Courseiva
AI Security →hardMultiple Select

AI0-001 AI Security Practice Question

A bank is deploying an LLM-based assistant that drafts responses to customer complaints. The assistant retrieves relevant policy passages from an internal vector database and includes them in the prompt. The security team wants to reduce the risk that an attacker can cause the assistant to reveal the full system prompt or internal policy text that the customer should not see. (Choose two.)

⚠ Common exam trap

The trap here is treating encryption at rest or higher sampling temperature as protections against prompt leakage, when the actual disclosure path is the model reproducing content that was placed in its context window.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Apply the principle of least privilege so the assistant only retrieves policy passages relevant to the specific customer complaint.

Reducing prompt and policy leakage in a retrieval-augmented assistant requires limiting what sensitive content enters the context and inspecting what leaves it. Filtering input and output catches extraction attempts and redacts restricted text, while least-privilege retrieval minimizes the sensitive passages available to the model in the first place. Together they shrink both the likelihood and the impact of disclosure, whereas storage encryption, full fine-tuning, and temperature changes do not close the generation channel.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Increase the model's temperature setting so responses vary and attackers cannot reliably reproduce extracted content.

    Why it's wrong here

    Higher temperature makes outputs more random, but it does not prevent disclosure of content already present in the prompt; an attacker can simply retry until a useful fragment appears. Sampling randomness is not a security boundary and may also degrade the quality and consistency of customer-facing complaint responses.

  • ✓

    Apply the principle of least privilege so the assistant only retrieves policy passages relevant to the specific customer complaint.

    Why this is correct

    Limiting retrieval to passages needed for the current complaint shrinks the amount of sensitive policy text placed in the prompt, so even a successful extraction attempt exposes far less. This reduces the blast radius of prompt leakage and complements output filtering by minimizing what the model can potentially reveal.

  • ✗

    Fine-tune the model on the bank's complete policy manual so it no longer needs retrieval at inference time.

    Why it's wrong here

    Fine-tuning on the full policy manual embeds sensitive content directly into model weights, which increases rather than decreases extraction risk and makes updates harder to control. A model that memorized the manual could reproduce restricted passages on its own, and the bank would lose the ability to revoke access to specific documents.

  • ✗

    Store the system prompt and policy passages in a separate encrypted database and grant the LLM read access only during inference.

    Why it's wrong here

    Encrypting the source data and restricting when the model reads it does not prevent the model from echoing that content in its output once it has been placed in the context window. The risk in this scenario is disclosure through generated text, so storage encryption and access timing do not address the extraction channel.

  • ✓

    Implement input and output filtering that detects and blocks attempts to extract system instructions or restricted policy content.

    Why this is correct

    Filtering both the incoming prompt and the model's response can catch known extraction patterns, such as requests to repeat the system message, and redact restricted policy text before it reaches the customer. It is a practical layered control that reduces disclosure risk without retraining the model, though it must be tuned to avoid blocking legitimate complaints.

About these practice questions

Courseiva writes every AI0-001 question from scratch — 962 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.