Courseiva

CCNA AI Security, Ethics and Governance Questions

7 of 82 questions · Page 2/2 · AI Security, Ethics and Governance · Answers revealed

76
MCQmedium

A healthcare organization uses an AI model to predict patient readmission risk. To comply with patient privacy regulations, they apply differential privacy during training. What is the primary trade-off of using differential privacy?

A.Increased training time for reduced bias
B.Lower interpretability for higher fairness
C.Faster inference for lower memory usage
D.Reduced model accuracy for increased privacy
AnswerD

Differential privacy injects calibrated noise into training data or gradients, mathematically bounding any individual's influence on the model. This privacy guarantee inherently perturbs learned parameters, degrading predictive performance. The trade-off is therefore measurable accuracy loss, which the healthcare scenario accepts to satisfy patient privacy regulations.

Why this answer

Differential privacy works by adding calibrated noise to the training process or model outputs, which directly reduces the model's accuracy in exchange for a quantifiable privacy guarantee (e.g., ε-differential privacy). This trade-off is fundamental: stronger privacy (lower ε) requires more noise, which degrades predictive performance. The healthcare organization must balance the need to protect patient data against the clinical utility of accurate readmission predictions.

Exam trap

The AI0-001 exam often tests the misconception that differential privacy primarily reduces bias or improves fairness, when in fact its core trade-off is accuracy for privacy, and fairness can be negatively impacted by the added noise.

How to eliminate wrong answers

Option A is wrong because differential privacy does not primarily target bias reduction; it addresses privacy, and increased training time is a secondary implementation cost, not the primary trade-off. Option B is wrong because differential privacy does not inherently lower interpretability or increase fairness; it may even reduce fairness if noise disproportionately affects minority subgroups, and interpretability is a separate concern. Option C is wrong because differential privacy does not improve inference speed or reduce memory usage; it typically adds computational overhead during training and does not affect inference latency or memory footprint.

77
MCQhard

A national security agency uses AI to analyze surveillance data for threat detection. The system is deployed in a high-stakes environment where false negatives could lead to missed threats, and false positives waste analyst time. Recently, a known hacker group attempted to evade detection by subtly modifying their communication patterns over time, a form of adversarial evasion. The agency wants to harden the system while maintaining performance. The system uses a deep neural network. Which mitigation strategy is most appropriate?

A.Switch to an unsupervised learning approach to detect anomalies
B.Simplify the model to a logistic regression to reduce the attack surface
C.Perform adversarial training using the hacker group's known evasion patterns
D.Add random noise to all input data to confuse evasion attempts
AnswerC

Adversarial training augments the training set with the group's known evasion patterns, so the deep neural network learns decision boundaries robust to those subtle modifications. This directly counters the observed evasion while retaining detection performance on legitimate traffic.

Why this answer

Adversarial training is the most appropriate mitigation because it directly incorporates known evasion patterns into the training process, making the deep neural network robust to the hacker group's subtle modifications. By retraining the model on adversarial examples, the decision boundary is hardened against these specific attacks without sacrificing overall detection performance. This approach is a standard defense in high-stakes security AI, balancing false positive and false negative rates while countering adversarial evasion.

Exam trap

CompTIA often tests the misconception that simplifying a model (e.g., to logistic regression) reduces attack surface, but in adversarial evasion, simpler models are actually more vulnerable because they lack the capacity to learn robust decision boundaries against crafted perturbations.

How to eliminate wrong answers

Option A is wrong because switching to unsupervised anomaly detection does not inherently defend against adversarial evasion; it may still be fooled by subtly modified patterns and often increases false positives due to lack of labeled threat data. Option B is wrong because simplifying to logistic regression reduces model capacity, making it less able to learn complex threat patterns and more susceptible to evasion, not less. Option D is wrong because adding random noise to input data degrades signal quality, increasing both false positives and false negatives, and does not target the specific evasion patterns used by the hacker group.

78
MCQhard

During a red-team exercise on an AI model, testers successfully extracted training data. Which vulnerability is this?

A.Membership inference
B.Model inversion
C.Adversarial example
D.Data poisoning
AnswerB

Model inversion reconstructs training-set samples by querying the model's outputs, directly satisfying the stem's constraint of extracted training data. Unlike membership inference, which only determines whether a record was used, inversion recovers actual feature values, making it the precise vulnerability demonstrated during this red-team exercise.

Why this answer

Model inversion attacks allow an adversary to reconstruct training data by exploiting the model's learned representations. In this scenario, the testers successfully extracted training data, which is the hallmark of a model inversion attack, not just inferring membership.

Exam trap

The AI0-001 exam often tests the distinction between 'extracting data' (model inversion) and 'inferring presence' (membership inference), so candidates mistakenly choose membership inference when the question explicitly states data was extracted.

How to eliminate wrong answers

Option A is wrong because membership inference only determines whether a specific data point was part of the training set, not extract the actual data. Option C is wrong because adversarial examples involve crafting inputs to cause misclassification, not extracting training data. Option D is wrong because data poisoning involves corrupting the training data to manipulate model behavior, not extracting existing training data.

79
Multi-Selecteasy

Which TWO of the following are best practices for securing an AI model against adversarial attacks?

Select 2 answers
A.Model pruning to reduce the number of parameters.
B.Adversarial training with perturbed examples.
C.Input sanitization and validation.
D.Increasing model complexity to capture more patterns.
E.Hyperparameter optimization using grid search.
AnswersB, C

Adversarial training with perturbed examples hardens the model by exposing it to manipulated inputs during fitting, so it learns decision boundaries robust to small, deliberate perturbations. This directly satisfies the stem's requirement for a best practise against adversarial attacks, reducing misclassification of crafted inputs at inference time.

Why this answer

Option B is correct because adversarial training explicitly augments the training set with perturbed inputs (e.g., FGSM or PGD examples) labeled with their true classes, which hardens the model's decision boundaries against small, intentionally crafted perturbations. Option C is correct because input sanitization and validation filter or normalize anomalous inputs (e.g., clipping pixel ranges, rejecting out-of-distribution values, or detecting unusual feature patterns) before inference, reducing the attack surface for adversarial examples. Option A is not a security best practice for adversarial robustness; pruning reduces parameters for efficiency and can even increase vulnerability by removing redundant features that aid generalization.

Option D is wrong because increasing model complexity typically enlarges the attack surface and can worsen overfitting to non-robust features, making adversarial examples easier to find. Option E is irrelevant to adversarial security, as grid search only tunes hyperparameters for performance metrics like accuracy, not robustness against crafted perturbations.

Exam trap

CompTIA often tests the misconception that increasing model complexity or pruning improves security, when in fact these techniques address performance or efficiency, not adversarial robustness.

80
MCQhard

An organization wants to implement an AI ethics board. Which composition best ensures independence and expertise?

A.All members from the legal department
B.IT department head and data scientists
C.Mix of internal stakeholders and external ethicists
D.Only senior executives from the company
AnswerC

Blending internal stakeholders with external ethicists satisfies the independence constraint: external members lack reporting lines to the organisation, so they can challenge internal priorities without career risk, while internal stakeholders supply operational context. This dual composition delivers both the detached scrutiny and domain expertise an ethics board requires.

Why this answer

An AI ethics board must combine internal stakeholders (who understand organizational context, data flows, and operational constraints) with external ethicists (who provide independent, unbiased perspectives and specialized knowledge of ethical frameworks like IEEE Ethically Aligned Design or the EU AI Act). This composition ensures the board can evaluate AI systems for bias, fairness, and transparency without being dominated by business or technical interests, which is critical for maintaining trust and regulatory compliance.

Exam trap

The AI0-001 exam often tests the misconception that technical expertise alone (Option B) is sufficient for AI ethics governance, but the trap is that independence and multidisciplinary perspectives are explicitly required to avoid conflicts of interest and ensure comprehensive ethical evaluation.

How to eliminate wrong answers

Option A is wrong because a board composed solely of legal department members lacks the technical expertise to assess AI model behavior, data provenance, and algorithmic bias, and may focus narrowly on legal compliance rather than broader ethical principles. Option B is wrong because IT department heads and data scientists bring deep technical knowledge but have inherent conflicts of interest (e.g., pressure to deploy models quickly) and lack the independent ethical oversight needed to challenge internal decisions. Option D is wrong because senior executives prioritize business outcomes and shareholder value, which can compromise impartiality and lead to ethics being subordinated to profit, violating the independence required for effective governance.

81
MCQmedium

A city agency deploys an AI system that scores permit applications. The vendor refuses to disclose model weights or feature importance, citing trade secrets. The agency's oversight board must still meet its obligation to explain adverse decisions to applicants. Which approach best satisfies that obligation?

A.Require the vendor to supply model-agnostic explanations, such as local surrogate or counterfactual reason codes, for each adverse decision.
B.Inform applicants that the decision was made by an automated system and provide a generic appeal link.
C.Replace the vendor model with a transparent rule-based scoring system that the agency builds in-house.
D.Publish the vendor's source code and trained weights so independent researchers can audit the decisions.
AnswerA

Model-agnostic techniques generate explanations from input-output behavior without exposing proprietary weights, so the agency can give applicants concrete reasons while the vendor keeps its intellectual property. Local surrogates and counterfactual reason codes translate a decision into interpretable factors. This satisfies the oversight duty and preserves the commercial relationship, which is exactly the constraint the scenario describes.

Why this answer

The agency must explain adverse decisions without forcing the vendor to reveal proprietary internals. Model-agnostic explainability, including local surrogates and counterfactual reason codes, derives per-decision explanations from observable behavior, so applicants receive meaningful factors and the board meets its duty. Full disclosure, generic notices, and replacing the system each either breach the constraint or fail to provide decision-specific reasoning.

Exam trap

The trap here is believing that meaningful explanation requires access to model weights, when model-agnostic techniques can produce per-decision reasons without disclosing proprietary internals.

82
Multi-Selecthard

A company is deploying an AI-based resume screening tool. The security team is concerned about adversarial attacks that could manipulate the tool's rankings. Which TWO of the following are effective defenses against such attacks? (Choose two.)

Select 2 answers
A.Input sanitization to remove special characters
B.Model extraction prevention via API rate limiting
C.Differential privacy during training
D.Certified robustness via randomized smoothing
E.Adversarial training with perturbed resumes
AnswersD, E

Randomized smoothing is a certified defense that provides provable robustness guarantees against small input perturbations. For resume screening, it could ensure that minor changes to a resume do not drastically alter the ranking. This technique is effective against adversarial attacks and adds a layer of security.

Why this answer

Adversarial training and certified robustness via randomized smoothing are both proactive defenses that make the model more resistant to crafted inputs. Adversarial training exposes the model to perturbed examples during training, while randomized smoothing provides a formal guarantee against small perturbations. These methods directly counter evasion attacks that could manipulate resume rankings.

Exam trap

The trap here is confusing privacy-preserving techniques like differential privacy with defenses against adversarial manipulation.

← PreviousPage 2 of 2 · 82 questions total

Ready to test yourself?

Try a timed practice session using only AI Security, Ethics and Governance questions.