Courseiva

AI0-001 AI Security, Ethics and Governance Practice Question

Which practice best ensures AI systems comply with regulations like GDPR?

⚠ Common exam trap

The AI0-001 exam often tests the misconception that security practices (like vulnerability scans) are sufficient for privacy compliance, but GDPR specifically requires proactive data governance measures like minimization and anonymization, not just reactive security controls.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Data minimization and anonymization

Data minimization and anonymization directly align with GDPR's core principles, such as Article 5(1)(c) which mandates that personal data be 'adequate, relevant and limited to what is necessary.' By collecting only essential data and applying techniques like k-anonymity or differential privacy, AI systems reduce the risk of re-identification and ensure compliance with data protection by design and by default (Article 25). This practice is a foundational governance measure, not a reactive or staffing solution.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Using open-source models only

    Why it's wrong here

    Open-source licensing terms govern code reuse, not personal data handling; the model's provenance does not determine whether processing satisfies GDPR. Compliance requires data protection controls and records. Restricting to open-source models is correct when the requirement is avoiding vendor licence fees or enabling code inspection.

  • ✗

    Regular vulnerability scans

    Why it's wrong here

    Vulnerability scans detect technical weaknesses in infrastructure and applications; they do not address lawful basis, consent, retention limits, or data subject requests under GDPR. Privacy compliance needs governance and data mapping. Scanning is correct for identifying unpatched software exposures in a security programme.

  • ✓

    Data minimization and anonymization

    Why this is correct

    Data minimisation limits processing to what the stated purpose requires, while anonymisation removes personal identifiers, so GDPR principles of purpose limitation, storage limitation and data protection by design are satisfied directly rather than through contractual or procedural controls.

  • ✗

    Hiring more data scientists

    Why it's wrong here

    Additional data scientists increase model-building capacity but do not by themselves enforce lawful processing, consent tracking, or data subject rights. GDPR compliance comes from governance, documentation, and privacy controls. Hiring specialists is correct when the gap is scarce machine-learning engineering skill, not regulatory adherence.

About these practice questions

This AI0-001 question is part of Courseiva's 962-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.