Courseiva

CCNA AI Governance and Ethics Questions

75 of 81 questions · Page 1/2 · AI Governance and Ethics · Answers revealed

1
MCQmedium

An AI risk manager is applying the NIST AI Risk Management Framework (AI RMF). In which function would the organization establish a risk management process and assign roles and responsibilities for AI oversight?

A.Map
B.Manage
C.Govern
D.Measure
AnswerC

The Govern function establishes the policies, processes, roles and responsibilities for AI risk management across the organisation. Assigning oversight accountability and defining the risk process therefore sits in Govern, which satisfies the stem's requirement before Map, Measure and Manage activities occur.

Why this answer

The Govern function in the NIST AI RMF is specifically designed to establish organizational structures, policies, and accountability mechanisms for AI risk management. This includes defining roles and responsibilities, setting risk management processes, and ensuring oversight across the AI lifecycle. The other functions (Map, Measure, Manage) focus on different aspects such as understanding context, assessing risks, and treating risks, respectively.

Exam trap

A common trap is to assume that the 'Manage' function covers all risk management activities including establishing processes and roles, because its name implies broad oversight. However, in the NIST AI RMF, 'Govern' is the specific function for setting up risk management processes and accountability structures, while 'Manage' is reserved for risk treatment after assessment.

How to eliminate wrong answers

Option A is wrong because the Map function focuses on understanding the AI system's context, including its intended use, stakeholders, and potential impacts, not on establishing governance structures or assigning roles. Option B is wrong because the Manage function deals with prioritizing, responding to, and treating identified risks after they have been assessed, not with setting up the initial risk management process or assigning oversight roles. Option D is wrong because the Measure function involves quantitative and qualitative assessment of AI risks, including metrics and monitoring, but does not cover the establishment of governance processes or role assignment.

2
MCQmedium

A company is training a large language model and wants to reduce its carbon footprint. Which practice is MOST effective for reducing training energy consumption while maintaining model quality?

A.Increase the batch size to the maximum the GPU memory allows
B.Use a larger model architecture to achieve higher accuracy faster
C.Use mixed-precision training and prune unnecessary parameters
D.Train the model on CPUs instead of GPUs
AnswerC

Mixed-precision training halves memory and compute per operation, while pruning removes redundant parameters, cutting training energy and carbon emissions directly. Both techniques preserve model quality, satisfying the requirement to reduce energy consumption without degrading accuracy.

Why this answer

Mixed-precision training (e.g., FP16/BF16 with FP32 master weights) reduces memory bandwidth and compute cost per operation, while pruning removes redundant parameters, lowering FLOPs and energy per training step. Together they cut energy consumption substantially without materially degrading model quality when done carefully. This is the most effective listed practice for reducing training energy while preserving quality.

Exam trap

AI0-001 often tests the misconception that bigger batch sizes or larger models automatically improve efficiency; candidates must recognize that precision reduction and pruning directly lower energy per useful training step.

How to eliminate wrong answers

Option A is wrong because simply maximizing batch size can improve hardware utilization but does not inherently reduce total energy per unit of model quality and may require more epochs or cause convergence issues. Option B is wrong because larger models increase compute and energy consumption, directly worsening the carbon footprint. Option D is wrong because CPUs are far less energy-efficient than GPUs for the parallel matrix operations in LLM training, so training on CPUs would dramatically increase energy use and time.

3
MCQmedium

A healthcare AI startup is developing a model to predict patient readmission risk. The company wants to ensure the model's decisions can be understood by clinicians. Which explainability technique provides local, model-agnostic explanations by fitting a simple surrogate model around a prediction?

A.SHAP values
B.LIME
C.Attention visualisation
D.Model cards
AnswerB

LIME fits a sparse linear surrogate around each individual prediction, so clinicians receive a local, model-agnostic explanation of which features drove that specific readmission risk score, satisfying the interpretability requirement without exposing the underlying model's internals.

Why this answer

LIME (Local Interpretable Model-agnostic Explanations) is the correct technique because it generates local explanations by fitting a simple, interpretable surrogate model (e.g., linear regression or decision tree) around a specific prediction. It is model-agnostic, meaning it works with any black-box classifier, and it perturbs the input data near the instance of interest to understand which features most influenced the prediction.

Exam trap

Candidates may confuse SHAP with LIME because both provide local, model-agnostic explanations, but LIME fits a surrogate model (e.g., linear regression) around the prediction, whereas SHAP uses Shapley values from game theory.

How to eliminate wrong answers

Option A is wrong because SHAP values provide both local and global explanations based on cooperative game theory (Shapley values), but they are not a surrogate model; they compute additive feature importance scores directly from the model's output. Option C is wrong because attention visualization is a technique specific to neural network architectures (e.g., transformers) and is not model-agnostic; it relies on internal attention weights, which are not available for arbitrary models. Option D is wrong because model cards are documentation artifacts that describe a model's intended use, performance, and limitations; they do not generate local explanations for individual predictions.

4
Multi-Selectmedium

A company wants to adopt green AI practices to reduce the environmental impact of training large models. Which TWO actions are most effective?

Select 2 answers
A.Use efficient model architectures (e.g., pruning, quantization)
B.Use larger datasets to improve accuracy
C.Train models only on weekends
D.Train models in the cloud to offload energy costs
E.Use energy-efficient hardware (e.g., TPUs or optimized GPUs)
AnswersA, E

Pruning and quantization shrink parameter counts and numeric precision, cutting the compute and energy consumed during training and inference. This directly satisfies the stem's goal of reducing environmental impact, since training cost scales with model size and floating-point operations.

Why this answer

Using efficient model architectures (A) and energy-efficient hardware (E) directly reduce energy consumption. Using larger datasets (B) increases energy use. Training models on weekends (C) does not affect total energy consumption.

Training models in the cloud (D) may offload energy costs to the provider but does not reduce total energy used.

5
MCQeasy

A company is considering using an open-source large language model for a commercial application. Which intellectual property consideration is MOST important when deciding between open-source and proprietary models?

A.The model's license terms and any restrictions on commercial use
B.The model's accuracy on benchmark tasks
C.The size of the model's parameter count
D.The model's training data provenance
AnswerA

Open-source licences vary widely: some permit unrestricted commercial deployment, while others impose copyleft, attribution, or usage caps that could block a commercial product. Reviewing the specific licence terms is therefore the decisive intellectual property check when weighing open-source against proprietary models.

Why this answer

The license terms of an open-source model dictate whether and how it can be used commercially, modified, or redistributed. Some licenses (e.g., Apache 2.0, MIT) are permissive, while others (e.g., GPL, AGPL, or custom licenses like Llama 2's) impose restrictions such as copyleft, attribution, or limits on commercial use. For a commercial application, failing to comply with these terms can lead to legal liability, making license review the most critical IP consideration.

Exam trap

AI0-001 often tests the distinction between technical performance metrics and legal/IP considerations, causing candidates to overlook license terms in favor of accuracy or model size.

How to eliminate wrong answers

Option B is wrong because accuracy on benchmarks is a performance metric, not an intellectual property concern; it does not address legal rights to use the model. Option C is wrong because parameter count is a technical specification indicating model size and capacity, not a legal or IP restriction. Option D is wrong because while training data provenance can raise IP issues (e.g., copyright infringement), it is a secondary consideration; the model's license explicitly governs the terms of use and is the primary IP factor for commercial adoption.

6
MCQhard

A financial institution is deploying an AI system to approve personal loans. To comply with the EU AI Act's high-risk AI requirements, the bank must ensure meaningful human oversight. Which implementation BEST satisfies this requirement?

A.Require a human to review and approve every loan decision before it becomes final
B.Use a separate AI model to audit the primary AI's decisions weekly
C.Allow applicants to appeal AI decisions through a customer service process
D.Provide a dashboard showing the AI's confidence score for each application
AnswerA

Requiring a human to review and approve every loan decision before it becomes final ensures meaningful human oversight, satisfying the EU AI Act's high-risk requirement. Human-in-the-loop approval prevents fully automated decisions, unlike post-hoc monitoring or logging alone.

Why this answer

The EU AI Act's high-risk requirements (Article 14) mandate that humans can effectively oversee AI systems, including the ability to intervene, override, or halt decisions. Requiring a human to review and approve every loan decision before it becomes final embeds a genuine human-in-the-loop control at the decision point, which is the strongest form of meaningful oversight for a high-risk credit-scoring use case. This ensures no automated output becomes binding without human judgment, directly satisfying the oversight obligation.

Exam trap

AI0-001 often tests the misconception that any human touchpoint (appeals, dashboards, audits) counts as 'meaningful human oversight' when the Act specifically requires the ability to intervene in or override the decision before it takes effect.

How to eliminate wrong answers

Option B is wrong because using a second AI model to audit decisions is still automated oversight with no human in the loop, and weekly review is retrospective rather than preventive. Option C is wrong because an appeal process is a post-hoc redress mechanism, not meaningful human oversight of the AI system itself, and the decision has already been enforced. Option D is wrong because displaying a confidence score merely informs a human without granting them authority or a mechanism to intervene, override, or stop the decision.

7
Multi-Selectmedium

A financial institution wants to use AI for loan approvals and must comply with fair lending laws. Which TWO practices should the institution adopt to mitigate bias and ensure compliance?

Select 2 answers
A.Remove all features except credit score to avoid bias
B.Use a black-box model without explainability to protect intellectual property
C.Use only demographic features to ensure equal treatment
D.Apply fairness-aware machine learning techniques during model training
E.Conduct disparate impact analysis on model outcomes
AnswersD, E

Fairness-aware training constrains the model's objective function to reduce disparate impact across protected groups, directly addressing the fair lending requirement. By penalising biased outcomes during fitting rather than only auditing afterwards, it satisfies the stem's compliance constraint at the point where bias enters the model.

Why this answer

Option D is correct because fairness-aware machine learning techniques (e.g., pre-processing, in-processing, or post-processing bias mitigation methods such as reweighting, adversarial debiasing, or equalized odds) directly address bias during model training, which is essential for fair lending compliance. Option E is correct because disparate impact analysis quantifies whether model outcomes disproportionately disadvantage protected groups, a key requirement under fair lending laws like the Equal Credit Opportunity Act (ECOA) and Fair Housing Act. Option A is incorrect because removing all features except credit score does not eliminate bias—credit scores themselves can reflect historical discrimination—and it may violate fair lending rules by ignoring relevant factors.

Option B is incorrect because black-box models without explainability hinder regulatory audits and adverse action explanations required by laws such as ECOA and the Fair Credit Reporting Act (FCRA). Option C is incorrect because using only demographic features would be both discriminatory and nonsensical for loan approval decisions.

Exam trap

AI0-001 often tests the misconception that removing sensitive features ('fairness through unawareness') eliminates bias, when proxy variables and historical bias in remaining features preserve discrimination.

8
Multi-Selecthard

A retail company is deploying an AI system that generates personalized marketing copy and product recommendations. The legal team wants to align the deployment with the NIST AI Risk Management Framework's core functions. Which two activities are part of the MAP function? (Choose two.)

Select 2 answers
A.Establishing organizational policies that assign accountability for AI risk decisions across product, legal, and engineering teams.
B.Applying technical controls such as output filters and rate limits to reduce the chance of harmful generated copy reaching customers.
C.Continuously tracking key performance indicators and drift metrics after the recommendation engine enters production.
D.Categorizing the likelihood and potential impact of risks such as manipulated recommendations or exposure of inferred preferences.
E.Documenting the specific business context, affected stakeholders, and intended purpose of the recommendation engine.
AnswersD, E

MAP includes identifying and characterizing risks, including estimating likelihood and impact, so that later functions can prioritize them. Categorizing risks for the recommendation engine, such as manipulated outputs or inference of sensitive preferences, is a mapping activity. It precedes measurement and management, and it determines which risks warrant deeper analysis or controls, making it a correct MAP responsibility.

Why this answer

The MAP function establishes context and characterizes risks. Documenting business context and stakeholders, and categorizing likelihood and impact of identified risks, are core mapping activities. Applying controls belongs to MANAGE, continuous post-deployment tracking belongs to MEASURE, and assigning accountability across the organization belongs to GOVERN, which underpins all other functions.

Exam trap

The trap here is treating the NIST AI RMF functions as sequential project phases, when GOVERN is cross-cutting and MEASURE and MANAGE activities can occur alongside mapping.

9
MCQmedium

A company using an AI-based hiring tool receives a candidate request for explanation of an automated rejection. Which GDPR principle is most directly relevant?

A.Right to erasure
B.Right to data portability
C.Right to access
D.Right to explanation
AnswerD

Automated rejection decisions fall under GDPR Article 22, which grants data subjects the right to meaningful information about the logic involved and to contest the outcome. The right to explanation directly satisfies the candidate's request for the reasoning behind the hiring tool's decision.

Why this answer

GDPR Article 22 grants individuals the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects, and Recital 71 explicitly references the right to obtain an explanation of such decisions. A hiring rejection is a significant decision, so the candidate's request for explanation maps directly to the right to explanation (often framed as part of Article 22 safeguards).

Exam trap

AI0-001 often tests the confusion between the right to access (Article 15) and the right to explanation (Article 22/Recital 71), leading candidates to pick 'right to access' when the question specifically asks about explaining an automated decision.

How to eliminate wrong answers

Option A is wrong because the right to erasure (Article 17) concerns deleting personal data, not obtaining an explanation of an automated decision. Option B is wrong because data portability (Article 20) concerns receiving and transmitting personal data in a machine-readable format, unrelated to decision explanations. Option C is wrong because the right to access (Article 15) lets individuals obtain a copy of their data and certain information, but the specific request for an explanation of automated decision logic is captured by Article 22/Recital 71, not Article 15 alone.

10
MCQmedium

A company is evaluating fairness metrics for a hiring model. They want to ensure that the model has similar true positive rates (TPR) across demographic groups. Which fairness metric should they use?

A.Calibration
B.Individual fairness
C.Demographic parity
D.Equalized odds
AnswerD

Equalized odds requires equal true positive rates and false positive rates across demographic groups, so it directly matches the stated TPR parity goal. Demographic parity or equal opportunity would not capture both error rates simultaneously.

Why this answer

Equalized odds requires that both true positive rates (TPR) and false positive rates (FPR) are equal across demographic groups, which directly matches the requirement for similar TPR across groups. It is the standard fairness metric when the goal is parity in error rates rather than parity in outcomes.

Exam trap

AI0-001 often tests the confusion between demographic parity (equal selection rates) and equalized odds (equal error rates) — candidates pick demographic parity because it sounds like 'fairness,' but the question specifies TPR, which is equalized odds.

How to eliminate wrong answers

Option A (Calibration) is wrong because calibration ensures predicted probabilities match observed frequencies within each group — it does not constrain TPR or FPR equality. Option B (Individual fairness) is wrong because it requires similar predictions for similar individuals, a similarity-based notion that says nothing about group-level TPR. Option C (Demographic parity) is wrong because it requires equal selection rates across groups regardless of actual qualifications, which is a different (and often incompatible) criterion from equalized odds.

11
MCQmedium

A hospital wants to train a diagnostic model using data from multiple hospitals without sharing raw patient data. Which technique allows model training across decentralised data while preserving privacy?

A.Differential privacy applied to the combined dataset
B.Centralising all data in one location and anonymising it
C.Federated learning
D.Using pseudonymisation and then pooling the data
AnswerC

Federated learning trains a shared model across decentralised sites by exchanging model updates rather than raw records, so each hospital's patient data stays local. This satisfies the privacy constraint while still producing a diagnostic model from multi-hospital data.

Why this answer

Federated learning trains a shared model across decentralized data sources by sending model updates (gradients or weights) rather than raw data to a central server, which aggregates them into a global model. This allows multiple hospitals to collaborate on a diagnostic model without ever sharing patient records.

Exam trap

AI0-001 often tests the misconception that anonymization or pseudonymisation satisfies 'no data sharing' — candidates pick those options, but only federated learning keeps raw data on-premises.

How to eliminate wrong answers

Option A is wrong because differential privacy applied to a combined dataset still requires centralizing the data, which violates the no-raw-data-sharing constraint. Option B is wrong because centralizing and anonymizing data still moves raw records to one location, which the hospitals explicitly want to avoid. Option D is wrong because pseudonymisation replaces identifiers but still pools the underlying records centrally, so raw patient data leaves each hospital.

12
Multi-Selecthard

A company is forming an AI ethics board to oversee the development of a high-stakes AI system for bail decision recommendations. Which THREE responsibilities should the board primarily undertake?

Select 3 answers
A.Review model outputs for disparate impact across demographic groups
B.Market the AI system to potential clients
C.Establish human-in-the-loop requirements for high-risk decisions
D.Define fairness criteria and acceptable bias thresholds
E.Write the production code for the AI model
AnswersA, C, D

Reviewing outputs for disparate impact directly addresses the fairness constraint inherent in bail recommendations, where historical arrest data can encode racial bias. The board examines error rates and outcome distributions across demographic groups, catching discriminatory patterns that accuracy metrics alone conceal. This satisfies the stem's high-stakes oversight requirement by providing ongoing, evidence-based scrutiny of deployed model behaviour.

Why this answer

Option A is correct because an AI ethics board overseeing a bail recommendation system must audit model outputs for disparate impact across demographic groups, since bail decisions are legally and ethically sensitive and bias can violate anti-discrimination requirements. Option C is correct because the board should establish human-in-the-loop requirements for high-risk decisions, ensuring that consequential bail recommendations are reviewed by a qualified human rather than fully automated. Option D is correct because the board must define fairness criteria and acceptable bias thresholds, giving the organization measurable standards for evaluating whether the system's outputs are equitable.

Option B is not a primary ethics-board responsibility because marketing the system to clients is a commercial function, not ethical oversight. Option E is not appropriate because writing production code is an engineering task, and the board should provide governance, review, and policy direction rather than implementation work.

Exam trap

AI0-001 often tests the boundary between governance and engineering — candidates pick 'write production code' or 'market the system' because they sound like responsibilities, but ethics boards set policy and review outcomes, not build or sell.

13
MCQmedium

A media company wants to use an AI system to generate synthetic voiceovers for news summaries. Before launch, the ethics board asks the team to address the risk that listeners may mistake synthetic audio for authentic recordings. Which control BEST mitigates this specific risk?

A.Restricting voice cloning to a single consented voice actor whose contract permits synthetic replication.
B.Publishing an annual transparency report describing how synthetic audio is used across the newsroom.
C.Watermarking the generated audio with an imperceptible signal that can be detected by verification tools.
D.A clear, persistent disclosure that the voiceover is AI-generated, presented alongside the audio.
AnswerD

The risk is that listeners mistake synthetic audio for authentic recordings. A prominent, persistent disclosure directly addresses that misconception at the point of consumption. Unlike hidden technical markers, it operates on the audience's understanding and reduces the chance of deception. It is therefore the control that most directly mitigates the specific perceptual risk the ethics board identified.

Why this answer

When the risk is audience deception about whether audio is synthetic, the most direct control is a clear and persistent disclosure at the point of consumption. Hidden watermarks, consent-based voice licensing, and periodic transparency reports address provenance, rights, and accountability respectively, but none of them prevents an ordinary listener from mistaking generated speech for an authentic recording.

Exam trap

The trap here is choosing a technical provenance marker such as a watermark when the stated risk is human misperception, which requires a perceptible disclosure.

14
MCQeasy

An AI ethics board is reviewing a model that recommends criminal sentencing lengths. They want to ensure that the model's false positive rates for different demographic groups are equal. Which fairness metric should they use?

A.Calibration
B.Individual fairness
C.Equalized odds
D.Demographic parity
AnswerC

Equalized odds requires true positive and false positive rates to match across demographic groups, directly satisfying the board's constraint of equal false positive rates. Unlike demographic parity, which only equalises positive prediction rates, it conditions on the actual outcome, making it the precise metric for sentencing recommendations where unequal errors cause harm.

Why this answer

Equalized odds requires that the model's true positive rates and false positive rates are equal across groups. Demographic parity only requires equal selection rates. Individual fairness ensures similar individuals are treated similarly but does not define group rates.

Calibration ensures predicted probabilities match actual outcomes for each group but does not enforce equal error rates.

15
MCQhard

A data scientist is evaluating a binary classifier for a hiring tool. They compute demographic parity and find that the selection rate for Group A is 0.2 and for Group B is 0.4. Which action would MOST directly address this disparity?

A.Use a different evaluation metric such as equalized odds
B.Remove the sensitive attribute from the training data
C.Collect more data for Group A to increase its representation
D.Retrain the model with a fairness constraint that enforces demographic parity
AnswerD

The 0.2 versus 0.4 selection rates show a demographic parity gap. Retraining with an explicit fairness constraint optimises the model to equalise selection rates across groups, directly targeting the measured disparity rather than adjusting thresholds post hoc.

Why this answer

Demographic parity requires that the selection rate be equal across groups. Since Group A has 0.2 and Group B has 0.4, the model violates demographic parity. Retraining with a fairness constraint that enforces demographic parity directly optimizes for this metric, making it the most direct action to address the disparity.

Exam trap

AI0-001 often tests the confusion between different fairness metrics; candidates may think that removing the sensitive attribute or collecting more data automatically fixes disparity, but only a constraint targeting the specific metric directly addresses it.

How to eliminate wrong answers

Option A is wrong because switching to equalized odds changes the fairness definition but does not directly fix the demographic parity disparity; it addresses a different metric (equal true positive and false positive rates). Option B is wrong because removing the sensitive attribute does not guarantee fairness, as proxy variables can still encode group membership, and it may not reduce the disparity. Option C is wrong because collecting more data for Group A might improve representation but does not ensure the model's selection rates become equal; it could even exacerbate the disparity if the underlying bias persists.

16
MCQeasy

Which NIST AI RMF function involves identifying the context, risks, and potential impacts of an AI system, including mapping the AI lifecycle and stakeholders?

A.Manage
B.Measure
C.Map
D.Govern
AnswerC

Map is the NIST AI RMF function that establishes context by identifying risks, impacts, stakeholders and the AI lifecycle. It satisfies the stem's requirement for contextual analysis, unlike Govern (policy), Measure (testing) or Manage (treatment), which address different stages of the framework.

Why this answer

The AI RMF's four functions are: Govern, Map, Measure, Manage. Map focuses on context and risk identification. Govern sets policies.

Measure evaluates metrics. Manage addresses risks through controls.

17
MCQeasy

A company wants to train a language model on sensitive customer data without transferring the raw data to a central server. Which privacy-preserving technique should they use?

A.Federated learning
B.Differential privacy
C.Data minimisation
D.Anonymisation
AnswerA

Federated learning trains the model locally on each device, exchanging only model updates rather than raw records, so sensitive customer data never leaves its source. This directly satisfies the stem's constraint of avoiding transfer to a central server, unlike centralised training approaches that require aggregating the dataset first.

Why this answer

Federated learning is the correct technique because it trains a shared model across decentralized edge devices holding local data, without transferring raw customer data to a central server. Only model updates (gradients) are sent to the aggregation server, preserving data locality and reducing exposure. This directly addresses the requirement of avoiding raw data transfer while still enabling collaborative model training.

Exam trap

CompTIA AI often tests the distinction between techniques that prevent raw data transfer (federated learning) versus techniques that protect data after it has been transferred (differential privacy, anonymisation), leading candidates to confuse privacy-preserving computation with output privacy.

How to eliminate wrong answers

Option B (Differential privacy) is wrong because it adds noise to query outputs or training data to protect individual records, but it does not prevent raw data from being transferred to a central server; it only limits information leakage from the released model. Option C (Data minimisation) is wrong because it is a principle of collecting only necessary data, not a technical mechanism for training a model without transferring raw data to a central location. Option D (Anonymisation) is wrong because it irreversibly removes personally identifiable information from the dataset before transfer, but the raw (anonymised) data still must be sent to a central server, violating the requirement of no raw data transfer.

18
MCQhard

A company trains a large language model on a dataset that includes copyrighted books. Under current legal interpretations, which statement about copyright infringement is MOST accurate?

A.Training on copyrighted data is generally permissible under the EU AI Act.
B.Training on copyrighted data is always covered by fair use in the US.
C.Training on copyrighted data is allowed as long as the model is not used commercially.
D.Training on copyrighted data without permission likely infringes copyright, though fair use may be a defense.
AnswerD

Copyright subsists automatically in original works, so reproducing books to train a model is prima facie infringement; fair use is only an affirmative defence, not a guarantee, and its success depends on the four statutory factors.

Why this answer

Training on copyrighted works without permission is generally considered copyright infringement, unless a specific exception applies (e.g., fair use in the US). Fair use is determined on a case-by-case basis and is not automatically granted. Using only public domain works avoids infringement.

The EU AI Act does not provide blanket permission.

19
MCQmedium

A hospital is implementing an AI system to analyze patient X-rays for potential fractures. The hospital must comply with HIPAA regulations. Which privacy-preserving technique allows the model to be trained on data from multiple hospitals without sharing raw patient data?

A.Federated learning
B.Differential privacy
C.Data anonymisation
D.Data pseudonymisation
AnswerA

Federated learning trains a shared model locally at each hospital, exchanging only model updates such as gradients rather than raw X-ray images. This satisfies HIPAA by keeping patient data within each hospital's boundary while still producing a model trained across multiple sites.

Why this answer

Federated learning allows multiple hospitals to collaboratively train a model without sharing raw patient data. Each hospital trains a local model on its own data, and only model updates (e.g., gradients or weights) are shared with a central server, which aggregates them. This preserves privacy and helps comply with HIPAA by keeping patient data on-premises.

Exam trap

AI0-001 often tests privacy-preserving techniques; candidates may confuse federated learning (no raw data sharing) with differential privacy (noise addition) or anonymisation (data sharing after de-identification).

How to eliminate wrong answers

Option B is wrong because differential privacy adds noise to data or queries to protect individual privacy, but it still requires data to be shared or a central dataset; it does not inherently enable training across multiple hospitals without sharing raw data. Option C is wrong because data anonymisation removes personally identifiable information, but the data must still be shared, and anonymisation can be reversed or may not satisfy HIPAA. Option D is wrong because pseudonymisation replaces identifiers with pseudonyms, but the data is still shared and may be re-identified; it does not prevent data sharing.

20
Multi-Selectmedium

A company is implementing an AI ethics board. Which TWO responsibilities should the board typically have?

Select 2 answers
A.Approving or rejecting high-risk AI initiatives
B.Writing code for fairness algorithms
C.Reviewing AI projects for ethical compliance and potential biases
D.Developing marketing strategies for AI products
E.Conducting daily data privacy audits
AnswersA, C

The board holds decision authority over high-risk AI initiatives, approving or rejecting them based on ethical risk assessment. This gatekeeping responsibility matches the stem's expectation that the board governs deployments, ensuring risky projects cannot proceed without ethical sign-off.

Why this answer

An AI ethics board should oversee AI projects for ethical compliance and approve high-risk AI initiatives. Implementing technical models and auditing data privacy are operational tasks not typically under the board's direct purview.

21
MCQmedium

A city government uses an AI system to allocate limited social services resources. To ensure fairness, they want to implement human oversight for high-stakes decisions. Which mechanism allows a human to review and potentially override the AI's decision before it is executed?

A.Human-on-the-loop
B.Human-in-command
C.Human-in-the-loop
D.Automated decision-making without human intervention
AnswerC

Human-in-the-loop places a person in the decision path before execution, allowing review and override of the AI's output. This satisfies the fairness requirement for high-stakes social services allocations, where automated decisions carry significant consequences for individuals.

Why this answer

Human-in-the-loop (HITL) is the correct mechanism because it requires a human to review and approve or reject the AI's decision before it is executed. This ensures that for high-stakes decisions, such as allocating limited social services, a human can intervene to prevent unfair or erroneous outcomes, directly addressing the fairness requirement.

Exam trap

In the CompTIA AI exam, candidates often confuse 'Human-in-the-loop' (human must review and approve before action) with 'Human-on-the-loop' (human monitors but action proceeds automatically unless overridden). This question requires pre-execution human review, so HITL is correct.

How to eliminate wrong answers

Option A is wrong because 'Human-on-the-loop' refers to a system where a human monitors AI decisions and can intervene during execution, but the decision is typically executed automatically unless the human steps in—this does not guarantee pre-execution review. Option B is wrong because 'Human-in-command' is a broader concept where a human has overall control and responsibility for the system's operation, but it does not specify a mandatory review step before each high-stakes decision is executed. Option D is wrong because 'Automated decision-making without human intervention' explicitly removes human oversight, which contradicts the requirement to implement human oversight for fairness.

22
MCQhard

A data scientist is building a machine learning model to predict employee attrition for an HR department. The model will be used to identify employees at risk of leaving and to suggest personalized retention offers. The company operates in the EU. Under the EU AI Act, which classification applies to this AI system?

A.It is a minimal-risk AI system because it only provides suggestions and does not make final decisions.
B.It is a prohibited AI system because it uses AI to infer emotions of employees.
C.It is a high-risk AI system because it is used in employment and workers management.
D.It is a limited-risk AI system and only requires transparency to employees about its use.
AnswerC

The EU AI Act classifies AI systems used in employment, workers management, and access to self-employment as high-risk. This includes systems for recruitment, promotion, termination, and task allocation. Predicting attrition and suggesting retention offers falls under HR management, so it is high-risk.

Why this answer

The EU AI Act explicitly classifies AI systems used in employment and workers management as high-risk. This includes systems that predict attrition and suggest retention strategies, as they can impact employees' careers and livelihoods. The system is not prohibited because it does not infer emotions, and it is not limited or minimal risk due to its HR application.

Exam trap

The trap here is assuming that AI systems that only provide recommendations or suggestions are not high-risk, but the EU AI Act focuses on the context of use, not the level of automation.

23
Multi-Selecteasy

A startup is training a large language model and wants to reduce its environmental impact. Which TWO practices are considered green AI?

Select 2 answers
A.Train on the largest possible dataset
B.Use energy-efficient hardware (e.g., TPUs)
C.Use redundant backup servers
D.Increase batch size to maximum
E.Optimize model architecture for lower computational cost
AnswersB, E

Energy-efficient hardware reduces power consumption.

Why this answer

Using energy-efficient hardware such as Tensor Processing Units (TPUs) or specialized AI accelerators reduces the power consumption per floating-point operation, directly lowering the carbon footprint of training large language models. This aligns with green AI principles by optimizing the energy-to-performance ratio.

Exam trap

CompTIA often tests the misconception that maximizing hardware utilization (e.g., large batch sizes or datasets) is inherently green, when in fact green AI focuses on minimizing total energy consumption and carbon emissions, not just throughput or utilization metrics.

24
MCQeasy

A data scientist discovers that a model trained to predict loan defaults is denying loans at a higher rate for a particular demographic group. Which type of bias is MOST likely present?

A.Confirmation bias
B.Selection bias
C.Algorithmic bias
D.Historical bias
AnswerD

Historical bias arises when training data reflects past societal or institutional prejudice, so the model reproduces those disparities. A loan model denying one demographic at higher rates mirrors biased historical lending decisions captured in the training set.

Why this answer

Historical bias occurs when the training data reflects past societal inequalities, leading the model to learn and perpetuate those patterns. In this case, if historical loan data shows higher denial rates for a demographic group due to past discriminatory practices, the model will replicate that bias in its predictions. This is the most likely cause because the model is not inherently biased but inherits bias from the data it was trained on.

Exam trap

The trap here is that candidates may confuse 'algorithmic bias' (a general term) with the specific root cause, failing to recognize that historical bias is the precise type when the bias originates from the training data rather than the algorithm itself.

How to eliminate wrong answers

Option A is wrong because confirmation bias refers to a human tendency to favor information that confirms preexisting beliefs, not a data-driven model bias in loan predictions. Option B is wrong because selection bias arises from non-random sampling of data (e.g., only including certain loan applicants), which is not described in the scenario where the model is trained on historical data. Option C is wrong because algorithmic bias is a broad term that can include historical bias, but the question asks for the most likely specific type, and historical bias directly explains the root cause in the training data.

25
MCQeasy

A company deploys an AI chatbot that generates product descriptions. The company wants to be transparent about AI-generated content. Which practice should they follow?

A.Clearly label AI-generated content as such
B.Publish a model card, but not label individual outputs
C.Add an invisible watermark but do not inform users
D.Do not disclose that content is AI-generated to avoid user confusion
AnswerA

Labelling AI-generated product descriptions directly satisfies the transparency requirement by disclosing the content's synthetic origin to readers. Unlike watermarking, which embeds imperceptible signals, or provenance metadata, which machines read, a visible label communicates authorship at the point of consumption, ensuring customers know the text was produced by the chatbot rather than a human.

Why this answer

Transparency about AI-generated content is a core principle of AI governance and ethics. Labeling AI-generated outputs as such allows users to make informed decisions about the content they consume, aligning with responsible AI practices.

Exam trap

The trap here is that candidates may think transparency is achieved through documentation alone (like model cards) or through hidden mechanisms, but Cisco tests that direct, user-visible labeling of AI-generated content is the ethical standard.

How to eliminate wrong answers

Option B is wrong because publishing a model card alone does not provide transparency for individual outputs; users need to know which specific content is AI-generated. Option C is wrong because an invisible watermark without informing users defeats the purpose of transparency, as users are unaware of the AI's involvement. Option D is wrong because intentionally hiding AI-generated content to avoid confusion violates ethical guidelines and erodes trust, as users have a right to know when content is AI-generated.

26
MCQhard

A healthcare AI system diagnosing diabetic retinopathy from retinal images shows high accuracy overall but significantly lower recall for patients with darker skin tones. Which fairness metric would BEST capture this disparity by comparing true positive rates across groups?

A.Calibration
B.Demographic parity
C.Equalised odds
D.Individual fairness
AnswerC

Equalised odds compares true positive rates and false positive rates across groups, so it directly exposes the lower recall for darker-skinned patients. Demographic parity or equal opportunity alone would not capture the full disparity across both error types that this metric requires.

Why this answer

Equalised odds is a fairness metric that requires both true positive rates (TPR) and false positive rates (FPR) to be equal across groups. In this scenario, the disparity is specifically in recall (TPR) for patients with darker skin tones, so equalised odds directly captures the difference in TPR between groups. It ensures that the model's ability to correctly identify positive cases is independent of the group attribute.

Exam trap

AI0-001 often tests the confusion between different fairness metrics. Candidates may choose demographic parity because it is commonly mentioned, but it does not address TPR disparities. The key is to recognize that the question asks for a metric comparing true positive rates across groups, which is equalised odds.

How to eliminate wrong answers

Option A is wrong because calibration measures how well predicted probabilities match actual outcomes, not the disparity in true positive rates across groups. Option B is wrong because demographic parity requires the same proportion of positive predictions across groups, regardless of actual outcomes; it does not focus on TPR. Option D is wrong because individual fairness requires similar predictions for similar individuals, which is a different concept and not group-based.

27
MCQhard

A financial institution deploys an AI model for loan approval. To meet regulatory requirements under the EU AI Act for high-risk AI systems, they must ensure human oversight. Which implementation best satisfies the requirement for meaningful human intervention?

A.Audit model decisions quarterly for bias
B.Allow users to appeal decisions through a customer service hotline
C.Display a confidence score for each decision
D.Provide a human reviewer with the ability to override the model's decision before finalization
AnswerD

Meaningful human oversight under the EU AI Act requires a reviewer who can actually intervene in the outcome, not merely observe. Granting authority to override the model's decision before it is finalised provides that effective intervention, satisfying the high-risk human-oversight obligation.

Why this answer

The EU AI Act's human oversight requirement for high-risk systems demands that humans can effectively monitor, intervene, and override AI outputs. Providing a human reviewer with the ability to override the model's decision before it is finalized directly implements meaningful human intervention at the decision point, which is the core of Article 14 oversight obligations.

Exam trap

AI0-001 often tests the distinction between post-hoc redress (appeals, audits) and pre-decision human intervention, causing candidates to select appeal mechanisms that do not satisfy Article 14's real-time oversight requirement.

How to eliminate wrong answers

Option A is wrong because quarterly bias audits are a post-hoc governance control, not real-time human oversight of individual decisions. Option B is wrong because a customer appeal hotline is a redress mechanism after the decision has already been made, not intervention before finalization. Option C is wrong because displaying a confidence score only informs a human; it does not by itself grant the ability to intervene or override the decision.

28
Multi-Selecthard

A healthcare AI system is subject to GDPR because it processes patient data. Which THREE requirements must the system satisfy?

Select 3 answers
A.Right to explanation of decisions
B.Explicit consent from all data subjects
C.Meaningful information about the logic involved in automated decision-making
D.Data minimization principles
E.Data retention period of at least 10 years
AnswersA, C, D

Article 22 and Recital 71 provide a right to explanation for automated decisions.

Why this answer

Article 22 of the GDPR grants data subjects the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects or similarly significant effects. For healthcare AI systems, this means patients have the right to obtain an explanation of the decision reached by the algorithm, such as how a diagnosis or treatment recommendation was derived. This requirement ensures transparency and accountability in high-stakes automated decisions.

Exam trap

Candidates often confuse the requirements of GDPR for AI systems. A common trap is assuming that explicit consent is always required for healthcare AI processing, but GDPR provides other lawful bases (e.g., vital interests, public health). The right to explanation is a distinct requirement under Article 22 for automated decision-making, and data minimization principles apply broadly.

29
MCQeasy

A marketing team wants to use an AI system to generate personalized advertisements that include realistic images of celebrities endorsing products. The legal team raises concerns about compliance with the EU AI Act. Which action should the team take to comply with the Act's transparency requirements?

A.Use only images of celebrities who are deceased, as the Act only applies to living individuals
B.Clearly disclose that the images are AI-generated and not real
C.Limit the advertisements to social media platforms that have their own AI disclosure policies
D.Obtain a license from each celebrity before generating their image
AnswerB

The EU AI Act requires that deepfake content be disclosed as artificially generated or manipulated. Using AI to create realistic images of celebrities endorsing products constitutes a deepfake, so the team must clearly label the content to inform viewers. This transparency requirement applies regardless of licensing.

Why this answer

Under the EU AI Act, deepfake content must be disclosed as artificially generated or manipulated. Generating realistic images of celebrities endorsing products without disclosure would violate this transparency requirement. The team must clearly label the images as AI-generated, regardless of licensing or platform policies.

Exam trap

The trap here is assuming that obtaining a license or relying on platform policies satisfies the EU AI Act's transparency requirements, when the Act specifically mandates disclosure of deepfake content.

30
MCQmedium

A data scientist needs to explain why a black-box model denied a loan application. Which explainability technique generates local feature importance values using a simpler interpretable model around the prediction?

A.Model card
B.LIME
C.Attention visualisation
D.SHAP values
AnswerB

LIME fits a simple interpretable surrogate model, such as a linear model, around the individual prediction and reports local feature importance for that single loan decision. This satisfies the stem's demand for local explanation of a black-box model's specific output.

Why this answer

LIME (Local Interpretable Model-agnostic Explanations) is the correct technique because it generates local feature importance values by fitting a simpler, interpretable model (e.g., linear regression or decision tree) around the prediction of the black-box model. This allows the data scientist to explain why a specific loan application was denied by identifying which features (e.g., income, credit score) most influenced that particular decision. Unlike global methods, LIME focuses on the local neighborhood of the instance, making it ideal for explaining individual predictions.

Exam trap

The AI0-001 exam often tests the distinction between local vs. global explainability methods, and the trap here is that candidates may confuse SHAP values (which also provide local feature importance) with LIME, failing to recognize that LIME uniquely uses a simpler interpretable surrogate model trained around the prediction, while SHAP uses game-theoretic contributions without a surrogate model.

How to eliminate wrong answers

Option A is wrong because a model card is a documentation artifact that summarizes a model's intended use, performance, and limitations at a global level, not a technique for generating local feature importance values for a single prediction. Option C is wrong because attention visualization is specific to neural network architectures (e.g., transformers) and provides insight into which parts of the input the model 'attends to,' but it is not a model-agnostic method for generating local feature importance with a simpler interpretable model. Option D is wrong because SHAP values, while they do provide local feature importance, are based on cooperative game theory (Shapley values) and do not use a simpler interpretable model around the prediction; instead, they compute additive feature contributions directly from the model's output.

31
MCQmedium

Under the EU AI Act, an AI system that uses subliminal techniques to materially distort a person's behaviour, causing psychological or physical harm, would be classified under which risk tier?

A.Unacceptable risk
B.Limited risk
C.High risk
D.Minimal risk
AnswerA

Subliminal manipulation causing psychological or physical harm falls squarely within the prohibited practises list under Article 5 of the EU AI Act. Such systems are banned outright, placing them in the unacceptable risk tier rather than high, limited or minimal risk.

Why this answer

Under the EU AI Act, AI systems that deploy subliminal, purposefully manipulative, or deceptive techniques to materially distort a person's behaviour and cause significant harm are explicitly banned. These practices are considered a clear threat to fundamental rights and are therefore classified as unacceptable risk. The Act's Article 5 prohibits such systems, placing them in the highest risk tier with outright bans.

Exam trap

AI0-001 often tests the distinction between prohibited practices (unacceptable risk) and high-risk systems, as candidates may confuse manipulative techniques with high-risk applications that require strict compliance rather than being banned.

How to eliminate wrong answers

Option B is wrong because limited risk systems are subject to transparency obligations only, such as disclosing that a user is interacting with an AI, and do not include manipulative techniques causing harm. Option C is wrong because high-risk systems are permitted but must meet strict requirements for safety, transparency, and human oversight; they do not include banned practices like subliminal manipulation. Option D is wrong because minimal risk systems are those with little to no risk, such as spam filters or AI-enabled video games, and are not subject to any additional regulatory requirements.

32
MCQmedium

A software vendor is developing an AI system that generates realistic images of people for use in marketing campaigns. The system will be sold to clients in the EU. Under the EU AI Act, which obligation applies to the vendor regarding the generated content?

A.The vendor must register the AI system in the EU database for high-risk systems.
B.The vendor must obtain explicit consent from all individuals whose likeness is used in the training data.
C.The vendor must conduct a conformity assessment before placing the system on the market.
D.The vendor must ensure that generated images are marked in a machine-readable format as artificially generated.
AnswerD

The EU AI Act requires providers of AI systems that generate synthetic content, such as images, to mark the output in a machine-readable format to indicate it is AI-generated. This applies to deepfakes and other synthetic media, ensuring transparency and enabling detection.

Why this answer

The EU AI Act requires that AI-generated content, including synthetic images, be marked in a machine-readable format to indicate its artificial origin. This is a transparency obligation for providers of such systems. The vendor must implement this marking.

Other obligations like consent, database registration, and conformity assessment apply to different risk categories or legal frameworks.

Exam trap

The trap here is confusing the AI Act's transparency obligation for synthetic content with GDPR consent requirements, or assuming that any AI system dealing with personal data is automatically high-risk.

33
MCQeasy

A company is developing an AI policy. Which of the following should be included to ensure accountability for AI-driven decisions?

A.A set of acceptable use cases for the AI
B.A description of the model architecture used
C.A list of approved training data sources
D.Designated roles for human oversight and decision authority
AnswerD

Assigning designated roles for human oversight and decision authority establishes named accountability for AI-driven outcomes, ensuring a responsible person can review, approve or override decisions. This satisfies the policy requirement for accountability, unlike generic principles or training mandates.

Why this answer

Accountability for AI-driven decisions requires clear assignment of human roles with oversight and decision authority. This ensures that there is a responsible party who can review, override, or be held liable for the AI's outputs, which is a core principle of AI governance frameworks such as the NIST AI Risk Management Framework.

Exam trap

Candidates often confuse the components of an AI governance policy, such as acceptable use or data sources, with the accountability mechanism of human oversight. The key is to remember that accountability requires designated roles with authority to review and override AI decisions.

How to eliminate wrong answers

Option A is wrong because acceptable use cases define scope, not accountability; they do not assign responsibility for decisions. Option B is wrong because describing the model architecture is a technical documentation detail, not a governance mechanism for accountability. Option C is wrong because listing approved training data sources addresses data provenance and bias, but does not establish who is responsible for the AI's decisions.

34
MCQmedium

A healthcare AI startup is developing a model to predict patient readmission risk. The model will be used to allocate post-discharge resources. Which regulatory framework primarily governs the use of patient data in this scenario?

A.GDPR
B.CCPA
C.HIPAA
D.EU AI Act
AnswerC

HIPAA governs protected health information held by covered entities and their business associates, so it directly constrains how the startup handles patient records for readmission prediction. Its Privacy and Security Rules dictate permissible use, disclosure and safeguarding of that data, satisfying the stem's requirement for the framework primarily regulating patient data in US healthcare.

Why this answer

HIPAA (Health Insurance Portability and Accountability Act) is the correct regulatory framework because the scenario involves a healthcare AI startup using protected health information (PHI) to predict patient readmission risk. HIPAA governs the use, disclosure, and safeguarding of PHI by covered entities and their business associates, which includes AI models processing patient data for post-discharge resource allocation.

Exam trap

CompTIA AI+ often tests the distinction between data privacy regulations (HIPAA, GDPR, CCPA) and AI-specific regulations (EU AI Act). Candidates may incorrectly assume the EU AI Act governs all AI data use, but the underlying data type (healthcare PHI) dictates the primary framework.

How to eliminate wrong answers

Option A is wrong because GDPR is a European Union regulation that applies to personal data of EU residents, but the scenario does not specify that the patients are in the EU or that the startup operates under EU jurisdiction; HIPAA is the primary U.S. healthcare data privacy law. Option B is wrong because CCPA is a California state law focused on consumer privacy and data rights for California residents, not specifically tailored to healthcare data or patient readmission models; it does not preempt HIPAA for protected health information. Option D is wrong because the EU AI Act governs the development and deployment of AI systems based on risk categories, but it does not directly regulate the use of patient data; data privacy for healthcare remains under GDPR or local health data laws, not the AI Act itself.

35
Multi-Selectmedium

Under the EU AI Act, an AI system used for credit scoring is classified as high-risk. Which THREE obligations apply to the deployer of such a system?

Select 3 answers
A.Register the system with a central EU database
B.Publish the model's source code publicly
C.Provide transparency information to affected individuals
D.Conduct a fundamental rights impact assessment
E.Ensure human oversight of the system's decisions
AnswersC, D, E

Deployers must inform individuals that an AI system is making decisions affecting them.

Why this answer

Article 13 of the EU AI Act requires deployers of high-risk AI systems to provide clear and meaningful transparency information to affected individuals, including the system's capabilities, limitations, and the logic behind decisions. This obligation ensures that individuals subject to automated credit scoring understand how their data is being used and can exercise their rights under the regulation.

Exam trap

The trap here is that candidates often confuse deployer obligations with provider obligations, mistakenly assigning registration and code publication duties to the deployer instead of the provider.

36
MCQmedium

A hospital wants to train a diagnostic AI model using data from multiple hospitals without sharing raw patient data. Which privacy-preserving technique allows collaborative training while keeping data local?

A.Differential privacy
B.Federated learning
C.Data anonymisation
D.Data pseudonymisation
AnswerB

Federated learning trains a shared model across hospitals by exchanging only model updates, such as gradients or weights, rather than raw patient records. Each hospital's data therefore stays local, satisfying the requirement for collaborative training without sharing patient data.

Why this answer

Federated learning is the correct technique because it enables multiple hospitals to collaboratively train a shared diagnostic AI model without exchanging raw patient data. Instead, each hospital trains a local model on its own data, and only encrypted model updates (e.g., gradients or weights) are sent to a central server for aggregation. This keeps all sensitive patient information local, directly addressing the requirement of data locality while still benefiting from collective learning.

Exam trap

CompTIA emphasizes the distinction between techniques that alter data before sharing (e.g., anonymization, pseudonymization) and techniques that keep data local and share only model parameters (federated learning). The trap is assuming that anonymizing or pseudonymizing data satisfies the 'keep data local' requirement, but these still involve data leaving the hospital.

How to eliminate wrong answers

Option A is wrong because differential privacy adds noise to data or model outputs to protect individual privacy, but it does not keep data local; it can be applied to centralized or federated settings, but alone it does not enable collaborative training without sharing raw data. Option C is wrong because data anonymisation removes or masks personally identifiable information (PII) from a dataset, but the anonymised data is still shared with other parties, which violates the requirement to keep raw patient data local. Option D is wrong because data pseudonymisation replaces identifiers with pseudonyms, but the pseudonymised data is still shared and can potentially be re-identified, failing to meet the strict local data constraint.

37
MCQmedium

A data scientist needs to explain why a specific loan application was rejected by a tree-based model. The model is complex and not inherently interpretable. Which method should the data scientist use to provide a local explanation for this single prediction?

A.LIME
B.SHAP values
C.Model cards
D.Attention visualization
AnswerA

LIME creates a simple, interpretable model around the prediction to explain the decision locally, making it ideal for this task.

Why this answer

LIME (Local Interpretable Model-agnostic Explanations) is the correct choice because it is specifically designed to provide local explanations for individual predictions by approximating the complex model with a simpler, interpretable surrogate model around that specific instance. For a tree-based model that is not inherently interpretable, LIME can explain why a single loan application was rejected by perturbing the input and observing the changes in predictions, making it ideal for this use case.

Exam trap

The AI0-001 exam often tests the distinction between local vs. global interpretability methods, and the trap here is that candidates may choose SHAP values (Option B) because they are also popular for explanations, but SHAP is more suited for global feature importance and can be overkill or less intuitive for a single-instance explanation compared to LIME's direct local surrogate approach.

How to eliminate wrong answers

Option B is wrong because SHAP values, while also providing local explanations, are based on cooperative game theory and compute Shapley values, which can be computationally expensive for complex tree-based models and may not be as straightforward for a single-prediction explanation as LIME's perturbation-based approach. Option C is wrong because model cards are documentation artifacts that describe the overall model's intended use, performance, and limitations, not a method for generating local explanations for individual predictions. Option D is wrong because attention visualization is a technique used primarily in neural network models (e.g., transformers) to highlight which parts of the input the model focuses on, and it is not applicable to tree-based models like decision trees or random forests.

38
MCQmedium

A health system wants to deploy an AI triage tool that analyzes patient symptoms and vital signs to prioritize emergency department patients. Before deployment, the governance committee must determine whether the tool qualifies as a high-risk AI system under the EU AI Act. Which factor is MOST determinative of that classification?

A.Whether the tool is deployed on-premises or through a cloud service
B.Whether the AI model was trained on a dataset containing more than 100,000 patient records
C.Whether the AI tool uses a deep learning architecture rather than a rules-based system
D.Whether the AI tool is used to make decisions that could significantly affect a patient's health, safety, or fundamental rights
AnswerD

Under the EU AI Act, high-risk classification is tied to the intended purpose and the significance of the impact on health, safety, or fundamental rights. A triage tool that prioritizes emergency patients directly affects health outcomes, so its risk level is determined by that impact rather than by the vendor's marketing claims or the model architecture.

Why this answer

High-risk classification under the EU AI Act hinges on the intended purpose and the severity of potential impact on health, safety, or fundamental rights. A triage tool that influences emergency care decisions can directly affect patient health, so it falls into the high-risk category regardless of data size, architecture, or deployment model.

Exam trap

The trap here is assuming that technical characteristics such as dataset size or model architecture determine high-risk classification, rather than the intended purpose and potential impact on health, safety, or fundamental rights.

39
MCQeasy

A data scientist notices that a hiring model systematically scores female candidates lower than male candidates with similar qualifications. The training data was collected from past hiring decisions where the company historically hired more men. Which type of AI bias is most directly demonstrated?

A.Selection bias
B.Algorithmic bias
C.Confirmation bias
D.Historical bias
AnswerD

Historical bias arises when training data reflects past human prejudice, so the model reproduces that pattern. Here, past hiring favoured men, embedding that imbalance in the labels. This directly satisfies the stem's constraint of skewed historical hiring decisions, producing lower scores for equally qualified female candidates.

Why this answer

Historical bias, because the model's lower scoring of female candidates stems directly from training data that reflects past hiring decisions where the company historically hired more men. This bias is embedded in the data itself, not introduced by the algorithm or data collection method. Historical bias occurs when the training data encodes societal or organizational prejudices from the past, which the model then perpetuates.

Exam trap

The AI0-001 exam often tests the distinction between historical bias (data-driven) and algorithmic bias (model-driven), and the trap here is that candidates confuse 'algorithmic bias' as the catch-all term, missing that the root cause is the historical data, not the algorithm's logic.

How to eliminate wrong answers

Option A is wrong because selection bias refers to systematic error in how data is sampled or collected (e.g., non-random sampling), not to bias inherited from historical outcomes in the training data. Option B is wrong because algorithmic bias is a broader term that includes any bias introduced by the algorithm's design or optimization process, but here the root cause is the historical data, not the algorithm itself. Option C is wrong because confirmation bias is a human cognitive bias where people favor information that confirms their preexisting beliefs, and it does not apply to a machine learning model's training process.

40
Multi-Selecthard

A company is deploying an AI system that falls under the EU AI Act's high-risk category. Which THREE requirements must the company fulfill?

Select 3 answers
A.Ensure human oversight to prevent or minimise risks
B.Obtain explicit consent from all affected individuals
C.Open-source the model's code to the public
D.Create and maintain technical documentation including the system's intended purpose
E.Establish a risk management system throughout the AI system's lifecycle
AnswersA, D, E

High-risk systems must be designed so natural persons can effectively oversee them, including the ability to intervene, override or halt operation. Human oversight detects and mitigates emerging risks during real-world use, directly fulfilling the EU AI Act's requirement to prevent or minimise harm.

Why this answer

The EU AI Act for high-risk systems requires risk management, human oversight, and transparency documentation. Open-sourcing the model is not required; obtaining consent is not a specific requirement for high-risk systems.

41
Multi-Selecthard

A bank wants to ensure its credit scoring model is fair across demographic groups. The model currently uses features like zip code, income, and credit history. To mitigate potential bias, which TWO actions should the data science team prioritize?

Select 2 answers
A.Analyze the model for disparate impact using statistical tests
B.Review features like zip code for potential proxy discrimination
C.Remove all features that could be correlated with protected attributes
D.Implement a fairness metric like demographic parity or equalized odds
E.Apply differential privacy to the training data
AnswersA, B

Disparate impact analysis helps identify whether the model adversely affects a protected group.

Why this answer

Analyzing the model for disparate impact using statistical tests (e.g., the 80% rule or chi-square test) directly measures whether the model produces systematically different outcomes for protected groups. This is a foundational step in fairness auditing, as it quantifies bias before any mitigation is applied, aligning with regulatory expectations like the Equal Credit Opportunity Act (ECOA).

Exam trap

CompTIA AI+ emphasizes that bias detection (statistical tests, proxy review) must come before mitigation. Many candidates incorrectly select mitigation actions like demographic parity or data removal as a first step, but the exam stresses that bias must first be measured and understood.

42
MCQmedium

A social media platform uses an AI system to moderate content. The system incorrectly flags legitimate posts as hate speech, disproportionately affecting minority groups. Which type of bias is likely present?

A.Algorithmic bias
B.Historical bias
C.Selection bias
D.Confirmation bias
AnswerA

Algorithmic bias arises when the model's design, training data, or optimisation produces systematically unfair outcomes for particular groups. The disproportionate flagging of minority users' legitimate posts is a direct manifestation of that bias embedded in the classifier's decision logic.

Why this answer

The AI system's output (incorrectly flagging legitimate posts as hate speech) is a direct result of the model's design, training data, or deployment choices, which is the definition of algorithmic bias. This bias disproportionately affects minority groups because the algorithm's decision-making process systematically produces unfair outcomes for those groups, even if the training data itself was not historically biased.

Exam trap

The AI0-001 exam often tests the distinction between 'algorithmic bias' (bias introduced by the model's design or deployment) and 'historical bias' (bias present in the training data), so candidates mistakenly choose historical bias when the question describes a system that actively produces unfair outcomes due to its own logic.

How to eliminate wrong answers

Option B (Historical bias) is wrong because historical bias refers to pre-existing societal prejudices reflected in the training data, not the algorithm's own flawed decision-making process; the question states the system 'incorrectly flags' posts, indicating the bias is in the algorithm's logic or thresholds, not just the data. Option C (Selection bias) is wrong because selection bias occurs when the training data is not representative of the real-world population (e.g., overrepresenting certain groups), but the problem here is the algorithm's misclassification of content, not a sampling issue. Option D (Confirmation bias) is wrong because confirmation bias is a human cognitive bias where people favor information that confirms their preexisting beliefs; it does not apply to an AI system's content moderation decisions.

43
MCQhard

A company is evaluating a vendor's AI system for hiring. The vendor claims the system is fair because it achieves demographic parity. However, the company discovers that the system has significantly different false positive rates across groups. Which fairness issue does this indicate?

A.The system violates individual fairness
B.The system suffers from selection bias
C.The system violates equalised odds
D.The system is not calibrated
AnswerC

Equalised odds requires equal true positive and false positive rates across groups, so differing false positive rates directly breach it. Demographic parity only matches selection rates, ignoring error distribution, which is why a system can satisfy parity yet still violate equalised odds.

Why this answer

Equalised odds requires that a model's false positive rates and true positive rates are equal across all demographic groups. Since the vendor's system has significantly different false positive rates across groups, it violates the equalised odds fairness criterion, even if demographic parity (equal selection rates) is satisfied. This is a core fairness metric in AI governance, as it ensures that errors are distributed equitably.

Exam trap

A common CompTIA AI exam trap is the distinction between demographic parity and equalised odds, as candidates may assume that equal selection rates (demographic parity) automatically guarantee fairness across all error types.

How to eliminate wrong answers

Option A is wrong because individual fairness focuses on treating similar individuals similarly, not on group-level error rates like false positives. Option B is wrong because selection bias refers to systematic errors in data collection or sampling that lead to unrepresentative training data, not to post-deployment disparities in model errors across groups. Option D is wrong because calibration measures whether predicted probabilities match actual outcomes within each group, which is a separate property from equalised odds; a model can be calibrated yet still have unequal false positive rates.

44
Multi-Selectmedium

A data scientist is using differential privacy to protect individual privacy in a training dataset. Which TWO actions are correct implementations of differential privacy?

Select 2 answers
A.Train the model on a small subset of data to reduce exposure
B.Remove all personally identifiable information (PII) from the dataset
C.Aggregate data into groups before training
D.Set a privacy budget (epsilon) to limit information leakage
E.Add noise to the training data to mask individual contributions
AnswersD, E

The privacy budget epsilon quantifies the privacy guarantee and is a core concept of differential privacy.

Why this answer

Setting a privacy budget (epsilon) is a core mechanism in differential privacy that quantifies and limits the amount of information leaked about any individual in the dataset. By controlling epsilon, the data scientist can formally bound the privacy loss, ensuring that the model's outputs do not reveal whether any specific individual's data was included in training.

Exam trap

A common pitfall in this question is thinking that removing PII or aggregating data is sufficient for differential privacy. In reality, differential privacy requires a formal mathematical framework with noise addition and a privacy budget parameter. CompTIA often tests this distinction.

45
MCQeasy

Which technique adds controlled noise to query results or training data to prevent an attacker from inferring whether a specific individual's data was included in the dataset?

A.Anonymisation
B.Federated learning
C.Differential privacy
D.Pseudonymisation
AnswerC

Differential privacy injects calibrated statistical noise into query outputs or training data, bounding how much any single record influences results. This mathematically limits inference about whether a specific individual's data was included, unlike anonymisation or masking.

Why this answer

Differential privacy is the technique that adds controlled statistical noise (e.g., Laplace or Gaussian noise) to query results or training data so that the presence or absence of any single individual's data cannot be inferred. It provides a mathematical guarantee (epsilon-differential privacy) that the output distribution is nearly identical whether or not a specific record is included. This directly matches the question's requirement.

Exam trap

AI0-001 often tests the confusion between anonymisation/pseudonymisation (which are data-masking techniques without formal guarantees) and differential privacy (which provides a mathematical privacy guarantee against inference), so candidates pick the familiar term instead of the rigorous one.

How to eliminate wrong answers

Option A is wrong because anonymisation removes or masks personally identifiable information but does not provide a formal guarantee against inference attacks — an attacker can still correlate quasi-identifiers to re-identify individuals (as shown in the Netflix Prize and AOL search log incidents). Option B is wrong because federated learning is a distributed training approach where models are trained locally on devices and only updates are aggregated; it protects raw data locality but does not by itself prevent inference about whether a specific individual's data was used. Option D is wrong because pseudonymisation replaces identifiers with pseudonyms but retains a mapping that can be reversed, so it does not prevent inference attacks and is not a formal privacy guarantee.

46
MCQmedium

A data scientist is training a resume screening model to rank job applicants. The training data includes historical hiring decisions from the past 10 years. The company wants to avoid unfair bias against underrepresented groups. Which type of bias is most likely present in the training data?

A.Algorithmic bias
B.Selection bias
C.Confirmation bias
D.Historical bias
AnswerD

Historical bias arises because the model learns from a decade of past hiring decisions that already reflect prior discriminatory outcomes, so the training labels themselves encode the unfair patterns the company now wants to avoid.

Why this answer

Historical bias occurs when training data reflects past human decisions or societal patterns that were themselves biased, causing the model to learn and perpetuate those patterns. A resume screening model trained on 10 years of hiring decisions will inherit whatever demographic skews existed in those decisions.

Exam trap

AI0-001 often tests the distinction between historical bias (bias baked into the data by past human decisions) and algorithmic bias (bias from model design) — candidates frequently pick 'algorithmic bias' whenever a model produces unfair outcomes, regardless of root cause.

How to eliminate wrong answers

Option A is wrong because algorithmic bias refers to bias introduced by the algorithm's design, optimization objective, or feature engineering, not by the historical data itself. Option B is wrong because selection bias refers to non-random sampling of the data (e.g., only including applicants from certain sources), which is a data-collection issue rather than the inherited-decision issue described. Option C is wrong because confirmation bias is a human cognitive bias where people favor information confirming preexisting beliefs, not a property of training data.

47
MCQeasy

An organisation is developing an AI policy. According to the NIST AI RMF, which function involves establishing policies and procedures to ensure the organisation governs AI responsibly?

A.Manage
B.Measure
C.Govern
D.Map
AnswerC

The Govern function establishes the policies, procedures, roles and accountability structures that ensure AI is developed and used responsibly across the organisation. It satisfies the stem's requirement for setting up governance, whereas Map, Measure and Manage handle risk identification, assessment and treatment.

Why this answer

The Govern function of the NIST AI RMF establishes policies, procedures, and organizational structures to ensure AI is developed and used responsibly. It is the foundational function that cultivates a risk-management culture and assigns accountability across the AI lifecycle.

Exam trap

AI0-001 often tests whether candidates can distinguish the four RMF functions by their verbs — Govern = policies/accountability, Map = context, Measure = analysis, Manage = treatment — and candidates frequently swap Govern and Manage.

How to eliminate wrong answers

Option A is wrong because Manage refers to allocating resources and implementing treatments to address risks identified by the other functions, not to establishing policies. Option B is wrong because Measure involves analyzing, assessing, and tracking AI risks using quantitative and qualitative methods. Option D is wrong because Map is about contextualizing and framing AI risks by understanding the system, its purpose, and its stakeholders.

48
MCQeasy

A municipality uses an AI system to triage requests for public housing assistance. Community advocates ask how they can challenge a denial that they believe resulted from an erroneous data match. Which governance mechanism is MOST appropriate to provide affected individuals with a route to contest automated outcomes?

A.A quarterly fairness audit that measures disparate impact across demographic groups in the triage outcomes.
B.A model card that documents the triage model's training data, performance metrics, and known limitations.
C.An appeals process that lets applicants request human review and correction of the data and logic behind a denial.
D.A published algorithmic impact assessment summarizing the system's risks and mitigations.
AnswerC

A contestability mechanism gives affected individuals a concrete path to question an automated outcome, have a human reconsider it, and correct erroneous inputs. This directly addresses the advocates' concern by ensuring decisions are not final simply because a model produced them. It also creates feedback that can reveal systematic data-matching errors, making it the most appropriate governance control for this scenario.

Why this answer

Contestability requires an actionable process through which an affected person can dispute an automated decision, obtain human review, and have errors corrected. An appeals process with human reconsideration provides that route. Impact assessments, model cards, and fairness audits improve transparency and systemic oversight but do not give individuals a means to challenge their own outcomes.

Exam trap

The trap here is equating transparency artifacts such as model cards or impact assessments with contestability, when disclosure alone does not give an individual a remedy.

49
MCQmedium

A company uses AI to generate marketing images. They want to ensure that the images are clearly identified as AI-generated to comply with transparency obligations. Which approach is most effective?

A.Add a disclaimer in the platform's terms of service
B.Include metadata in the image file indicating it is AI-generated
C.Embed a visible watermark stating 'AI-generated' in each image
D.Rely on deepfake detection algorithms to flag the images
AnswerC

A visible watermark embedded in each image directly satisfies transparency obligations, because viewers immediately recognise the content as AI-generated. This labelling persists within the image itself, unlike metadata, which can be stripped or overlooked during sharing.

Why this answer

A visible watermark embedded directly in each generated image is the most effective transparency measure because it travels with the image regardless of where it is copied, screenshotted, or re-shared, and it is immediately perceivable by any viewer. Metadata can be stripped, and terms of service are not seen by end viewers, so a visible watermark is the only option that guarantees the AI-generated nature is disclosed at the point of consumption.

Exam trap

The trap is assuming that metadata or terms of service satisfy 'transparency' — the exam expects you to recognize that only a visible, persistent marker guarantees the viewer actually sees the AI disclosure.

How to eliminate wrong answers

Option A is wrong because terms of service are legal documents that end viewers of an image never read — they do not provide transparency at the point of consumption. Option B is wrong because metadata (such as C2PA or EXIF tags) is easily stripped by social media platforms, screenshotting, or re-encoding, so it cannot guarantee disclosure. Option D is wrong because deepfake detection algorithms are reactive, imperfect, and used after the fact — they do not proactively label content as AI-generated and often produce false positives or negatives.

50
Multi-Selecthard

A company is deploying a generative AI system that produces text content. To comply with emerging transparency obligations, which THREE measures should they implement?

Select 3 answers
A.Watermark AI-generated content
B.Disclose AI involvement to users
C.Encrypt all training data
D.Provide deepfake detection tools
E.Limit model access to internal employees only
AnswersA, B, D

Watermarking helps identify AI-generated content and is a transparency best practice.

Why this answer

Watermarking AI-generated content (Option A) is correct because it embeds an imperceptible, machine-detectable signal into the output, enabling provenance verification. This directly addresses transparency obligations by allowing downstream systems to identify synthetic text, which is a key requirement in emerging AI regulations such as the EU AI Act.

Exam trap

CompTIA often tests the distinction between security controls (encryption, access control) and governance/transparency measures, so candidates mistakenly select encryption or access restriction as fulfilling transparency obligations when they do not.

51
Multi-Selectmedium

A software company is developing an AI-powered code generation tool that suggests code snippets to developers. The company wants to align with the EU AI Act's transparency requirements. Which two actions should the company take? (Choose two.)

Select 2 answers
A.Provide documentation to developers about the AI system's capabilities and limitations
B.Publish the full training dataset used to train the code generation model
C.Ensure the AI system marks AI-generated code with a machine-readable watermark
D.Clearly disclose that the code suggestions are generated by an AI system and not by a human
E.Obtain explicit consent from every developer before they use the tool
AnswersA, D

The EU AI Act requires that providers of certain AI systems supply instructions for use, including information about the system's capabilities and limitations. For a code generation tool, documenting potential inaccuracies or biases helps developers use the tool responsibly and aligns with transparency obligations.

Why this answer

The EU AI Act's transparency obligations for AI systems that interact with users require clear disclosure that the user is interacting with an AI, and for providers to supply instructions for use that describe capabilities and limitations. For a code generation tool, informing developers that suggestions are AI-generated and documenting the tool's limitations fulfills these duties.

Exam trap

The trap here is conflating transparency with open-sourcing training data or obtaining consent, which are not required by the EU AI Act for this type of tool.

52
MCQhard

A hospital plans to deploy an AI system that analyzes patient data to predict the likelihood of hospital readmission. The system will be used to allocate post-discharge care resources. The hospital's ethics committee wants to ensure compliance with the EU AI Act's requirements for high-risk AI systems. Which practice is MOST critical for meeting the Act's human oversight requirements?

A.Ensuring that a qualified clinician can review and override the AI's recommendations before care resources are allocated
B.Requiring that the AI system's predictions are always followed to maintain consistency in care allocation
C.Publishing the AI system's algorithm in a peer-reviewed journal before deployment
D.Deploying the AI system only after it achieves 100% accuracy on historical readmission data
AnswerA

The EU AI Act requires high-risk AI systems to be designed with human oversight, enabling humans to effectively oversee, interpret, and override the system. For a readmission prediction tool, a clinician must be able to review and override recommendations to prevent harm. This ensures meaningful human control over decisions affecting patient care.

Why this answer

For high-risk AI systems, the EU AI Act mandates human oversight to ensure that humans can effectively monitor and intervene in the system's operation. In a hospital readmission prediction tool used for care allocation, a clinician must be able to review and override the AI's recommendations, preserving human judgment in decisions that affect patient health.

Exam trap

The trap here is equating human oversight with unattainable accuracy goals or public disclosure, rather than with the ability for a human to review and override the AI's decisions.

53
MCQmedium

An AI system trained on historical medical records shows that certain racial groups have higher predicted risk for a disease. The data reflects real-world differences in diagnosis rates due to unequal access to healthcare. Which type of bias is this?

A.Algorithmic bias
B.Selection bias
C.Historical bias
D.Confirmation bias
AnswerC

Historical bias arises when training data reflects past societal inequities, such as unequal healthcare access producing differing diagnosis rates. The model learns and reproduces those existing disparities, which is precisely the real-world diagnostic inequality described in the scenario.

Why this answer

Historical bias occurs when training data reflects pre-existing societal inequalities or biases, even if the data is accurately collected and representative. Here, the medical records show real-world differences in diagnosis rates due to unequal healthcare access, meaning the data itself encodes a historical inequity. The model learns and perpetuates this pattern, predicting higher risk for certain racial groups based on biased historical outcomes rather than true biological differences.

Thus, the bias is inherent in the data's origin, not in the algorithm or sampling method.

Exam trap

AI0-001 often tests the distinction between historical bias and other bias types by presenting a scenario where data accurately reflects real-world disparities, tempting candidates to choose algorithmic or selection bias when the root cause is societal inequity embedded in the data.

How to eliminate wrong answers

Option A is wrong because algorithmic bias refers to bias introduced by the algorithm's design, optimization, or implementation (e.g., flawed feature selection or proxy variables), not by the historical data itself. Option B is wrong because selection bias occurs when the data sample is not representative of the population, often due to non-random sampling or exclusion criteria; here, the data is representative of real-world diagnosis rates, so the bias is not from sample selection. Option D is wrong because confirmation bias is a cognitive bias where humans favor information that confirms their preexisting beliefs, not a bias in the data or model.

54
MCQhard

An AI model for skin cancer detection achieves high accuracy but performs poorly on dark skin tones. The team wants to evaluate whether the model is calibrated across skin tones. Which fairness metric should they use?

A.Equalised odds
B.Demographic parity
C.Individual fairness
D.Calibration
AnswerD

Calibration measures whether predicted probabilities match observed outcomes within each group, so comparing calibration curves across skin tones directly tests whether confidence scores are equally reliable. It isolates probability reliability, unlike equalised odds or demographic parity, which assess error or selection rates instead.

Why this answer

Calibration is the correct metric because it directly measures whether the predicted probabilities of skin cancer match the actual outcomes across different skin tones. A model can have high overall accuracy but be miscalibrated for a subgroup if its confidence scores are systematically over- or under-confident for that group. In this scenario, the team needs to check if the model's risk scores are equally reliable for dark skin tones as for light skin tones, which is exactly what calibration assesses.

Exam trap

The AI0-001 exam often tests the distinction between fairness metrics by presenting a scenario where 'accuracy' is high but subgroup performance differs, and candidates mistakenly choose equalized odds or demographic parity instead of recognizing that the core issue is confidence score reliability, i.e., calibration.

How to eliminate wrong answers

Option A is wrong because equalized odds requires that the true positive rate and false positive rate are equal across groups, which is a measure of error rate fairness, not calibration. Option B is wrong because demographic parity requires that the proportion of positive predictions is the same across groups, which can be achieved even if the model is poorly calibrated. Option C is wrong because individual fairness requires that similar individuals receive similar predictions, which is a different concept from group-level calibration across skin tones.

55
MCQmedium

A healthcare technology company is preparing to deploy an AI system that analyzes patient X-rays to detect early-stage lung cancer. The system is intended to be marketed as a medical device in the European Union. Under the EU AI Act, which classification and corresponding obligation apply to this system?

A.It is a limited-risk AI system and only needs to provide transparency notices to patients about its use.
B.It is a high-risk AI system and must comply with requirements for risk management, data governance, technical documentation, and human oversight before being placed on the market.
C.It is a minimal-risk AI system and can be deployed without any additional regulatory requirements beyond existing medical device regulations.
D.It is a prohibited AI system because it uses subliminal techniques to manipulate patient behavior.
AnswerB

AI systems intended to be used as safety components in the management and operation of critical digital infrastructure, or in medical devices, are explicitly listed in Annex III of the EU AI Act as high-risk. The company must therefore implement a risk management system, ensure data governance, maintain technical documentation, and provide for human oversight, among other obligations.

Why this answer

The EU AI Act classifies AI systems used in medical devices as high-risk under Annex III. This triggers a comprehensive set of obligations including risk management, data governance, technical documentation, and human oversight. The system is not prohibited, nor is it limited or minimal risk, because its output directly affects patient diagnosis and safety.

Exam trap

The trap here is assuming that because the AI is a medical device, it automatically falls under minimal risk or is exempt from the AI Act, when in fact medical AI is explicitly high-risk.

56
MCQeasy

A hospital wants to train a diagnostic model using patient data from multiple hospitals without sharing raw patient records. Which technique enables collaborative model training while keeping data decentralised?

A.Pseudonymisation
B.Differential privacy
C.Federated learning
D.Anonymisation
AnswerC

Federated learning trains a shared model across hospitals by exchanging only model updates or gradients, keeping raw patient records on each local site. This decentralised approach satisfies the requirement to collaborate without sharing patient data, unlike centralised training on pooled records.

Why this answer

Federated learning enables multiple parties to collaboratively train a shared model without exchanging raw data. Each hospital trains a local model on its own patient records, and only model updates (e.g., gradients or weights) are sent to a central server for aggregation. This keeps sensitive data decentralised and reduces privacy risks, making it the correct choice for collaborative training across hospitals.

Exam trap

AI0-001 often tests the confusion between privacy-preserving techniques (pseudonymisation, anonymisation, differential privacy) and collaborative training paradigms (federated learning), so candidates may pick a privacy method that does not enable decentralised model training.

How to eliminate wrong answers

Option A is wrong because pseudonymisation replaces direct identifiers with pseudonyms but still requires sharing the data, which does not enable decentralised training. Option B is wrong because differential privacy adds noise to data or outputs to protect individual privacy, but it does not by itself provide a collaborative training framework across multiple parties. Option D is wrong because anonymisation removes identifiers entirely, but the data must still be shared, and anonymisation alone does not support joint model training without centralising data.

57
MCQmedium

A company uses an AI system to screen job applicants. Under the GDPR, if the system makes automated decisions that have a legal or similarly significant effect on individuals, the data subject has the right to obtain an explanation of the decision. What is this right commonly called?

A.Right to erasure (right to be forgotten)
B.Right to explanation
C.Right to object
D.Right to data portability
AnswerB

Under GDPR Article 22, automated decisions producing legal or similarly significant effects entitle the data subject to meaningful information about the logic involved. This data subject right is commonly termed the right to explanation, satisfying the stem's requirement for an explanation of the decision.

Why this answer

Under GDPR Article 22, data subjects have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. Recital 71 and Article 13-15 collectively establish what is commonly called the 'right to explanation' — the right to obtain meaningful information about the logic involved, as well as the significance and envisaged consequences of the automated decision. This is the term used in the question stem.

Exam trap

AI0-001 often tests the confusion between GDPR data subject rights — candidates pick 'right to object' or 'right to erasure' because they sound relevant, but only the right to explanation specifically addresses automated decision-making transparency.

How to eliminate wrong answers

Option A is wrong because the right to erasure (Article 17) concerns deleting personal data when it is no longer necessary or processing is unlawful — it does not address automated decision-making explanations. Option C is wrong because the right to object (Article 21) allows data subjects to object to processing based on legitimate interests or direct marketing, not to demand an explanation of an automated decision. Option D is wrong because the right to data portability (Article 20) allows receiving personal data in a structured, machine-readable format and transmitting it to another controller — unrelated to explaining automated decisions.

58
Multi-Selecthard

A company is conducting a vendor AI assessment for a third-party natural language processing service. They need to ensure the vendor's AI governance practices align with their own. Which THREE areas should they evaluate?

Select 3 answers
A.The vendor's model architecture and training framework
B.The vendor's data handling and privacy practices
C.The vendor's marketing budget for AI services
D.The vendor's transparency documentation and model cards
E.The vendor's bias testing and fairness evaluation results
AnswersB, D, E

Data handling practices are critical for compliance and security.

Why this answer

Data handling and privacy practices are a core component of AI governance, ensuring that the vendor's use of customer data complies with regulations like GDPR or CCPA and aligns with the company's own data protection policies. During a vendor AI assessment, evaluating how the vendor collects, stores, processes, and secures data is critical to mitigate risks of data breaches, unauthorized use, or non-compliance, which directly impacts trust and legal liability.

Exam trap

Candidates often confuse technical performance metrics (like model architecture) with governance-specific evaluation areas (like transparency and bias testing), leading them to select options that sound relevant but fall outside the scope of AI governance during a vendor assessment.

59
MCQmedium

A company is required to disclose that content has been generated or significantly modified by AI. Which practice directly addresses this transparency obligation?

A.Applying AI watermarking
B.Using LIME for explanations
C.Implementing federated learning
D.Publishing a model card
AnswerA

AI watermarking embeds a detectable signal into generated content, enabling disclosure that material was AI-generated or modified. This directly satisfies the stem's transparency obligation, unlike consent, retention or accuracy controls that address different AI governance concerns.

Why this answer

AI watermarking directly addresses the transparency obligation by embedding a detectable signal into AI-generated content, enabling clear disclosure that the content was produced or significantly modified by AI. This practice aligns with regulatory requirements for provenance and traceability, as watermarks can be verified by automated systems or human inspection to confirm AI origin.

Exam trap

The AI0-001 exam often tests the distinction between transparency of content origin (watermarking) and model transparency (model cards) or interpretability (LIME), leading candidates to confuse documentation with active disclosure mechanisms.

How to eliminate wrong answers

Option B is wrong because LIME (Local Interpretable Model-agnostic Explanations) is a technique for explaining individual model predictions, not for disclosing AI-generated content; it addresses interpretability, not transparency of content origin. Option C is wrong because federated learning is a distributed training method that keeps data local to preserve privacy, and it has no mechanism for marking or disclosing AI-generated outputs. Option D is wrong because a model card documents a model's intended use, performance, and limitations, but it does not embed a disclosure signal into the content itself; it is a static document, not a dynamic transparency mechanism for generated outputs.

60
MCQmedium

A company deploys an AI resume screening tool. It learns from historical hiring data where most successful hires were male, leading the model to favour male candidates. Which type of bias is this primarily?

A.Historical bias
B.Confirmation bias
C.Algorithmic bias
D.Selection bias
AnswerA

Historical bias arises when training data reflects past societal inequities, so the model reproduces them. Here the historical hiring data over-represents male successes, and the model learns that pattern, favouring male candidates. This directly satisfies the stem's constraint: bias originating from skewed historical outcomes rather than sampling or labelling errors.

Why this answer

The model learned from historical hiring data that already contained a gender imbalance, where most successful hires were male. This is a classic case of historical bias, where the training data reflects past societal or organizational biases, and the AI system perpetuates those biases in its predictions. The bias originates in the data, not in the model's algorithm or the sampling method.

Exam trap

The CompTIA AI exam often tests the distinction between historical bias and algorithmic bias, where candidates mistakenly attribute the problem to the algorithm itself rather than recognizing that the bias was already present in the training data.

How to eliminate wrong answers

Option B (Confirmation bias) is wrong because confirmation bias is a human cognitive bias where people favor information that confirms their preexisting beliefs, not a data-driven bias in an AI model. Option C (Algorithmic bias) is wrong because algorithmic bias refers to bias introduced by the model's design, optimization function, or feature weighting, whereas here the bias stems from the training data itself. Option D (Selection bias) is wrong because selection bias occurs when the training data is not representative of the target population due to non-random sampling, but the problem states the model learned from historical hiring data that accurately reflected past decisions—the bias is in the outcomes, not the sampling process.

61
MCQmedium

A financial institution needs to deploy a credit scoring model that is interpretable to regulators. The model must provide clear reasons for each decision. Which model type should the institution choose?

A.A glass-box model such as logistic regression or a decision tree
B.A gradient-boosted tree ensemble with SHAP explanations
C.A black-box model with a model card describing its behavior
D.A deep neural network with LIME explanations
AnswerA

Glass-box models such as logistic regression and decision trees expose their internal decision logic, so each credit decision can be explained directly to regulators. This satisfies the interpretability constraint, unlike opaque neural networks or ensemble methods whose reasoning cannot be clearly justified.

Why this answer

A glass-box model such as logistic regression or a decision tree is inherently interpretable, meaning its internal decision logic can be directly examined and explained to regulators without post-hoc approximation. For credit scoring, regulators often require clear, auditable reasons for each decision (e.g., adverse action notices under ECOA/Regulation B), and glass-box models provide this natively. This makes them the correct choice when interpretability is a hard requirement.

Exam trap

AI0-001 often tests whether candidates equate post-hoc explanation tools (SHAP, LIME) with true interpretability — regulators in high-stakes domains typically require inherently interpretable models, not approximations.

How to eliminate wrong answers

Option B is wrong because gradient-boosted trees are ensemble models that are not inherently interpretable — SHAP provides post-hoc approximations that may not satisfy regulators requiring direct model transparency. Option C is wrong because a black-box model with a model card describes behavior at a high level but does not provide per-decision explanations, which regulators require. Option D is wrong because deep neural networks are black boxes, and LIME provides local approximations that can be unstable and are not considered sufficient for regulatory-grade interpretability in credit scoring.

62
MCQeasy

A data scientist needs to explain a single prediction from a complex ensemble model to a business stakeholder. Which technique generates local, interpretable explanations by perturbing input features and fitting a simple surrogate model?

A.LIME
B.Model card
C.SHAP
D.Attention visualisation
AnswerA

LIME perturbs individual input features around a single prediction and fits a sparse linear surrogate, producing a locally faithful, interpretable explanation. This satisfies the stem's requirement for local explanations of one ensemble prediction for a business stakeholder.

Why this answer

LIME (Local Interpretable Model-agnostic Explanations) explains individual predictions by perturbing inputs and learning a linear surrogate. SHAP provides Shapley values, which are also local but game-theoretic. Attention visualisation is for transformer models.

Model cards describe global model behaviour.

63
MCQhard

A retail company uses an AI system to dynamically adjust prices based on individual browsing behavior. The system occasionally offers different prices to different customers for the same product. A customer advocacy group raises concerns under the EU AI Act. Which statement BEST describes the compliance obligation?

A.The company must provide clear information about the use of AI for personalized pricing and ensure it does not exploit vulnerabilities of specific groups.
B.The company must obtain prior authorization from a national supervisory authority before deploying any AI system that adjusts prices.
C.The company must ensure the AI system does not use subliminal techniques to distort behavior, as such techniques are prohibited under the EU AI Act.
D.The company must publish the source code of the pricing algorithm to demonstrate compliance with the EU AI Act.
AnswerA

The EU AI Act requires transparency for AI systems that interact with people or generate content, and it prohibits exploiting vulnerabilities of age, disability, or social situations. Personalized pricing can exploit such vulnerabilities, so the company must disclose the AI use and avoid targeting susceptible groups unfairly.

Why this answer

The EU AI Act emphasizes transparency and prohibits AI systems from exploiting vulnerabilities of specific groups. Personalized pricing that adjusts based on browsing behavior can exploit economic or social vulnerabilities, so the company must clearly inform customers about the AI use and ensure it does not unfairly target protected groups.

Exam trap

The trap here is assuming that any AI-driven price adjustment is prohibited or requires prior regulatory approval, rather than recognizing that transparency and non-exploitation obligations apply.

64
Multi-Selectmedium

A data governance team is developing an AI policy for a large corporation. Which TWO elements are essential for a responsible AI governance framework?

Select 2 answers
A.GPU cluster monitoring
B.AI ethics board
C.Single-model strategy
D.Automated model retraining pipeline
E.Vendor AI assessment
AnswersB, E

An ethics board provides governance and oversight for AI development and deployment.

Why this answer

An AI ethics board is essential for a responsible AI governance framework because it provides human oversight, ethical review, and accountability for AI decisions. This board ensures that AI initiatives align with corporate values, legal requirements, and ethical principles, such as fairness, transparency, and non-discrimination. Without an ethics board, there is no formal mechanism to challenge biased models or approve high-risk AI use cases.

Exam trap

The AI0-001 exam often tests the distinction between operational/technical elements (like monitoring or retraining) and governance/ethics elements (like oversight boards and vendor assessments), so candidates mistakenly select technical options thinking they are part of governance.

65
Multi-Selectmedium

A research lab is training a large language model and wants to minimize its environmental impact. Which THREE practices are most effective for reducing the carbon footprint of model training?

Select 3 answers
A.Apply model compression techniques like pruning and quantization
B.Extend the number of training epochs to ensure convergence
C.Train the model on a data center powered by renewable energy
D.Use energy-efficient hardware such as TPUs or low-power GPUs
E.Increase the model size to achieve better accuracy faster
AnswersA, C, D

Compression reduces model size and inference cost, and can also reduce training energy.

Why this answer

Model compression techniques like pruning and quantization directly reduce the computational requirements of training and inference. Pruning removes redundant weights, and quantization reduces the precision of weights (e.g., from 32-bit to 8-bit), which lowers the number of operations and memory bandwidth needed, thereby decreasing energy consumption and carbon emissions.

Exam trap

A common pitfall is assuming that more training epochs or larger models always lead to better performance. However, extending epochs or increasing model size significantly raises energy consumption and carbon emissions, contradicting the goal of minimizing environmental impact.

66
MCQmedium

A healthcare AI startup is developing a diagnostic tool that uses patient data to predict disease risk. To comply with HIPAA and minimize privacy risks while still training accurate models, which privacy-preserving technique should they prioritize?

A.Anonymization
B.Pseudonymization
C.Differential privacy
D.Data minimization
AnswerC

Differential privacy adds calibrated noise to training data or outputs, mathematically bounding any single patient's contribution. This satisfies HIPAA's privacy constraint while preserving aggregate statistical utility, unlike encryption or anonymisation, which either hinder training or remain vulnerable to re-identification.

Why this answer

Differential privacy is the correct choice because it provides a formal mathematical guarantee that the output of a model does not reveal whether any individual's data was included in the training set. This is essential for HIPAA compliance as it prevents re-identification attacks even when an adversary has auxiliary information. Unlike anonymization or pseudonymization, differential privacy adds calibrated noise to the training process or query results, ensuring strong privacy protection while preserving model utility.

Exam trap

The AI0-001 exam often tests the misconception that anonymization or pseudonymization are sufficient for HIPAA compliance in AI contexts, but the trap here is that these techniques do not protect against inference attacks or re-identification in high-dimensional data, whereas differential privacy provides a provable mathematical guarantee.

How to eliminate wrong answers

Option A is wrong because anonymization, while removing direct identifiers, is vulnerable to re-identification attacks through data linkage and does not provide a formal privacy guarantee; it is not sufficient for HIPAA compliance in high-dimensional patient data. Option B is wrong because pseudonymization replaces identifiers with pseudonyms but still allows re-identification if the pseudonym mapping is compromised or through cross-referencing, and it does not prevent inference attacks on the model's outputs. Option D is wrong because data minimization reduces the amount of data collected but does not protect the privacy of the data that is used; it is a complementary practice, not a privacy-preserving technique for training models.

67
MCQmedium

An organisation is deploying an AI system for credit scoring, which is considered high-risk under the EU AI Act. Which requirement is NOT typically mandated for high-risk systems?

A.Ensure training data is relevant and representative
B.Publish the complete source code of the AI system
C.Establish a risk management system
D.Provide human oversight mechanisms
AnswerB

The EU AI Act mandates risk management, data governance, technical documentation, logging, human oversight and accuracy, but not source code publication. Releasing complete source code is a transparency choice, not a legal obligation, so it is not typically required for high-risk systems.

Why this answer

The EU AI Act mandates several requirements for high-risk AI systems, including risk management, data governance (relevant and representative training data), technical documentation, transparency, human oversight, and accuracy/robustness. Publishing the complete source code is not a typical requirement; the Act focuses on transparency and documentation, not open-sourcing proprietary code. Therefore, option B is the requirement that is NOT typically mandated.

Exam trap

The trap is assuming that transparency under the EU AI Act means publishing source code; candidates may confuse transparency with open-source requirements.

How to eliminate wrong answers

Option A is wrong because ensuring training data is relevant and representative is a core data governance requirement for high-risk AI under the EU AI Act. Option C is wrong because establishing a risk management system is explicitly required for high-risk AI systems. Option D is wrong because providing human oversight mechanisms is a mandated requirement for high-risk AI systems.

68
MCQmedium

During an audit of an AI system, the auditor requests documentation on the model's intended use, performance metrics, and limitations. Which tool is designed to provide this information in a standardized format?

A.SHAP values
B.LIME
C.Model card
D.Data card
AnswerC

A model card is the standardised artefact documenting a model's intended use, performance metrics and limitations, directly satisfying the auditor's request. Unlike datasheets, which describe training datasets, model cards address the deployed model itself, giving the transparency evidence required for AI governance audits.

Why this answer

A model card is a standardized document that describes a model's intended use, performance metrics, limitations, ethical considerations, and other relevant details. It is specifically designed to provide transparency and accountability documentation for AI models, matching the auditor's request. Model cards were popularized by Google and are now a common governance artifact.

Exam trap

AI0-001 often tests the confusion between explainability techniques (SHAP, LIME) and documentation artifacts (model cards, data cards) — candidates must recognize that the auditor is asking for standardized documentation, not a prediction-explanation method.

How to eliminate wrong answers

Option A is wrong because SHAP values are a technique for explaining individual predictions by attributing feature contributions, not a documentation format for model metadata. Option B is wrong because LIME is a local interpretability method that approximates model behavior around a single prediction, not a standardized documentation tool. Option D is wrong because a data card documents a dataset's provenance, composition, and characteristics, not the model's intended use and performance metrics.

69
MCQmedium

A health-tech firm is preparing a model card for a clinical decision support tool that flags patients at risk of sepsis. The compliance team asks which element of the model card is MOST directly relevant to documenting the system's intended use and out-of-scope applications. Which section should the team prioritize?

A.The 'Performance Metrics' section, which reports AUROC, sensitivity, and specificity at the deployed decision threshold.
B.The 'Training Data' section, which lists the source datasets, their collection dates, and demographic composition.
C.The 'Intended Use' section, which specifies the clinical populations, care settings, and decision boundaries for which the model was validated.
D.The 'Ethical Considerations' section, which discusses potential harms and mitigation strategies identified during review.
AnswerC

This section is the authoritative declaration of the model's scope. It records which patient populations, care environments, and decision types were validated, and explicitly lists out-of-scope uses such as autonomous diagnosis without clinician review. Without this, downstream users cannot judge whether deploying the tool in a new setting is appropriate, so it is the most directly relevant element for the compliance question.

Why this answer

A model card's intended use section is the formal declaration of the validated operating envelope: the populations, settings, and decision types the model supports, plus explicitly excluded uses. Compliance reviewers rely on it to confirm that a proposed deployment falls inside the validated scope. Training data, performance metrics, and ethical considerations are supporting evidence but do not define the boundary of appropriate use.

Exam trap

The trap here is assuming that strong performance metrics or ethical review notes substitute for an explicit intended-use statement, when scope must be declared separately.

70
MCQeasy

A company is deploying an AI system that screens job applications. According to the EU AI Act, this system is likely classified as high-risk because it affects employment opportunities. Which requirement must the company implement for high-risk AI systems?

A.A human-in-the-loop mechanism that enables override of the AI's decisions
B.Full transparency by publishing the model's source code and training data
C.Annual third-party audits of the model's energy consumption
D.Obtaining explicit consent from each applicant to process their data
AnswerA

High-risk AI systems under the EU AI Act require human oversight, so a human-in-the-loop mechanism allowing override of screening decisions satisfies this. It ensures employment outcomes remain subject to meaningful human review rather than automated determination.

Why this answer

Under the EU AI Act, high-risk AI systems must implement appropriate human oversight measures, including human-in-the-loop mechanisms that allow humans to override or intervene in the AI's decisions. This is a key requirement to ensure accountability and prevent harm in critical areas like employment.

Exam trap

AI0-001 often tests the specific requirements for high-risk AI systems, and candidates may confuse GDPR consent requirements with EU AI Act obligations, or think transparency means publishing source code.

How to eliminate wrong answers

Option B is wrong because full transparency by publishing source code and training data is not a mandatory requirement for high-risk AI systems; the Act requires transparency obligations but not to that extent, and it may conflict with intellectual property. Option C is wrong because annual third-party audits of energy consumption are not specified in the EU AI Act; while there are requirements for conformity assessments, energy consumption audits are not a core requirement. Option D is wrong because obtaining explicit consent from each applicant is a GDPR requirement for data processing, not a specific requirement for high-risk AI systems under the EU AI Act, though data protection laws still apply.

71
MCQhard

A researcher is developing a generative AI model that creates realistic images. To comply with emerging transparency obligations, the researcher must ensure that AI-generated content can be identified as such. Which technique embeds a digital identifier directly into the content that survives compression and cropping?

A.Model cards
B.Watermarking AI-generated content
C.Deepfake detection software
D.Disclosure statements in metadata
AnswerB

Watermarking embeds a robust, imperceptible signal directly into the image pixels, so the identifier persists through compression and cropping—exactly the durability the stem demands. Unlike metadata tagging, which is stripped by re-encoding, watermarking binds provenance to the content itself, satisfying transparency obligations for AI-generated media.

Why this answer

Watermarking embeds a persistent digital identifier directly into the pixel data of an image, using techniques like spread-spectrum or discrete wavelet transform to survive common transformations such as JPEG compression and cropping. This makes it the correct technique for ensuring AI-generated content remains identifiable even after editing or distribution.

Exam trap

CompTIA tests the distinction between passive metadata (which is fragile) and active content-level embedding (which is resilient), leading candidates to mistakenly choose disclosure statements in metadata because they confuse 'digital identifier' with 'metadata field'.

How to eliminate wrong answers

Option A is wrong because model cards are documentation artifacts that describe a model's intended use, performance, and limitations, not a technique for embedding identifiers into content. Option C is wrong because deepfake detection software analyzes content after the fact to identify manipulation, but does not embed a persistent identifier into the content itself. Option D is wrong because disclosure statements in metadata (e.g., EXIF or XMP fields) are easily stripped or altered during compression, cropping, or re-encoding, and do not survive as robustly as a watermark embedded in the pixel data.

72
MCQmedium

A data scientist is using SHAP to explain a complex ensemble model's predictions. A business stakeholder asks why a particular prediction was made. The data scientist wants to show the most influential features for that single prediction. Which SHAP visualisation is most appropriate?

A.A SHAP summary plot showing mean absolute SHAP values across all features
B.A SHAP dependence plot for the top feature
C.A SHAP bar chart of absolute feature importance
D.A SHAP force plot for the individual prediction
AnswerD

A force plot displays the push and pull each feature exerts on one specific prediction, showing magnitude and direction for that single case. It satisfies the stakeholder's request for the most influential features behind an individual outcome, unlike global summary plots.

Why this answer

A SHAP force plot is specifically designed to visualize the contribution of each feature to a single prediction, showing how features push the prediction from the base value (average model output) to the final prediction. This makes it the ideal choice for explaining an individual prediction to a business stakeholder, as it provides a clear, localized explanation of feature impacts.

Exam trap

CompTIA often tests the distinction between global vs. local interpretability, and the trap here is that candidates confuse summary plots (global) or dependence plots (global) with force plots (local), leading them to choose a globally-focused visualization for a single-prediction explanation.

How to eliminate wrong answers

Option A is wrong because a SHAP summary plot shows global feature importance across all predictions (mean absolute SHAP values), not the contribution of features for a single prediction. Option B is wrong because a SHAP dependence plot shows how the value of a single feature affects the model's output across the dataset, not the feature contributions for a specific prediction. Option C is wrong because a SHAP bar chart of absolute feature importance aggregates feature importance globally, ignoring the direction and magnitude of feature contributions for an individual instance.

73
MCQhard

An AI team is developing a model that approves loan applications. The dataset contains historical loan decisions where a protected group was disproportionately denied loans. The team wants to ensure the model does not perpetuate this bias. Which fairness metric should be used during validation to directly measure whether the model's positive prediction rate is equal across groups?

A.Demographic parity
B.Calibration
C.Individual fairness
D.Equalised odds
AnswerA

Demographic parity compares the positive prediction rate between groups, directly quantifying whether approval rates are equal regardless of protected attributes. This matches the requirement to measure equal positive prediction rates across groups, exposing the historical denial disparity.

Why this answer

Demographic parity (also called statistical parity) directly measures whether the positive prediction rate is equal across groups. It is the fairness metric that compares the proportion of positive outcomes for each protected group, which aligns with the requirement to measure equal positive prediction rates.

Exam trap

AI0-001 often tests the confusion between demographic parity and equalised odds — candidates must remember that demographic parity only looks at positive prediction rates, while equalised odds also considers true and false positive rates.

How to eliminate wrong answers

Option B is wrong because calibration measures whether predicted probabilities match actual outcomes within groups, not whether positive prediction rates are equal. Option C is wrong because individual fairness focuses on treating similar individuals similarly, not on group-level positive rates. Option D is wrong because equalised odds requires equal true positive and false positive rates across groups, which is a different condition than equal positive prediction rates.

74
MCQmedium

An AI system is being deployed to detect deepfakes in video content. To comply with transparency obligations, what should the company implement?

A.A system to automatically block all deepfake content
B.A visible or invisible watermark on AI-generated videos
C.A process to report deepfake content to law enforcement
D.Encryption of the video files to prevent tampering
AnswerB

Watermarking embeds a detectable marker in AI-generated video, letting viewers and automated systems identify synthetic content. This satisfies the transparency obligation by making the artificial origin of deepfake videos disclosable and verifiable, rather than relying on post-hoc detection alone.

Why this answer

Transparency obligations under AI governance frameworks (e.g., EU AI Act) require clear disclosure when content is AI-generated. A visible or invisible watermark directly informs viewers that the video is synthetic, fulfilling this requirement without over-blocking legitimate content. Option B is correct because it provides a verifiable, non-disruptive method of labeling AI-generated media.

Exam trap

CompTIA AI+ certification often tests the distinction between transparency (disclosure) and security (blocking, encryption, reporting), leading candidates to confuse a governance obligation with a technical control like blocking or encryption.

How to eliminate wrong answers

Option A is wrong because automatically blocking all deepfake content would violate freedom of expression and could suppress legitimate AI-generated art, satire, or educational material; transparency does not mandate censorship. Option C is wrong because reporting to law enforcement is a reactive, post-hoc measure that does not satisfy the proactive transparency obligation to label content at the point of consumption. Option D is wrong because encryption protects integrity and confidentiality but does not disclose the synthetic origin of the content to viewers, thus failing the transparency requirement.

75
Multi-Selectmedium

A data scientist is using LIME to explain a black-box model. Which TWO characteristics of LIME are true?

Select 2 answers
A.It provides a measure of model confidence in its prediction
B.It requires access to the model's internal parameters
C.It provides a global ranking of feature importance across the entire dataset
D.It creates an interpretable surrogate model locally around a prediction
E.It can be used with any machine learning model
AnswersD, E

LIME fits an interpretable surrogate model, such as a sparse linear model, on samples generated locally around the instance being explained. This satisfies the stem's constraint because the approximation is faithful only near that prediction, not globally across the model.

Why this answer

Option D is correct because LIME (Local Interpretable Model-agnostic Explanations) works by perturbing the input around a specific prediction and fitting a simple, interpretable surrogate model (such as a linear model or decision tree) that approximates the black-box model's behavior in that local neighborhood. Option E is correct because LIME is model-agnostic: it only requires the ability to query the model's predictions (input-output access), so it can be applied to any machine learning model, including neural networks, SVMs, and gradient-boosted trees. Option A is not correct because LIME explains which features drove a prediction, not the model's confidence or probability calibration.

Option B is not correct because LIME treats the model as a black box and does not need internal parameters or gradients. Option C is not correct because LIME produces local explanations for individual predictions, not a global feature-importance ranking across the entire dataset.

Exam trap

AI0-001 often tests the distinction between local and global explanation methods, and candidates may mistakenly think LIME provides global feature importance or requires model internals.

Page 1 of 2 · 81 questions totalNext →

Ready to test yourself?

Try a timed practice session using only AI Governance and Ethics questions.