Courseiva

AI0-001 AI Security, Ethics and Governance Practice Question

Exhibit

[security]
enable_model_encryption = false
enable_input_sanitization = true
enable_adversarial_defense = false
audit_level = basic
[privacy]
data_minimization = enabled
pii_detection = enabled
[governance]
fairness_audit = quarterly

Refer to the exhibit. A security auditor identifies a critical vulnerability that could allow an attacker to manipulate model inputs to cause misclassification. Which configuration setting is most directly responsible for this vulnerability?

⚠ Common exam trap

The AI0-001 exam often tests the distinction between input sanitization (which handles malformed or malicious data) and adversarial defense (which specifically counters perturbation-based attacks), causing candidates to mistakenly choose input sanitization as the answer.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

enable_adversarial_defense = false

The vulnerability described is an adversarial attack on model inputs, which directly exploits the absence of adversarial defenses. Setting `enable_adversarial_defense = false` disables mechanisms like adversarial training or input perturbation detection that prevent misclassification from manipulated inputs. This configuration is the most direct root cause because it explicitly turns off the defense designed to counter such attacks.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    enable_input_sanitization = true

    Why it's wrong here

    Enabling input sanitisation mitigates injection and malformed-input attacks; it does not cause misclassification. The vulnerability stems from the model's own robustness configuration, such as an unvalidated or adversarially exposed inference endpoint. Sanitisation is the correct control when untrusted user input reaches a model, but here it is the safeguard, not the flaw.

  • ✗

    audit_level = basic

    Why it's wrong here

    Audit level controls how much request and response detail is logged for compliance; it does not filter or harden model inputs, so adversarial examples still reach the model. It is tempting because auditing supports incident investigation, and would be correct when the requirement is forensic traceability rather than input validation.

  • ✓

    enable_adversarial_defense = false

    Why this is correct

    Disabling adversarial defence removes the input-perturbation filtering that detects and sanitises crafted samples before inference, so manipulated inputs reach the model unchecked and cause misclassification. This setting directly governs the vulnerability the auditor identified, whereas other options address access control or data handling rather than input integrity.

  • ✗

    pii_detection = enabled

    Why it's wrong here

    PII detection scans inputs for sensitive data such as names or card numbers; it does not validate or sanitise model inputs against adversarial perturbation. It is tempting because it is a security-oriented setting, and would be correct when the requirement is redacting or flagging personal data in prompts and responses.

About these practice questions

One of 962 original AI0-001 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.