Courseiva

AI0-001 AI Security, Ethics and Governance Practice Question

Which THREE are effective methods for ensuring data privacy in AI training? (Choose three.)

⚠ Common exam trap

The AI0-001 exam often tests the distinction between security controls (like encryption) and privacy-preserving techniques, trapping candidates who confuse data protection at rest with privacy during model training.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Data anonymization

Data anonymization (B) is correct because removing or masking personally identifiable information (PII) such as names, addresses, and identifiers before training prevents the model from learning or exposing individual identities. Differential privacy (C) is correct because it adds calibrated statistical noise (e.g., via mechanisms like Laplace or Gaussian noise with a privacy budget epsilon) so that the inclusion or exclusion of any single record has a negligible effect on outputs, providing a formal privacy guarantee. Federated learning (E) is correct because it trains models locally on each device or silo and shares only model updates (e.g., gradients or weights) rather than raw data, keeping sensitive data on the originating endpoint. Data encryption at rest (A) protects stored data against unauthorized access but does not prevent privacy leakage during training or inference, so it is not one of the three methods for ensuring privacy in AI training. Data replication (D) merely copies data to additional locations, which increases exposure and does nothing to protect privacy, so it is not a valid method.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Data encryption at rest

    Why it's wrong here

    Encryption at rest protects stored data from physical theft or unauthorised disk access, but training pipelines read decrypted records into memory, so it does nothing against re-identification, memorisation or inference leakage. It is tempting because it is a genuine privacy control for storage compliance, and would be correct where data at rest is the exposure.

  • ✓

    Data anonymization

    Why this is correct

    Data anonymisation removes or alters personally identifiable information before it enters the training set, so the model never learns identifiers tied to real individuals. This directly satisfies the stem's data privacy requirement by preventing re-identification from model outputs or memorised training data, a stronger safeguard than post-training access controls alone.

  • ✓

    Differential privacy

    Why this is correct

    Differential privacy adds calibrated statistical noise to training data or gradients, mathematically bounding how much any single record can influence the model's output. This satisfies the stem's data privacy constraint by preventing inference of individual details from the trained model, even under adversarial queries.

  • ✗

    Data replication

    Why it's wrong here

    Replication copies data to additional stores, multiplying exposure points and retention obligations without removing or masking any personal identifiers. It tempts because replication supports availability and backup, and it would be correct for resilience or disaster recovery — but privacy requires anonymisation, consent management or access controls, not duplication.

  • ✓

    Federated learning

    Why this is correct

    Federated learning trains models locally on each device, sharing only model updates rather than raw data, so personal information never leaves its source. This directly satisfies the privacy constraint by preventing centralised collection of sensitive training records, reducing breach exposure and supporting data-minimisation obligations under GDPR-style rules.

About these practice questions

Courseiva writes every AI0-001 question from scratch — 962 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.