AI0-001 AI Security, Ethics and Governance Practice Question
During a red-team exercise on an AI model, testers successfully extracted training data. Which vulnerability is this?
⚠ Common exam trap
The AI0-001 exam often tests the distinction between 'extracting data' (model inversion) and 'inferring presence' (membership inference), so candidates mistakenly choose membership inference when the question explicitly states data was extracted.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Model inversion
Model inversion attacks allow an adversary to reconstruct training data by exploiting the model's learned representations. In this scenario, the testers successfully extracted training data, which is the hallmark of a model inversion attack, not just inferring membership.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Membership inference
Why it's wrong here
Membership inference determines whether a specific record was part of the training set; it does not reconstruct the record's contents. Extracting training data is training data extraction, a distinct attack. Membership inference is the right classification when the goal is confirming an individual's inclusion, not recovering the data itself.
- ✓
Model inversion
Why this is correct
Model inversion reconstructs training-set samples by querying the model's outputs, directly satisfying the stem's constraint of extracted training data. Unlike membership inference, which only determines whether a record was used, inversion recovers actual feature values, making it the precise vulnerability demonstrated during this red-team exercise.
- ✗
Adversarial example
Why it's wrong here
Adversarial examples are perturbed inputs crafted to cause misclassification at inference time; they do not recover memorised training records. Extracting training data is training data extraction. Adversarial examples would be the correct classification for a scenario describing manipulated inputs producing wrong predictions, not data recovery.
- ✗
Data poisoning
Why it's wrong here
Data poisoning corrupts training inputs to skew model behaviour, so it cannot describe an attack that reads data out of a trained model. It is tempting because both are training-phase threats, and poisoning would be the answer if testers had injected malicious samples to degrade or backdoor the model's predictions.
About these practice questions
Courseiva writes every AI0-001 question from scratch — 962 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.