rationales that regulators require for automated decisions, directly satisfying the explanation mandate. Governance practice must therefore operationalise interpretability so each decision can be justified to auditors and affected individuals.

Why this answer

Deploying explainability tools (B) is the most directly relevant governance practice because the regulation specifically requires explanations for automated decisions. Explainability tools, such as LIME or SHAP, generate human-interpretable justifications for model outputs, enabling compliance with transparency mandates. This directly addresses the need to understand and communicate why a particular decision was made, unlike other practices that focus on privacy, fairness, or oversight.

Exam trap

The AI0-001 exam often tests the distinction between governance practices that are about oversight (ethics board) or data protection (differential privacy) versus those that directly implement a specific technical requirement (explainability), leading candidates to choose a broader or unrelated option.

How to eliminate wrong answers

Option A is wrong because differential privacy is a technique for protecting individual data points by adding noise to queries or training data, not for generating explanations for decisions; it addresses privacy compliance, not explainability. Option C is wrong because bias audits detect and measure unfairness or discrimination in model outcomes, but they do not provide per-decision explanations required by the regulation; they focus on fairness, not transparency. Option D is wrong because establishing an AI ethics board provides high-level governance and policy oversight, but it does not directly implement the technical capability to produce explanations for individual automated decisions, which is the core regulatory requirement.

56
Multi-Selecthard

A logistics company is preparing an AI governance program for a route-optimization model that influences driver schedules. The compliance team must demonstrate accountability to regulators. Which two practices best establish documented accountability for this system? (Choose two.)

Select 2 answers
A.Increase the model's inference throughput by deploying additional GPU nodes in each region.
B.Maintain a model card and system inventory entry recording intended use, training data provenance, and known limitations.
C.Publish the model's hyperparameters and training loss curves on the company's public website.
D.Restrict model access to the data science team and rotate their credentials every thirty days.
E.Assign a named accountable owner and require periodic risk reviews with recorded decisions and sign-offs.
AnswersB, E

A model card with an inventory entry creates the authoritative record regulators expect: what the system is for, what data shaped it, and where it is known to be weak. It also links the deployed model to its owner and version. That documentation is the backbone of an accountability claim because it shows the organization understood and disclosed the system's scope and constraints.

Why this answer

Accountability is demonstrated through artifacts that show who owns the system and how its risks were assessed over time. A model card and inventory entry document intended use, data provenance, and limitations, while a named owner with recurring recorded risk reviews and sign-offs proves that governance was actively exercised. Throughput scaling, publishing engineering metrics, and access hardening address performance, disclosure, and security rather than accountability.

Exam trap

The trap here is equating security hardening or engineering transparency with accountability, when regulators expect documented ownership and a recorded history of risk decisions.

57
MCQhard

An organization uses an AI-based hiring tool. To prevent bias, they want to ensure the model's decisions are explainable. Which approach is most suitable?

A.Use reinforcement learning with fairness constraints
B.Use a simpler interpretable model like logistic regression
C.Use a black-box deep learning model with SHAP explanations
D.Use ensemble methods with feature importance
AnswerB

Logistic regression produces inherently interpretable coefficients, so each hiring decision can be traced to specific feature weights — directly satisfying the explainability requirement. Unlike black-box models needing post-hoc tools such as SHAP or LIME, its reasoning is transparent by design, making bias auditing straightforward.

Why this answer

A simpler interpretable model like logistic regression provides inherent transparency—its coefficients directly show the weight and direction of each input feature on the hiring decision. This makes it easy for auditors and stakeholders to verify that the model is not using protected attributes (e.g., race, gender) in a biased way, without needing post-hoc explanation tools. The key is that the model itself is interpretable by design, not just explained after the fact.

Exam trap

The AI0-001 exam often tests the distinction between a model that is inherently interpretable (like logistic regression) versus a model that is explained post-hoc (like SHAP on a deep network), where the trap is that candidates assume any explanation method makes a black-box model 'explainable' in the same way.

How to eliminate wrong answers

Option A is wrong because reinforcement learning with fairness constraints focuses on optimizing a reward signal over time, which is not designed for static, explainable decision-making in hiring; it also introduces complexity that undermines the goal of straightforward explainability. Option C is wrong because using a black-box deep learning model with SHAP explanations still relies on post-hoc approximations that can be inaccurate or misleading, and SHAP values do not guarantee that the model's internal logic is free from bias—they only approximate feature contributions. Option D is wrong because ensemble methods with feature importance (e.g., random forest) provide only global importance scores that can be unstable and do not offer per-decision transparency; they also fail to reveal how features interact in a specific hiring outcome.

58
Multi-Selectmedium

Which THREE of the following are key principles of AI ethics as defined by major frameworks?

Select 3 answers
A.Transparency
B.Scalability
C.Accountability
D.Latency
E.Fairness
AnswersA, C, E

Transparency requires that AI systems' capabilities, limitations, and decision processes be openly disclosed to stakeholders. Major frameworks including the OECD AI Principles and UNESCO recommendations list it as a core ethical principle, enabling informed use and accountability.

Why this answer

Transparency (A) is a core AI-ethics principle because major frameworks require that AI systems' capabilities, limitations, data use, and decision logic be disclosed and explainable to affected stakeholders. Accountability (C) is likewise fundamental, as frameworks such as the OECD AI Principles and UNESCO Recommendation demand that responsibility for AI outcomes be clearly assigned to identifiable humans or organizations, with mechanisms for redress. Fairness (E) is a third key principle, requiring that AI systems avoid unjust bias and discrimination and treat individuals and groups equitably across the lifecycle.

By contrast, scalability (B) is an engineering and performance concern about handling growing workloads, and latency (D) is a technical metric of response delay; neither is an ethical principle in AI frameworks.

Exam trap

The AI0-001 exam often tests candidates by mixing technical performance metrics (scalability, latency) with ethical principles, expecting you to recognize that only value-based concepts like transparency, accountability, and fairness belong to AI ethics frameworks.

59
MCQeasy

Which practice best ensures AI systems comply with regulations like GDPR?

A.Using open-source models only
B.Regular vulnerability scans
C.Data minimization and anonymization
D.Hiring more data scientists
AnswerC

Data minimisation limits processing to what the stated purpose requires, while anonymisation removes personal identifiers, so GDPR principles of purpose limitation, storage limitation and data protection by design are satisfied directly rather than through contractual or procedural controls.

Why this answer

Data minimization and anonymization directly align with GDPR's core principles, such as Article 5(1)(c) which mandates that personal data be 'adequate, relevant and limited to what is necessary.' By collecting only essential data and applying techniques like k-anonymity or differential privacy, AI systems reduce the risk of re-identification and ensure compliance with data protection by design and by default (Article 25). This practice is a foundational governance measure, not a reactive or staffing solution.

Exam trap

The AI0-001 exam often tests the misconception that security practices (like vulnerability scans) are sufficient for privacy compliance, but GDPR specifically requires proactive data governance measures like minimization and anonymization, not just reactive security controls.

How to eliminate wrong answers

Option A is wrong because using open-source models only does not inherently ensure GDPR compliance; open-source models can still process excessive personal data or lack proper anonymization, and licensing terms do not substitute for regulatory adherence. Option B is wrong because regular vulnerability scans address security vulnerabilities (e.g., CVE patching) but do not enforce data minimization, purpose limitation, or anonymization required by GDPR; they are a security practice, not a privacy governance practice. Option D is wrong because hiring more data scientists does not guarantee compliance; without implementing specific technical controls like anonymization or data minimization, additional personnel cannot mitigate systemic privacy risks or meet GDPR's accountability requirements.

60
MCQeasy

An AI team is developing a model that will make hiring recommendations. Which ethical principle requires that candidates be informed about how their data is used and have a way to challenge decisions?

A.Fidelity.
B.Non-maleficence.
C.Beneficence.
D.Transparency and contestability.
AnswerD

Transparency requires informing candidates about data use, and contestability gives them a way to challenge automated decisions. Together they form a core ethical principle for high-stakes AI like hiring. This principle ensures individuals are not subject to opaque, unchallengeable decisions, aligning with fairness and due process expectations.

Why this answer

Transparency and contestability directly require that candidates be informed about data use and have a way to challenge decisions. Beneficence, non-maleficence, and fidelity are ethical principles but do not specifically mandate disclosure and challenge mechanisms in automated hiring.

Exam trap

The trap here is selecting a broad ethical principle like non-maleficence when the scenario specifically describes disclosure and challenge rights.

61
MCQhard

A social media company uses an AI content moderation system to filter hate speech. The system uses a natural language processing model trained on user reports. Recently, the model's false positive rate has increased, blocking legitimate posts. An internal audit reveals that a coordinated group of users has been falsely reporting harmless posts, causing the model to learn incorrect patterns. The company needs to address the attack and restore accuracy. The engineering team can modify the training pipeline. What is the most effective first step?

A.Redesign the training pipeline to incorporate a reputation system for reporting users
B.Increase the weight of non-reported posts to counteract the reported posts' influence
C.Apply adversarial training to make the model robust to crafted inputs
D.Retrain the model on a dataset that excludes all user-reported posts
AnswerA

A reputation system weights each reporter's contribution by trustworthiness, so coordinated false reports from low-reputation accounts carry little training influence. This directly neutralises the poisoning attack described in the stem, restoring accuracy without discarding legitimate user reports.

Why this answer

The root cause is a coordinated attack where malicious users exploit the reporting mechanism to poison the training data. Incorporating a reputation system into the training pipeline allows the model to weigh or filter user reports based on the trustworthiness of the reporting user, directly mitigating the impact of false reports without discarding legitimate feedback. This addresses the adversarial behavior at the source, restoring accuracy by ensuring the model learns from reliable signals.

Exam trap

CompTIA often tests the distinction between defending against data poisoning (attacks on the training data) versus evasion or adversarial examples (attacks on the model at inference), and the trap here is that candidates confuse adversarial training (Option C) as a catch-all defense, when it specifically addresses input perturbations, not poisoned labels.

How to eliminate wrong answers

Option B is wrong because simply increasing the weight of non-reported posts does not prevent the model from learning the incorrect patterns from the poisoned reports; the false reports still influence the training loss, and the imbalance may not correct the learned bias. Option C is wrong because adversarial training is designed to make models robust to crafted input perturbations (e.g., small changes to text), not to attacks on the training data via poisoned labels or reports; it does not address the data poisoning vector. Option D is wrong because excluding all user-reported posts removes a valuable source of ground truth for content moderation, discarding legitimate reports along with the malicious ones, which would reduce the model's ability to detect actual hate speech and likely degrade overall performance.

62
Multi-Selecteasy

Which TWO of the following are common threats to AI model security?

Select 2 answers
A.SQL injection
B.Data poisoning
C.Adversarial examples
D.Distributed denial-of-service (DDoS)
E.Phishing attacks
AnswersB, C

Data poisoning corrupts the training set itself, so the model learns manipulated patterns and returns attacker-chosen outputs at inference. It targets the integrity of the learning pipeline rather than the deployed model, making it a recognised threat to AI model security.

Why this answer

Data poisoning (B) is a core AI-specific threat in which an attacker corrupts the training dataset so the model learns incorrect or malicious behavior, degrading accuracy or implanting backdoors. Adversarial examples (C) are also a fundamental AI model threat, where inputs are deliberately perturbed with small, often imperceptible changes that cause the model to misclassify or produce attacker-chosen outputs. By contrast, SQL injection (A) targets database-driven applications through malicious query strings, not the model itself, and DDoS (D) is an availability attack that floods network or service resources rather than manipulating model behavior.

Phishing (E) is a social-engineering attack against users' credentials or trust, not a direct threat to AI model integrity or inference.

Exam trap

The AI0-001 exam often tests the distinction between traditional IT security threats (like SQL injection or DDoS) and AI-specific threats (like data poisoning and adversarial examples), so candidates may incorrectly select familiar network or application attacks instead of recognizing the unique AI attack vectors.

63
MCQeasy

A cybersecurity analyst monitors an AI chatbot that frequently produces offensive responses when given specific prompts. The development team suspects an adversarial attack. Which mitigation strategy is most effective against such prompt injection attacks?

A.Retrain the model on a larger, curated dataset
B.Encrypt all communication between users and the chatbot
C.Reduce the model's number of parameters
D.Implement input validation and sanitization
AnswerD

Input validation and sanitisation filter or neutralise malicious prompt content before it reaches the model, directly blocking injected instructions that trigger offensive outputs. This addresses the root cause at the input boundary rather than attempting post-hoc output filtering, satisfying the requirement to mitigate prompt injection.

Why this answer

Prompt injection attacks exploit the model's inability to distinguish between user input and system instructions. Input validation and sanitization (e.g., filtering special characters, enforcing strict schema checks, and using allowlists) directly neutralize malicious payloads before they reach the model's inference engine, preventing the model from executing unintended commands.

Exam trap

The AI0-001 exam often tests the misconception that retraining or model size adjustments can fix security vulnerabilities, when in fact the issue lies in input handling and trust boundaries, not the model's training data or architecture.

How to eliminate wrong answers

Option A is wrong because retraining on a larger dataset does not address the root cause of prompt injection; the model will still be vulnerable to crafted inputs that bypass its instruction-following boundaries. Option B is wrong because encryption protects data in transit but does not inspect or filter the content of prompts, so it cannot prevent injection attacks. Option C is wrong because reducing the number of parameters degrades model performance and does not mitigate injection; the attack exploits input handling, not model capacity.

64
MCQhard

A financial services firm deploys an AI system to screen loan applications. The model was trained on historical data that reflected biased lending practices. After deployment, a regulatory body investigates and finds that the model denies loans at a disproportionately higher rate to a protected demographic group. The firm must address this issue while maintaining compliance with fair lending laws. The Chief AI Officer proposes four possible actions. Which action is the most appropriate first step?

A.Retrain the model using a debiased dataset and implement fairness-aware algorithms, then validate with fairness metrics
B.Document the model's predictions and submit a report to the regulator explaining the historical dataset bias
C.Immediately deploy a rule-based system to manually review all denial decisions from the AI system
D.Disclose the bias findings to all rejected applicants and offer them priority reconsideration
AnswerA

Retraining with a debiased dataset and fairness-aware algorithms directly removes the historical lending bias embedded in the training data, then fairness metrics validate that denial rates no longer disproportionately harm the protected group, satisfying fair lending compliance before further deployment.

Why this answer

The most appropriate first step is to remediate the model itself by retraining on a debiased dataset, applying fairness-aware algorithms, and validating with fairness metrics. This addresses the root cause — biased historical training data — rather than only documenting or disclosing the problem. It also aligns with fair lending laws that require the model's outcomes to be non-discriminatory, not merely reported.

Exam trap

AI0-001 often tests whether candidates choose root-cause remediation over documentation or disclosure, so the trap is picking a reporting or manual-review option that sounds responsible but does not fix the bias.

How to eliminate wrong answers

Option B is wrong because documenting and reporting the bias does not fix the discriminatory outcomes and leaves the firm exposed to ongoing regulatory violation. Option C is wrong because replacing the AI with manual review is a drastic operational change that does not address the underlying model bias and may not scale. Option D is wrong because disclosing bias to rejected applicants and offering reconsideration is a reactive remediation that does not correct the model or prevent future discriminatory denials.

65
MCQmedium

An AI system used for resume screening is found to consistently rank male candidates higher than female candidates with similar qualifications. The HR director wants to remediate this bias without significantly reducing model accuracy. Which technique should be applied?

A.Apply adversarial debiasing to the model during training.
B.Use a random selection of candidates to avoid bias.
C.Remove the gender feature from the dataset and retrain.
D.Collect more training data from underrepresented groups.
AnswerA

Adversarial debiasing trains a classifier to predict the protected attribute while the main model learns to prevent it, removing gender-correlated signals from the representation. This reduces disparate ranking while preserving predictive performance, meeting the HR director's accuracy constraint.

Why this answer

Adversarial debiasing is the correct technique because it directly addresses bias during training by introducing an adversarial network that attempts to predict the protected attribute (e.g., gender) from the model's predictions. The main model is trained to maximize accuracy while minimizing the adversary's ability to infer the protected attribute, thereby reducing bias without a significant drop in predictive performance. This approach is more effective than simple feature removal or data collection because it actively learns to remove correlations between the protected attribute and the output.

Exam trap

CompTIA often tests the misconception that simply removing the protected attribute (e.g., gender) from the dataset is sufficient to eliminate bias, but candidates must understand that bias can persist through correlated features (proxy discrimination).

How to eliminate wrong answers

Option B is wrong because random selection of candidates would destroy the model's predictive accuracy entirely, as it ignores all qualifications and job-relevant features, which is not a valid remediation technique. Option C is wrong because simply removing the gender feature does not eliminate bias; the model can still learn gender proxies from correlated features such as years of experience, education, or job titles, leading to indirect discrimination. Option D is wrong because collecting more data from underrepresented groups may improve representation but does not guarantee removal of existing bias in the model's decision boundary; it can even introduce new imbalances if not handled carefully, and it does not actively debias the training process.

66
MCQeasy

A startup develops an AI recruiting tool that screens resumes. After deployment, they receive a complaint from a candidate who claims the system rejected them due to age discrimination. The startup has no formal AI governance process. They want to quickly assess and remediate the issue. The dataset includes age as a feature. What should they do first?

A.Conduct a bias analysis to measure the model's impact on different age groups
B.Apologize to the candidate and offer a manual review of their resume
C.Immediately remove age from the feature set and retrain the model
D.Ignore the complaint because age is a legitimate business requirement
AnswerA

Measuring outcomes across age groups establishes whether the model actually disadvantages older candidates before any remediation. Since age is a training feature, this analysis identifies the specific disparity and informs whether to remove the feature, reweight samples, or retrain.

Why this answer

The first step in addressing a potential bias issue is to conduct a bias analysis to measure the model's impact on different age groups. This allows the startup to quantify the extent of any discriminatory behavior before taking remediation steps, ensuring that actions are data-driven and targeted. Without this analysis, any subsequent fix (like removing age) might be premature or ineffective, and could even introduce new biases.

Exam trap

CompTIA often tests the misconception that removing a protected attribute (like age) is sufficient to eliminate bias, when in fact proxy features can perpetuate discrimination, making a bias analysis the necessary first step.

How to eliminate wrong answers

Option B is wrong because apologizing and offering a manual review is a reactive customer service response that does not address the root cause of the bias in the model; it fails to assess or remediate the systemic issue. Option C is wrong because immediately removing age from the feature set and retraining the model is a hasty action that could mask the problem without understanding whether age is a proxy for other correlated features (e.g., years of experience), potentially leading to unintended discrimination or model degradation. Option D is wrong because ignoring the complaint outright violates ethical AI principles and regulatory requirements (such as EEOC guidelines), and age is not a legitimate business requirement for resume screening unless it is a bona fide occupational qualification, which is rarely the case.

67
MCQhard

During a penetration test, a security engineer discovers that an AI-powered chatbot can be tricked into revealing sensitive customer data by using specially crafted prompts. What type of attack is this, and what is the best mitigation?

A.Prompt injection attack; implement input validation and context sanitization
B.Model inversion attack; apply differential privacy during training
C.Data poisoning attack; implement strict access controls
D.Membership inference attack; add noise to model outputs
AnswerA

Crafted prompts that override instructions and leak sensitive data constitute prompt injection. Because the model cannot distinguish trusted instructions from untrusted user content, mitigation requires validating and sanitising inputs, and isolating context, before the prompt reaches the model.

Why this answer

This is a prompt injection attack, where an attacker crafts inputs that cause the AI model to override its original instructions or constraints, leading to unintended behavior such as revealing sensitive data. The best mitigation is input validation and context sanitization, which filters or neutralizes malicious prompt content before it reaches the model, preventing the injection from succeeding.

Exam trap

The AI0-001 exam often tests the distinction between attacks that occur during training (e.g., data poisoning, model inversion) versus those that occur during inference (e.g., prompt injection), leading candidates to confuse the attack phase and choose a wrong mitigation.

How to eliminate wrong answers

Option B is wrong because a model inversion attack reconstructs training data from model outputs, not by manipulating prompts, and its mitigation (differential privacy) does not address prompt-level manipulation. Option C is wrong because data poisoning involves corrupting the training data to influence model behavior, not exploiting the model at inference time via prompts, and strict access controls are a general security measure, not a direct mitigation for prompt injection. Option D is wrong because a membership inference attack determines if a specific record was used in training, not by tricking the model with prompts, and adding noise to outputs is a privacy technique, not a defense against prompt injection.

68
MCQhard

A global bank deploys a generative AI assistant that summarizes internal policy documents for loan officers across the European Union and the United States. The compliance team must ensure the system respects regional AI regulations. Which of the following actions is MOST appropriate for aligning the deployment with these requirements?

A.Classify the assistant's risk level per jurisdiction, document the conformity assessment, and maintain human oversight and logging for its outputs.
B.Restrict the assistant to English-language documents only, because language localization is the primary regulatory differentiator across regions.
C.Rely on the foundation model provider's terms of service and published model card as sufficient evidence of regulatory compliance.
D.Disable all output logging to minimize the personal data stored, since data minimization is the only regulatory requirement that applies.
AnswerA

Generative assistants used in credit-related workflows can fall into higher-risk categories under the EU AI Act and are subject to sector rules such as fair lending in the US. A defensible approach maps each jurisdiction's requirements, performs and documents a conformity or impact assessment, and keeps human review plus audit logs. This addresses transparency, accountability, and oversight obligations simultaneously.

Why this answer

Cross-border AI deployments must be governed per jurisdiction rather than by a single global policy. A risk classification, documented assessment, and operational controls such as human oversight and logging create an auditable compliance posture. Vendor documentation alone cannot substitute for deployer obligations, and neither data minimization nor language restriction addresses the core regulatory duties for a credit-adjacent generative tool.

Exam trap

The trap here is treating a foundation model provider's documentation as sufficient compliance evidence instead of recognizing the deployer's own assessment and oversight obligations.

69
MCQmedium

A data scientist trains a sentiment analysis model on user reviews. To ensure transparency, they want to explain why the model classified a particular review as negative. Which explainability technique should they use?

A.Decision tree surrogate model
B.Principal component analysis
C.SHAP (SHapley Additive exPlanations)
D.t-SNE dimensionality reduction
AnswerC

SHAP assigns each input feature a Shapley value quantifying its contribution to a specific prediction, producing local, per-instance explanations. For a single review classified negative, this pinpoints which words drove the outcome, satisfying the transparency requirement better than global or inherently interpretable alternatives.

Why this answer

SHAP (SHapley Additive exPlanations) provides per-feature attribution for individual predictions, making it suitable for explaining why a particular review was classified as negative. Option A is incorrect because a decision tree surrogate model is a global explanation method, not a local explanation for a single instance. Option B is incorrect because PCA is a dimensionality reduction technique, not an explainability method.

Option D is incorrect because t-SNE is used for high-dimensional data visualization, not for explaining model predictions.

70
MCQeasy

A media company uses a generative AI service to draft marketing copy. Legal asks the AI governance team to reduce the risk that outputs reproduce copyrighted passages from the training corpus. Which control most directly addresses that specific risk?

A.Log every prompt and response for ninety days and store the logs in the governance archive.
B.Require all marketing staff to complete annual training on the organization's acceptable-use policy.
C.Enable content-provenance metadata and output filtering that flags or blocks near-verbatim matches to known copyrighted text.
D.Lower the model's temperature setting so generated text is more deterministic.
AnswerC

Near-verbatim reproduction is the concrete harm legal is worried about, and provenance metadata plus similarity filtering targets it at generation time. The filter compares candidate output against reference corpora and blocks or flags long matching spans, while provenance metadata records how the content was produced. Together they give the governance team an enforceable, auditable control tied to the identified risk.

Why this answer

The risk is that generated marketing copy could contain near-verbatim copyrighted material. A control that inspects output for long matches against reference corpora and blocks or flags them, paired with provenance metadata, directly reduces that exposure and leaves an audit trail. Training, temperature tuning, and logging influence behavior or records but do not detect or stop a reproducing output before publication.

Exam trap

The trap here is assuming that lowering model temperature or adding awareness training prevents memorized text from being reproduced, when neither examines the generated output for infringement.

71
Multi-Selectmedium

Which THREE of the following are key principles of trustworthy AI as defined by major regulatory bodies?

Select 3 answers
A.Fairness and non-discrimination
B.Transparency and explainability
C.Maximum profitability
D.Proprietary secrecy
E.Accountability
AnswersA, B, E

Fairness and non-discrimination require AI systems to avoid unjustified disparate treatment or outcomes across protected groups. Regulatory frameworks including the EU AI Act and OECD principles treat this as a core trustworthy AI requirement, satisfying the stem's demand for key principles.

Why this answer

Fairness and non-discrimination (A) is a core principle because trustworthy AI frameworks such as the EU AI Act and OECD AI Principles require systems to avoid biased outcomes and unjust discrimination across protected groups. Transparency and explainability (B) is also correct, as these bodies mandate that AI decisions be understandable and that stakeholders can access meaningful information about how systems operate. Accountability (E) is correct because trustworthy AI requires clear responsibility and redress mechanisms, ensuring that developers and deployers can be held answerable for system outcomes.

Maximum profitability (C) is not a trustworthiness principle; it is a business objective and is not part of regulatory AI ethics definitions. Proprietary secrecy (D) is also not a principle, since trustworthiness frameworks emphasize disclosure, auditability, and transparency rather than concealment.

Exam trap

The AI0-001 exam often tests the distinction between ethical principles and business goals, so candidates mistakenly select 'maximum profitability' or 'proprietary secrecy' because they confuse corporate interests with regulatory requirements for trustworthy AI.

72
MCQhard

An organization implements AI governance following the NIST AI Risk Management Framework. They need to ensure that all model decisions are logged with sufficient detail for later audit. Which logging requirement is most critical for traceability?

A.Input data and model name only
B.Source code and training dataset hash
C.Model outputs and confidence scores only
D.Timestamp, input data, output, and model version
AnswerD

Traceability requires reconstructing each decision, so logs must capture the timestamp, the exact input data, the produced output, and the model version that generated it. Without the model version, an auditor cannot attribute behaviour to a specific deployed artefact.

Why this answer

Timestamp, input data, output, and model version together provide full traceability for audit. Option A is wrong because logging only input data and model name misses outputs, timestamp, and version, which are essential for traceability. Option B is wrong because source code and training dataset hash are not part of the inference audit trail; they are more relevant to model development.

Option C is wrong because logging only model outputs and confidence scores misses inputs and model version, making it impossible to fully trace decisions.

73
MCQmedium

A company implements an AI-based chatbot for customer service. After deployment, customers report that the chatbot sometimes uses offensive language. The development team reviews the training data and finds no explicit offensive content. What is the most likely explanation?

A.There is a bug in the deployment pipeline
B.The model is overfitting to rare examples
C.The model learned biased language patterns from the training corpus
D.The training data was poisoned by an attacker
AnswerC

Offensive output can emerge without explicit slurs in the corpus, because the model learns statistical associations and tone patterns from biased language present in the training data. Deployment then surfaces these learned patterns as offensive responses.

Why this answer

The chatbot's offensive language likely stems from biased or toxic patterns present in the training corpus, even if no explicit offensive content was flagged. Large language models learn statistical associations from their training data, and if the corpus contains subtle biases, stereotypes, or indirect toxic language, the model can reproduce these patterns in its responses. This is a well-known issue in AI ethics and governance, where models inadvertently amplify societal biases embedded in the data.

Exam trap

The AI0-001 exam often tests the distinction between explicit data contamination (poisoning) and implicit bias learned from benign-looking data, so the trap here is assuming that the absence of explicit offensive content in the training data means the model cannot produce offensive output.

How to eliminate wrong answers

Option A is wrong because a deployment pipeline bug would typically cause functional failures (e.g., model not loading, incorrect API calls) or output errors, not the generation of offensive language that is contextually coherent. Option B is wrong because overfitting to rare examples would cause the model to memorize specific training instances, leading to exact or near-exact reproductions of those rare inputs, not the generation of novel offensive language that was not present in the training data. Option D is wrong because data poisoning requires an attacker to deliberately inject malicious samples into the training set, which would likely leave traces of explicit offensive content; the scenario states no explicit offensive content was found, making this less likely than the model learning implicit biases from the existing corpus.

74
MCQmedium

A hospital's AI triage model was trained on five years of historical admissions. A governance review finds that patients over 75 are systematically assigned lower acuity scores than clinically equivalent younger patients, even though age is not an input feature. Which governance control most directly addresses this finding?

A.Run a proxy-variable and disparate-impact analysis on the model's outputs before each deployment.
B.Deploy the model in shadow mode and compare its predictions against clinician judgment for one week.
C.Increase the volume of historical training data by adding ten more years of admissions records.
D.Encrypt the training dataset at rest and restrict access to the model registry.
AnswerA

Age is excluded as a direct input, so the disparity must enter through a correlated proxy such as prior utilization, comorbidity coding, or referral source. Testing outputs for disparate impact across age cohorts exposes that indirect pathway and produces evidence the governance board can act on. It targets the observed harm directly rather than treating symptoms such as logging or encryption.

Why this answer

The disparity appears despite age being excluded, which is the classic signature of a proxy variable carrying protected-class information into the model. Testing outcomes for disparate impact across age cohorts, and tracing which features correlate with age, is the control that both detects and documents the harm. Data volume, cryptography, and shadow comparison each address different concerns and leave the indirect bias unmeasured.

Exam trap

The trap here is assuming that removing a protected attribute such as age from the feature set automatically removes bias, when correlated proxy features keep reproducing the disparity.

75
Multi-Selecteasy

Which TWO of the following are essential components of a responsible AI governance framework?

Select 2 answers
A.Assignment of a responsible owner for each AI system's outcomes
B.Using ensemble methods to reduce overfitting
C.Clear documentation of model development and decision-making processes
D.Automated hyperparameter tuning to improve accuracy
E.Deploying models on dedicated hardware to reduce latency
AnswersA, C

Accountability is a fundamental governance requirement.

Why this answer

Assigning a responsible owner for each AI system's outcomes ensures accountability, which is a core principle of AI governance. This owner is typically a designated individual or team that oversees the system's lifecycle, including monitoring for bias, compliance with regulations, and handling incidents. Without clear ownership, there is no single point of contact for ethical or legal issues, making governance ineffective.

Exam trap

CompTIA often tests the distinction between technical implementation details (like ensemble methods or hyperparameter tuning) and governance framework components, so candidates mistakenly select options that improve model performance rather than those ensuring accountability and transparency.

Page 1 of 2 · 82 questions totalNext →

Ready to test yourself?

Try a timed practice session using only AI Security, Ethics and Governance questions.