AI0-001 AI Security, Ethics and Governance Practice Question
Which TWO of the following are best practices for securing an AI model against adversarial attacks?
⚠ Common exam trap
CompTIA often tests the misconception that increasing model complexity or pruning improves security, when in fact these techniques address performance or efficiency, not adversarial robustness.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Adversarial training with perturbed examples.
Option B is correct because adversarial training explicitly augments the training set with perturbed inputs (e.g., FGSM or PGD examples) labeled with their true classes, which hardens the model's decision boundaries against small, intentionally crafted perturbations. Option C is correct because input sanitization and validation filter or normalize anomalous inputs (e.g., clipping pixel ranges, rejecting out-of-distribution values, or detecting unusual feature patterns) before inference, reducing the attack surface for adversarial examples. Option A is not a security best practice for adversarial robustness; pruning reduces parameters for efficiency and can even increase vulnerability by removing redundant features that aid generalization. Option D is wrong because increasing model complexity typically enlarges the attack surface and can worsen overfitting to non-robust features, making adversarial examples easier to find. Option E is irrelevant to adversarial security, as grid search only tunes hyperparameters for performance metrics like accuracy, not robustness against crafted perturbations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Model pruning to reduce the number of parameters.
Why it's wrong here
Pruning removes redundant weights to shrink the model and speed inference, which does not alter the decision boundaries that adversarial perturbations exploit. It tempts because pruning is a genuine optimisation technique, and would be the right choice when the goal is reducing model size, latency or memory footprint rather than hardening against crafted inputs.
- ✓
Adversarial training with perturbed examples.
Why this is correct
Adversarial training with perturbed examples hardens the model by exposing it to manipulated inputs during fitting, so it learns decision boundaries robust to small, deliberate perturbations. This directly satisfies the stem's requirement for a best practise against adversarial attacks, reducing misclassification of crafted inputs at inference time.
- ✓
Input sanitization and validation.
Why this is correct
Input sanitization and validation strip malicious payloads—such as crafted perturbation strings or prompt-injection characters—before they reach the model, directly satisfying the stem's requirement to defend against adversarial inputs. Filtering and normalising inbound data reduces the attack surface at the earliest point, blocking manipulation attempts that would otherwise alter inference behaviour.
- ✗
Increasing model complexity to capture more patterns.
Why it's wrong here
Increasing model complexity enlarges the attack surface by introducing more parameters for gradient-based adversarial perturbations to exploit, directly contradicting the security requirement for robustness. This option is tempting because deeper models often improve accuracy on benign data, making it a correct choice for performance optimisation tasks where generalisation, not adversarial defence, is the primary goal.
- ✗
Hyperparameter optimization using grid search.
Why it's wrong here
Grid search tunes hyperparameters such as learning rate and depth to improve accuracy or convergence, leaving the model equally susceptible to crafted perturbations. It tempts because hyperparameter optimisation is a legitimate part of model development, and would be correct when the objective is maximising predictive performance rather than adversarial robustness.
About these practice questions
One of 962 original AI0-001 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.