AI0-001 · topic practice
Operating Systems practice questions
Practise CompTIA AI+ AI0-001 Operating Systems practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.
What the exam tests
What to know about Operating Systems
Operating Systems questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common Operating Systems exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Practice set
Operating Systems questions
20 questions · select your answer, then reveal the explanation
An AI team is deploying a fine-tuned LLM for a code generation assistant. They need to ensure the model outputs only syntactically valid JSON for integration with downstream systems. Which prompt engineering technique is MOST effective for enforcing structured output?
Trap 1: Provide a few-shot example of a valid JSON response in the prompt
A single few-shot example demonstrates format but does not guarantee every response parses as JSON; the model may still emit prose or malformed brackets. Few-shot prompting is the right choice when teaching a task pattern or style, not when downstream systems require guaranteed syntactic validity.
Trap 2: Include a system prompt that says 'You are a helpful coding…
A persona instruction sets tone and role, not output syntax; it cannot constrain token generation to valid JSON. It is tempting because system prompts do steer behaviour, and this one would be the right choice when the goal is shaping a general assistant's helpfulness rather than enforcing a machine-readable schema.
Trap 3: Use chain-of-thought prompting to have the model reason…
Chain-of-thought elicits intermediate reasoning tokens, which typically appear in the output and break JSON parsing. It is the right choice when the task needs multi-step arithmetic or logic, not when the requirement is a strictly parseable structured payload.
- A
Enable JSON mode in the API call, specifying the desired JSON schema
JSON mode constrains decoding to emit only tokens forming valid JSON, and the supplied schema further restricts keys, types and nesting. This guarantees syntactic validity at generation time, satisfying the downstream integration constraint that raw prompt instructions alone cannot reliably enforce.
- B
Provide a few-shot example of a valid JSON response in the prompt
Why it fails: A single few-shot example demonstrates format but does not guarantee every response parses as JSON; the model may still emit prose or malformed brackets. Few-shot prompting is the right choice when teaching a task pattern or style, not when downstream systems require guaranteed syntactic validity.
- C
Include a system prompt that says 'You are a helpful coding assistant.'
Why it fails: A persona instruction sets tone and role, not output syntax; it cannot constrain token generation to valid JSON. It is tempting because system prompts do steer behaviour, and this one would be the right choice when the goal is shaping a general assistant's helpfulness rather than enforcing a machine-readable schema.
- D
Use chain-of-thought prompting to have the model reason step-by-step before answering
Why it fails: Chain-of-thought elicits intermediate reasoning tokens, which typically appear in the output and break JSON parsing. It is the right choice when the task needs multi-step arithmetic or logic, not when the requirement is a strictly parseable structured payload.
A healthcare AI system is subject to GDPR because it processes patient data. Which THREE requirements must the system satisfy?
Trap 1: Explicit consent from all data subjects
Consent is not always required; other legal bases may apply.
Trap 2: Data retention period of at least 10 years
Retention periods vary; no universal 10-year requirement.
- A
Right to explanation of decisions
Article 22 and Recital 71 provide a right to explanation for automated decisions.
- B
Explicit consent from all data subjects
Why it fails: Consent is not always required; other legal bases may apply.
- C
Meaningful information about the logic involved in automated decision-making
GDPR requires transparency about how decisions are made.
- D
Data minimization principles
GDPR requires that only necessary data be processed.
- E
Data retention period of at least 10 years
Why it fails: Retention periods vary; no universal 10-year requirement.
A company deploys a machine learning model that makes predictions on streaming data. Over time, the data distribution shifts, causing model performance to degrade. Which monitoring strategy is most appropriate to detect this drift?
Trap 1: Compare the distribution of predictions to the training set
Prediction distribution comparison can indicate shift but is less reliable than performance metrics.
Trap 2: Monitor the model's training loss
Training loss can stay low even if the underlying data distribution changes.
Trap 3: Retrain the model daily on new data
Retraining is a remedy, not a monitoring method for detecting drift.
- A
Compare the distribution of predictions to the training set
Why it fails: Prediction distribution comparison can indicate shift but is less reliable than performance metrics.
- B
Monitor the model's training loss
Why it fails: Training loss can stay low even if the underlying data distribution changes.
- C
Retrain the model daily on new data
Why it fails: Retraining is a remedy, not a monitoring method for detecting drift.
- D
Track the model's accuracy on a fixed validation set over time
Accuracy drop on a static validation set indicates concept drift.
A company is deploying a generative AI system that produces text content. To comply with emerging transparency obligations, which THREE measures should they implement?
Trap 1: Encrypt all training data
Encryption is a security measure, not a transparency obligation.
Trap 2: Limit model access to internal employees only
Access control is about security and privacy, not transparency.
- A
Watermark AI-generated content
Watermarking helps identify AI-generated content and is a transparency best practice.
- B
Disclose AI involvement to users
Users should be informed when they are interacting with AI-generated content.
- C
Encrypt all training data
Why it fails: Encryption is a security measure, not a transparency obligation.
- D
Provide deepfake detection tools
Detection tools help verify authenticity and meet transparency requirements.
- E
Limit model access to internal employees only
Why it fails: Access control is about security and privacy, not transparency.
A hospital uses an AI system to prioritize patient triage based on vital signs and medical history. During a trial, the system consistently assigns lower urgency to elderly patients with chronic conditions, even when their symptoms suggest high risk. Which approach best addresses this bias?
Trap 1: Use a different dataset from a similar hospital without checking…
Swapping datasets without demographic checks risks importing the same or different bias, leaving the elderly under-triage unresolved. A different hospital's data suits expanding coverage or validating generalisation, but only after auditing representation and label distributions against the target population.
Trap 2: Manually increase the weight of age-related features in the model
Manually upweighting age features amplifies the spurious correlation rather than removing it, pushing predictions further from clinical risk. Feature weighting suits deliberate emphasis of known predictive signals, but here the bias stems from historical data and proxy features that must be rebalanced.
Trap 3: Replace the neural network with a decision tree to simplify…
Swapping the neural network for a decision tree changes the model class, not the training data or labels encoding age-related assumptions, so the learned disparity persists. Decision trees suit scenarios needing interpretable, rule-based logic over tabular data, but bias mitigation requires auditing and rebalancing the dataset or applying fairness constraints.
- A
Use a different dataset from a similar hospital without checking demographics
Why it fails: Swapping datasets without demographic checks risks importing the same or different bias, leaving the elderly under-triage unresolved. A different hospital's data suits expanding coverage or validating generalisation, but only after auditing representation and label distributions against the target population.
- B
Manually increase the weight of age-related features in the model
Why it fails: Manually upweighting age features amplifies the spurious correlation rather than removing it, pushing predictions further from clinical risk. Feature weighting suits deliberate emphasis of known predictive signals, but here the bias stems from historical data and proxy features that must be rebalanced.
- C
Replace the neural network with a decision tree to simplify decision logic
Why it fails: Swapping the neural network for a decision tree changes the model class, not the training data or labels encoding age-related assumptions, so the learned disparity persists. Decision trees suit scenarios needing interpretable, rule-based logic over tabular data, but bias mitigation requires auditing and rebalancing the dataset or applying fairness constraints.
- D
Audit the training data for representation of elderly patients and retrain with balanced data
Auditing the training data for representation of elderly patients directly addresses the dataset bias causing the system to deprioritise this group. Retraining with balanced data corrects the skewed distribution of chronic-condition cases, satisfying the fairness constraint that the AI must not systematically discriminate based on age. This approach ensures the model learns genuine risk patterns rather than spurious correlations from under-represented subgroups.
Which THREE factors are common causes of bias in AI systems?
Trap 1: Cross-validation
Cross-validation is a method to evaluate models, not a cause of bias.
Trap 2: High regularization
Regularization reduces variance, not bias.
- A
Cross-validation
Why it fails: Cross-validation is a method to evaluate models, not a cause of bias.
- B
Lack of diversity in the development team
Homogeneous teams may overlook biased assumptions.
- C
Unrepresentative training sample
If sample doesn't reflect population, model will be biased.
- D
Biased historical data used for training
Historical biases can be learned by the model.
- E
High regularization
Why it fails: Regularization reduces variance, not bias.
A company wants to build a conversational agent that can handle complex multi-step tasks such as booking a flight, reserving a hotel, and scheduling a car rental in a single session. The agent must be able to break down the user's request into sub-tasks, call external APIs, and reason about the results. Which design pattern is BEST suited for this requirement?
Trap 1: Retrieval-Augmented Generation (RAG) with a vector store
RAG retrieves documents from a vector store to ground responses in source content; it provides no mechanism for decomposing goals, sequencing API calls, or reasoning over their outputs. It is tempting because RAG is the right pattern when answers must cite internal knowledge rather than orchestrate external actions.
Trap 2: A single large language model prompt with all instructions
A single prompt cannot iteratively decompose tasks, invoke external APIs, and reason over returned results across turns; it produces one static completion. It is tempting because a monolithic prompt suffices for straightforward single-shot generation, such as summarising text or answering a self-contained question.
Trap 3: Fine-tuning a model on a dataset of flight, hotel, and rental…
Fine-tuning adapts a model's weights to a conversational style or domain, but it adds no mechanism for decomposing tasks, invoking external APIs or reasoning over their results. It tempts when domain-specific tone is the goal. A tool-use or agent pattern provides that orchestration.
- A
Retrieval-Augmented Generation (RAG) with a vector store
Why it fails: RAG retrieves documents from a vector store to ground responses in source content; it provides no mechanism for decomposing goals, sequencing API calls, or reasoning over their outputs. It is tempting because RAG is the right pattern when answers must cite internal knowledge rather than orchestrate external actions.
- B
An agentic workflow implementing the ReAct pattern with tool use
ReAct interleaves reasoning traces with tool calls, letting the agent decompose the request, invoke flight, hotel and car APIs, then reason over each result before the next step. This satisfies the multi-step, external-API constraint that a single prompt or plain chain cannot handle.
- C
A single large language model prompt with all instructions
Why it fails: A single prompt cannot iteratively decompose tasks, invoke external APIs, and reason over returned results across turns; it produces one static completion. It is tempting because a monolithic prompt suffices for straightforward single-shot generation, such as summarising text or answering a self-contained question.
- D
Fine-tuning a model on a dataset of flight, hotel, and rental conversations
Why it fails: Fine-tuning adapts a model's weights to a conversational style or domain, but it adds no mechanism for decomposing tasks, invoking external APIs or reasoning over their results. It tempts when domain-specific tone is the goal. A tool-use or agent pattern provides that orchestration.
A company is building a recommendation system that uses user embeddings stored in a vector database. The system must retrieve the top 10 most similar items for a given user query. Which vector database feature is MOST critical for this task?
Trap 1: Built-in data versioning
Data versioning tracks changes to datasets and embeddings over time, supporting reproducibility and rollback rather than query-time similarity ranking. It is tempting because versioning matters when embeddings are regenerated, but the requirement is retrieving the top 10 nearest neighbours, which depends on vector indexing and distance metrics.
Trap 2: ACID transaction support
ACID transactions guarantee atomic, consistent writes across records, which matters for concurrent updates but not for similarity ranking. It is tempting because transactional integrity sounds essential for production databases, yet top-10 retrieval depends on vector indexing and distance metrics, not on transactional write semantics.
Trap 3: SQL query interface
A SQL interface supports structured filtering and joins, not approximate nearest-neighbour ranking over high-dimensional embeddings. It is tempting because SQL is familiar for querying stored data, but top-10 similarity retrieval depends on vector indexing and distance metrics such as cosine or Euclidean search, which SQL alone does not provide.
- A
Built-in data versioning
Why it fails: Data versioning tracks changes to datasets and embeddings over time, supporting reproducibility and rollback rather than query-time similarity ranking. It is tempting because versioning matters when embeddings are regenerated, but the requirement is retrieving the top 10 nearest neighbours, which depends on vector indexing and distance metrics.
- B
ACID transaction support
Why it fails: ACID transactions guarantee atomic, consistent writes across records, which matters for concurrent updates but not for similarity ranking. It is tempting because transactional integrity sounds essential for production databases, yet top-10 retrieval depends on vector indexing and distance metrics, not on transactional write semantics.
- C
Approximate nearest neighbor (ANN) search
Approximate nearest neighbour search indexes embeddings so the top 10 most similar items are retrieved without comparing every vector. This satisfies the low-latency similarity requirement, which exact brute-force comparison across a large embedding store cannot meet at scale.
- D
SQL query interface
Why it fails: A SQL interface supports structured filtering and joins, not approximate nearest-neighbour ranking over high-dimensional embeddings. It is tempting because SQL is familiar for querying stored data, but top-10 similarity retrieval depends on vector indexing and distance metrics such as cosine or Euclidean search, which SQL alone does not provide.
A financial institution is deploying an AI system to approve personal loans. To comply with the EU AI Act's high-risk AI requirements, the bank must ensure meaningful human oversight. Which implementation BEST satisfies this requirement?
Trap 1: Use a separate AI model to audit the primary AI's decisions weekly
Auditing by another model replaces one automated decision with two, leaving no human in the loop, which the EU AI Act's oversight requirement demands. Model-based auditing suits ongoing quality assurance and drift detection, not the human review of individual high-risk decisions.
Trap 2: Allow applicants to appeal AI decisions through a customer service…
Appeals occur after an adverse decision, so they provide redress rather than oversight of the decision itself; the EU AI Act requires human oversight during operation, such as a human reviewing or overriding outputs before they take effect. Appeals suit post-hoc dispute resolution, not real-time control of a high-risk system.
Trap 3: Provide a dashboard showing the AI's confidence score for each…
A confidence score display leaves the reviewer as a passive observer; the AI still decides, so no human can genuinely intervene. Dashboards suit monitoring model performance over time, whereas oversight requires a person to review evidence and authorise or override each decision.
- A
Require a human to review and approve every loan decision before it becomes final
Requiring a human to review and approve every loan decision before it becomes final ensures meaningful human oversight, satisfying the EU AI Act's high-risk requirement. Human-in-the-loop approval prevents fully automated decisions, unlike post-hoc monitoring or logging alone.
- B
Use a separate AI model to audit the primary AI's decisions weekly
Why it fails: Auditing by another model replaces one automated decision with two, leaving no human in the loop, which the EU AI Act's oversight requirement demands. Model-based auditing suits ongoing quality assurance and drift detection, not the human review of individual high-risk decisions.
- C
Allow applicants to appeal AI decisions through a customer service process
Why it fails: Appeals occur after an adverse decision, so they provide redress rather than oversight of the decision itself; the EU AI Act requires human oversight during operation, such as a human reviewing or overriding outputs before they take effect. Appeals suit post-hoc dispute resolution, not real-time control of a high-risk system.
- D
Provide a dashboard showing the AI's confidence score for each application
Why it fails: A confidence score display leaves the reviewer as a passive observer; the AI still decides, so no human can genuinely intervene. Dashboards suit monitoring model performance over time, whereas oversight requires a person to review evidence and authorise or override each decision.
A team is building a recommendation system using collaborative filtering. They have a sparse user-item matrix. Which technique should they use to handle the sparsity and improve recommendations?
Trap 1: Association rule mining
Association rule mining discovers co-occurrence patterns in transactional baskets; it does not factorise a sparse user-item matrix into latent user and item vectors. It is tempting because both mine implicit preference data, but it would be correct for market-basket analysis such as "customers who bought X also bought Y".
Trap 2: k-nearest neighbors
k-nearest neighbors computes similarity directly on the sparse user-item matrix, so distances between users with few overlapping ratings become unreliable and accuracy degrades. It is tempting because it is a collaborative filtering method, but it would be correct on dense rating data where neighbourhood similarity is meaningful.
Trap 3: Content-based filtering
Content-based filtering recommends by matching item attributes to a user's own profile, ignoring other users' ratings entirely, so it cannot exploit the collaborative signal the sparse matrix encodes. It is tempting because it handles new items well, but it would be correct when item metadata is rich and interaction data is scarce.
- A
Association rule mining
Why it fails: Association rule mining discovers co-occurrence patterns in transactional baskets; it does not factorise a sparse user-item matrix into latent user and item vectors. It is tempting because both mine implicit preference data, but it would be correct for market-basket analysis such as "customers who bought X also bought Y".
- B
Matrix factorization
Matrix factorization decomposes the sparse user-item matrix into lower-dimensional latent factor matrices, capturing hidden relationships between users and items. This reduces dimensionality and fills implicit gaps, generating meaningful recommendations despite missing ratings that plague collaborative filtering on sparse data.
- C
k-nearest neighbors
Why it fails: k-nearest neighbors computes similarity directly on the sparse user-item matrix, so distances between users with few overlapping ratings become unreliable and accuracy degrades. It is tempting because it is a collaborative filtering method, but it would be correct on dense rating data where neighbourhood similarity is meaningful.
- D
Content-based filtering
Why it fails: Content-based filtering recommends by matching item attributes to a user's own profile, ignoring other users' ratings entirely, so it cannot exploit the collaborative signal the sparse matrix encodes. It is tempting because it handles new items well, but it would be correct when item metadata is rich and interaction data is scarce.
A team is building an AI-powered recommendation system for an e-commerce platform. They want to test the system before deployment. Which TWO types of testing are MOST relevant for this AI system? (Select TWO)
Trap 1: Load testing the web server
Load testing measures web server throughput and concurrency, not recommendation quality. It is tempting because production traffic volumes matter, but the question asks which testing validates the AI system itself, so relevance ranking, bias and drift testing are the applicable types.
Trap 2: Integration tests for API calls
Integration tests for API calls verify that services exchange requests and responses correctly, not that recommendations are accurate or unbiased. It is tempting because the system is API-driven, but the question asks which testing validates the AI model itself, so data and model evaluation types are relevant.
Trap 3: Regression testing on the UI
Regression testing on the UI checks that interface elements still render and behave after changes; it exercises no model behaviour. It is tempting because regressions do affect AI products, but the question targets validating the recommendation engine, so model-focused testing such as accuracy and fairness evaluation applies.
- A
Load testing the web server
Why it fails: Load testing measures web server throughput and concurrency, not recommendation quality. It is tempting because production traffic volumes matter, but the question asks which testing validates the AI system itself, so relevance ranking, bias and drift testing are the applicable types.
- B
Integration tests for API calls
Why it fails: Integration tests for API calls verify that services exchange requests and responses correctly, not that recommendations are accurate or unbiased. It is tempting because the system is API-driven, but the question asks which testing validates the AI model itself, so data and model evaluation types are relevant.
- C
Evaluation frameworks for model output quality
Evaluation frameworks assess recommendation output quality, such as relevance, ranking accuracy and coverage, before deployment. This directly satisfies the stem's requirement to test the AI system's behaviour, catching quality issues that conventional functional testing would miss.
- D
Unit tests for data pipelines
Unit tests for data pipelines verify each transformation, schema check and ingestion step in isolation, catching corrupt or malformed records before they poison training. For a recommendation system, this satisfies the need to test components before deployment, since faulty feature engineering silently degrades model output.
- E
Regression testing on the UI
Why it fails: Regression testing on the UI checks that interface elements still render and behave after changes; it exercises no model behaviour. It is tempting because regressions do affect AI products, but the question targets validating the recommendation engine, so model-focused testing such as accuracy and fairness evaluation applies.
A company is adopting a secure development lifecycle for its new AI product. Which THREE activities are essential for secure AI development? (Select three.)
Trap 1: Deploying the model on the fastest hardware available
Hardware speed affects training and inference latency, not security posture. It is tempting because performance is a visible engineering concern and faster GPUs are often prioritised in AI projects. Secure development instead demands threat modelling, secure data pipelines, and model validation against poisoning and evasion attacks.
Trap 2: Using homomorphic encryption for all data at rest
Homomorphic encryption protects data during computation, not at rest; applying it universally is impractical and unrelated to SDLC essentials. It is tempting because it is a genuine privacy-enhancing technique for confidential inference. Secure AI development instead requires threat modelling, data provenance controls, and adversarial testing across the lifecycle.
- A
Implementing secure data pipelines
Secure data pipelines enforce provenance, access control and integrity checks on training and inference data, preventing poisoned or tampered inputs entering the model. This satisfies the secure development lifecycle requirement by embedding security controls at the data ingestion stage rather than post-deployment.
- B
Threat modeling using STRIDE
STRIDE provides a structured taxonomy for enumerating spoofing, tampering, repudiation, information disclosure, denial of service and elevation threats against AI components. Applying it during design satisfies the secure development lifecycle requirement by identifying architectural weaknesses before code is written.
- C
Deploying the model on the fastest hardware available
Why it fails: Hardware speed affects training and inference latency, not security posture. It is tempting because performance is a visible engineering concern and faster GPUs are often prioritised in AI projects. Secure development instead demands threat modelling, secure data pipelines, and model validation against poisoning and evasion attacks.
- D
Audit logging of AI interactions
Audit logging records prompts, outputs and model decisions, giving traceability for incident response and misuse detection. It satisfies the secure development lifecycle requirement for monitoring AI interactions, complementing input validation and access controls across the product's lifetime.
- E
Using homomorphic encryption for all data at rest
Why it fails: Homomorphic encryption protects data during computation, not at rest; applying it universally is impractical and unrelated to SDLC essentials. It is tempting because it is a genuine privacy-enhancing technique for confidential inference. Secure AI development instead requires threat modelling, data provenance controls, and adversarial testing across the lifecycle.
A security engineer is conducting threat modeling for an AI system that uses a pre-trained image classifier. Applying STRIDE, which threat category most directly addresses an attacker manipulating the model's behavior by providing carefully crafted inputs that the model was not trained to handle robustly?
Trap 1: Repudiation
Repudiation concerns denying that an action occurred, typically lacking audit evidence, and does not describe crafted inputs altering model predictions. It is tempting where logging of inference requests is absent, but adversarial example manipulation is Tampering, which covers modifying model behaviour.
Trap 2: Information disclosure
Information disclosure covers exposure of model data, weights or training inputs, not adversarial inputs altering predictions. It is tempting because model extraction and membership inference leak information, but crafted-input manipulation maps to Tampering, which addresses modification of model behaviour.
Trap 3: Spoofing
Spoofing concerns impersonating a legitimate user, device or service, not perturbing classifier outputs. It is tempting because adversarial examples can impersonate a target class, yet STRIDE places manipulation of the model's processing and behaviour under Tampering, which covers the crafted input itself.
- A
Repudiation
Why it fails: Repudiation concerns denying that an action occurred, typically lacking audit evidence, and does not describe crafted inputs altering model predictions. It is tempting where logging of inference requests is absent, but adversarial example manipulation is Tampering, which covers modifying model behaviour.
- B
Tampering
Tampering covers adversarial inputs that alter model behaviour at inference time, satisfying the stem's crafted-input constraint. Unlike spoofing, which targets identity, tampering directly addresses integrity attacks on the classifier's decision boundary, such as adversarial examples the pre-trained model never encountered during training.
- C
Information disclosure
Why it fails: Information disclosure covers exposure of model data, weights or training inputs, not adversarial inputs altering predictions. It is tempting because model extraction and membership inference leak information, but crafted-input manipulation maps to Tampering, which addresses modification of model behaviour.
- D
Spoofing
Why it fails: Spoofing concerns impersonating a legitimate user, device or service, not perturbing classifier outputs. It is tempting because adversarial examples can impersonate a target class, yet STRIDE places manipulation of the model's processing and behaviour under Tampering, which covers the crafted input itself.
A company is deploying an LLM-powered application that answers questions based on internal documents. They want to minimize prompt injection attacks where users trick the model into ignoring instructions. Which THREE measures should they implement? (Select THREE)
Trap 1: Set temperature to 0.0 for all queries
Temperature controls sampling randomness, not instruction hierarchy; a deterministic output still obeys injected text embedded in retrieved documents. It is tempting because low temperature reduces creative drift in factual answering tasks, but it provides no separation between system instructions and untrusted user content.
Trap 2: Allow the model to execute any code from user prompts for…
Arbitrary code execution from prompts hands attackers the execution environment, escalating injection into remote code execution. It is tempting where dynamic tool use or data transformation is required, but that demands sandboxed, allow-listed functions invoked through validated schemas, not unrestricted interpreter access.
- A
Use a system-level prompt that clearly defines allowed behavior and boundaries
A system-level prompt establishes persistent instructions that take precedence over user turns, defining permitted behaviour and boundaries. This constrains the model's response space so user input is less able to override the application's original directives.
- B
Set temperature to 0.0 for all queries
Why it fails: Temperature controls sampling randomness, not instruction hierarchy; a deterministic output still obeys injected text embedded in retrieved documents. It is tempting because low temperature reduces creative drift in factual answering tasks, but it provides no separation between system instructions and untrusted user content.
- C
Allow the model to execute any code from user prompts for flexibility
Why it fails: Arbitrary code execution from prompts hands attackers the execution environment, escalating injection into remote code execution. It is tempting where dynamic tool use or data transformation is required, but that demands sandboxed, allow-listed functions invoked through validated schemas, not unrestricted interpreter access.
- D
Implement a separate classifier to detect and block injection attempts
A dedicated classifier inspects incoming prompts and flags or blocks known injection patterns before they reach the LLM, adding a detection layer independent of the model's own instruction-following, which satisfies the requirement to minimise prompt injection.
- E
Sanitize user inputs to remove special tokens or injection patterns
Sanitising inputs strips special tokens and known injection patterns that could override system instructions, preventing user text from being interpreted as commands. This directly reduces the attack surface for prompt injection in the document-questioning application.
A team is designing an AI system for autonomous driving. They need to decide between an end-to-end deep learning approach versus a modular pipeline (perception, planning, control). Which is a key advantage of the modular approach?
Trap 1: It typically has lower inference latency.
Modular pipelines split perception, planning and control into separate stages, so each adds its own inference overhead rather than sharing one network pass, raising latency. It is tempting because modular decomposition genuinely aids debugging, safety certification and component-level testing — the right choice when interpretability and regulatory auditability outweigh end-to-end latency.
Trap 2: It handles novel scenarios better due to joint training.
Modular components are trained separately, so there is no joint training to exploit; each module optimises its own objective. Joint training is the property of end-to-end networks, which is why that approach is selected when large labelled datasets spanning the whole task are available.
Trap 3: It requires less engineering effort.
The modular approach demands more engineering effort, since each stage needs its own model, interface and testing. It is selected when teams require interpretability, regulatory auditability or independent component updates, not to reduce the total build cost.
- A
It typically has lower inference latency.
Why it fails: Modular pipelines split perception, planning and control into separate stages, so each adds its own inference overhead rather than sharing one network pass, raising latency. It is tempting because modular decomposition genuinely aids debugging, safety certification and component-level testing — the right choice when interpretability and regulatory auditability outweigh end-to-end latency.
- B
Each module can be validated separately.
A modular pipeline exposes defined interfaces between perception, planning and control, so each stage can be tested and validated in isolation before integration. This satisfies the safety-critical need to localise faults, which an end-to-end network cannot isolate.
- C
It handles novel scenarios better due to joint training.
Why it fails: Modular components are trained separately, so there is no joint training to exploit; each module optimises its own objective. Joint training is the property of end-to-end networks, which is why that approach is selected when large labelled datasets spanning the whole task are available.
- D
It requires less engineering effort.
Why it fails: The modular approach demands more engineering effort, since each stage needs its own model, interface and testing. It is selected when teams require interpretability, regulatory auditability or independent component updates, not to reduce the total build cost.
A company is required to disclose that content has been generated or significantly modified by AI. Which practice directly addresses this transparency obligation?
Trap 1: Using LIME for explanations
LIME explains individual model predictions to developers and auditors; it produces no user-facing label, watermark or disclosure statement. It is tempting because explainability supports accountability, and would be correct where the requirement is interpreting why a model produced a given output rather than declaring AI involvement.
Trap 2: Implementing federated learning
Federated learning trains models across decentralised data without centralising it, addressing privacy and data-residency concerns. It is tempting because it is an AI governance practice, and would be correct where the requirement is keeping training data on-device rather than informing recipients that content is AI-generated.
Trap 3: Publishing a model card
A model card documents a model's intended use, training data and performance for reviewers; it does not mark or label deployed output. It is tempting because it is a recognised transparency artefact, and would be correct where the obligation is disclosing model characteristics to stakeholders rather than flagging AI-generated content.
- A
Applying AI watermarking
AI watermarking embeds a detectable signal into generated content, enabling disclosure that material was AI-generated or modified. This directly satisfies the stem's transparency obligation, unlike consent, retention or accuracy controls that address different AI governance concerns.
- B
Using LIME for explanations
Why it fails: LIME explains individual model predictions to developers and auditors; it produces no user-facing label, watermark or disclosure statement. It is tempting because explainability supports accountability, and would be correct where the requirement is interpreting why a model produced a given output rather than declaring AI involvement.
- C
Implementing federated learning
Why it fails: Federated learning trains models across decentralised data without centralising it, addressing privacy and data-residency concerns. It is tempting because it is an AI governance practice, and would be correct where the requirement is keeping training data on-device rather than informing recipients that content is AI-generated.
- D
Publishing a model card
Why it fails: A model card documents a model's intended use, training data and performance for reviewers; it does not mark or label deployed output. It is tempting because it is a recognised transparency artefact, and would be correct where the obligation is disclosing model characteristics to stakeholders rather than flagging AI-generated content.
An organization wants to ensure its AI systems comply with new regulations requiring explanations for automated decisions. Which governance practice is most directly relevant?
Trap 1: Implementing differential privacy
Differential privacy adds calibrated noise to outputs to protect individuals in training data; it produces no explanation of a decision. Explainability tooling such as SHAP or LIME addresses the regulatory requirement. Differential privacy would be right when the obligation is privacy protection.
Trap 2: Conducting bias audits
Bias audits measure disparate impact across protected groups, not the reasoning behind an individual automated decision, so they cannot satisfy an explanation mandate. They are tempting because audits are a recognised AI governance control, and would be correct where the regulation targets discriminatory outcomes rather than explainability.
Trap 3: Establishing an AI ethics board
An ethics board sets principles and reviews dilemmas; it does not itself produce the per-decision explanation artefacts the regulation demands. It is tempting because boards do govern AI, and would be right when the requirement is broad policy oversight rather than documented reasoning for each automated outcome.
- A
Implementing differential privacy
Why it fails: Differential privacy adds calibrated noise to outputs to protect individuals in training data; it produces no explanation of a decision. Explainability tooling such as SHAP or LIME addresses the regulatory requirement. Differential privacy would be right when the obligation is privacy protection.
- B
Deploying explainability tools
Explainability tools generate the feature attributions and decision rationales that regulators require for automated decisions, directly satisfying the explanation mandate. Governance practice must therefore operationalise interpretability so each decision can be justified to auditors and affected individuals.
- C
Conducting bias audits
Why it fails: Bias audits measure disparate impact across protected groups, not the reasoning behind an individual automated decision, so they cannot satisfy an explanation mandate. They are tempting because audits are a recognised AI governance control, and would be correct where the regulation targets discriminatory outcomes rather than explainability.
- D
Establishing an AI ethics board
Why it fails: An ethics board sets principles and reviews dilemmas; it does not itself produce the per-decision explanation artefacts the regulation demands. It is tempting because boards do govern AI, and would be right when the requirement is broad policy oversight rather than documented reasoning for each automated outcome.
An AI development team is building a system to detect fraudulent transactions. They want to ensure the model complies with regulations requiring that individuals can question automated decisions. Which governance element is most relevant?
Trap 1: Model versioning
Model versioning tracks which artefact produced a prediction, aiding audit and rollback, yet it does not itself give an individual an explanation of the decision. It would be the right choice when the requirement is reproducibility of deployed models rather than contestability of outcomes.
Trap 2: Differential privacy
Differential privacy adds statistical noise to protect individual records in the training data; it does not expose the reasoning behind a specific decision. It is tempting because it is a recognised AI governance control, but it would be the right choice when the requirement is privacy preservation rather than contestability.
Trap 3: Data minimization
Data minimisation limits collection and retention of personal data, which supports privacy compliance but provides no mechanism for explaining or challenging an automated outcome. It would be correct where the obligation concerns reducing stored personal data, not the right to question a decision.
- A
Right to explanation
The right to explanation gives individuals meaningful information about the logic and factors behind an automated decision, letting them question and contest outcomes. It directly satisfies the stem's regulatory requirement that people can challenge automated fraud determinations, unlike accuracy or latency governance elements.
- B
Model versioning
Why it fails: Model versioning tracks which artefact produced a prediction, aiding audit and rollback, yet it does not itself give an individual an explanation of the decision. It would be the right choice when the requirement is reproducibility of deployed models rather than contestability of outcomes.
- C
Differential privacy
Why it fails: Differential privacy adds statistical noise to protect individual records in the training data; it does not expose the reasoning behind a specific decision. It is tempting because it is a recognised AI governance control, but it would be the right choice when the requirement is privacy preservation rather than contestability.
- D
Data minimization
Why it fails: Data minimisation limits collection and retention of personal data, which supports privacy compliance but provides no mechanism for explaining or challenging an automated outcome. It would be correct where the obligation concerns reducing stored personal data, not the right to question a decision.
A company is deploying an AI system that screens job applications. According to the EU AI Act, this system is likely classified as high-risk because it affects employment opportunities. Which requirement must the company implement for high-risk AI systems?
Trap 1: Full transparency by publishing the model's source code and…
Publishing source code and training data is not an EU AI Act requirement for high-risk systems; that obligation concerns GPAI models, not employment screening. High-risk providers must instead implement risk management, technical documentation, logging, human oversight and conformity assessment. Transparency here means informing affected persons, not open-sourcing proprietary models.
Trap 2: Annual third-party audits of the model's energy consumption
Energy-consumption audits address environmental impact, not the EU AI Act's high-risk requirements of risk management, data governance, technical documentation, logging, transparency, human oversight and conformity assessment. It is tempting because sustainability auditing is topical, but it does not satisfy the Act's high-risk obligations.
Trap 3: Obtaining explicit consent from each applicant to process their data
Explicit consent is a GDPR data-processing condition, not an EU AI Act high-risk obligation; the Act instead requires risk management, technical documentation, logging, human oversight and conformity assessment. It is tempting because consent feels protective, but consent alone does not satisfy the high-risk regime.
- A
A human-in-the-loop mechanism that enables override of the AI's decisions
High-risk AI systems under the EU AI Act require human oversight, so a human-in-the-loop mechanism allowing override of screening decisions satisfies this. It ensures employment outcomes remain subject to meaningful human review rather than automated determination.
- B
Full transparency by publishing the model's source code and training data
Why it fails: Publishing source code and training data is not an EU AI Act requirement for high-risk systems; that obligation concerns GPAI models, not employment screening. High-risk providers must instead implement risk management, technical documentation, logging, human oversight and conformity assessment. Transparency here means informing affected persons, not open-sourcing proprietary models.
- C
Annual third-party audits of the model's energy consumption
Why it fails: Energy-consumption audits address environmental impact, not the EU AI Act's high-risk requirements of risk management, data governance, technical documentation, logging, transparency, human oversight and conformity assessment. It is tempting because sustainability auditing is topical, but it does not satisfy the Act's high-risk obligations.
- D
Obtaining explicit consent from each applicant to process their data
Why it fails: Explicit consent is a GDPR data-processing condition, not an EU AI Act high-risk obligation; the Act instead requires risk management, technical documentation, logging, human oversight and conformity assessment. It is tempting because consent feels protective, but consent alone does not satisfy the high-risk regime.
Free account
Track your progress over time
Create a free account to save your results and see which topics improve across sessions.
Focused Operating Systems sessions
Start a Operating Systems only practice session
Every question in these sessions is drawn from the Operating Systems domain — nothing else.
Related practice questions
Related AI0-001 topic practice pages
Move into related areas when this topic feels solid.
Implementing AI Solutions practice questions
Targeted AI0-001 practice covering Implementing AI Solutions.
AI Governance and Ethics practice questions
Work through AI0-001 questions on AI Governance and Ethics.
AI Concepts and Techniques practice questions
Work through AI0-001 questions on AI Concepts and Techniques.
AI Concepts and Foundations practice questions
Targeted AI0-001 practice covering AI Concepts and Foundations.
AI Security practice questions
Targeted AI0-001 practice covering AI Security.
AI Infrastructure and Technologies practice questions
Targeted AI0-001 practice covering AI Infrastructure and Technologies.
AI Models and Data Engineering practice questions
Work through AI0-001 questions on AI Models and Data Engineering.
Machine Learning and Deep Learning practice questions
Targeted AI0-001 practice covering Machine Learning and Deep Learning.
AI Security, Ethics and Governance practice questions
Practise AI0-001 questions linked to AI Security, Ethics and Governance.
AI Implementation and Operations practice questions
Practise AI0-001 questions linked to AI Implementation and Operations.
CompTIA A+ hardware practice questions
Sharpen your AI0-001 knowledge of CompTIA A+ hardware.
CompTIA A+ mobile devices practice questions
Sharpen your AI0-001 knowledge of CompTIA A+ mobile devices.
Frequently asked questions
- What does the AI0-001 exam test about Operating Systems?
- Operating Systems questions test whether you can apply the concept in context, not just recognise a definition.
- How should I use these practice questions?
- Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
- Can I practise just Operating Systems questions in a focused session?
- Yes — the session launcher on this page draws every question from the Operating Systems domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
- Where can I practise other AI0-001 topics?
- Use the topic links above to move to related areas, or go back to the AI0-001 question bank to see all topics.
- Are these real exam questions or dumps?
- These are original practice questions written to test the same concepts the AI0-001 exam covers. They are not copied from any real exam or dump site.
Track your progress
A free account saves results across sessions and highlights which topics need work.
Sign up freeExam traps to avoid
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.