AI0-001 AI Security, Ethics and Governance Practice Question
Exhibit
[security] enable_model_encryption = false enable_input_sanitization = true enable_adversarial_defense = false audit_level = basic [privacy] data_minimization = enabled pii_detection = enabled [governance] fairness_audit = quarterly
Refer to the exhibit. A security auditor identifies a critical vulnerability that could allow an attacker to manipulate model inputs to cause misclassification. Which configuration setting is most directly responsible for this vulnerability?
⚠ Common exam trap
The AI0-001 exam often tests the distinction between input sanitization (which handles malformed or malicious data) and adversarial defense (which specifically counters perturbation-based attacks), causing candidates to mistakenly choose input sanitization as the answer.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
enable_adversarial_defense = false
The vulnerability described is an adversarial attack on model inputs, which directly exploits the absence of adversarial defenses. Setting `enable_adversarial_defense = false` disables mechanisms like adversarial training or input perturbation detection that prevent misclassification from manipulated inputs. This configuration is the most direct root cause because it explicitly turns off the defense designed to counter such attacks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
enable_input_sanitization = true
Why it's wrong here
Enabling input sanitisation mitigates injection and malformed-input attacks; it does not cause misclassification. The vulnerability stems from the model's own robustness configuration, such as an unvalidated or adversarially exposed inference endpoint. Sanitisation is the correct control when untrusted user input reaches a model, but here it is the safeguard, not the flaw.
- ✗
audit_level = basic
Why it's wrong here
Audit level controls how much request and response detail is logged for compliance; it does not filter or harden model inputs, so adversarial examples still reach the model. It is tempting because auditing supports incident investigation, and would be correct when the requirement is forensic traceability rather than input validation.
- ✓
enable_adversarial_defense = false
Why this is correct
Disabling adversarial defence removes the input-perturbation filtering that detects and sanitises crafted samples before inference, so manipulated inputs reach the model unchecked and cause misclassification. This setting directly governs the vulnerability the auditor identified, whereas other options address access control or data handling rather than input integrity.
- ✗
pii_detection = enabled
Why it's wrong here
PII detection scans inputs for sensitive data such as names or card numbers; it does not validate or sanitise model inputs against adversarial perturbation. It is tempting because it is a security-oriented setting, and would be correct when the requirement is redacting or flagging personal data in prompts and responses.
About these practice questions
One of 962 original AI0-001 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.