AI0-001 AI Security Practice Question
A company deploys an LLM-based application that retrieves external web content to answer user queries. An attacker crafts a webpage that, when retrieved, injects a hidden instruction telling the LLM to ignore its system prompt and output sensitive internal data. What type of attack is this?
⚠ Common exam trap
AI0-001 often tests the confusion between direct and indirect prompt injection; candidates might overlook that the attack vector is external content, not direct user input.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Indirect prompt injection
Indirect prompt injection occurs when an attacker injects malicious instructions into external content that the LLM retrieves and processes, such as a webpage. The LLM then executes those instructions, potentially ignoring its system prompt and leaking sensitive data. This is distinct from direct prompt injection, where the attacker directly inputs the malicious prompt.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Direct prompt injection
Why it's wrong here
Direct prompt injection arrives through the user's own input, whereas here the payload is embedded in retrieved external web content, making it indirect. It is tempting because both manipulate the LLM's instructions, and direct injection would be correct if the attacker typed the malicious instruction into the chat themselves.
- ✗
Jailbreaking
Why it's wrong here
Jailbreaking bypasses a model's own safety guardrails through crafted prompts, not through poisoned retrieved content. It is tempting because both manipulate model behaviour, but this attack exploits the retrieval pipeline injecting instructions into context, which is indirect prompt injection.
- ✗
Model inversion attack
Why it's wrong here
Model inversion reconstructs training data by querying a model's outputs, so it does not describe instructions smuggled in via retrieved web content. It is tempting because it also targets sensitive data exposure, and would fit a scenario where an attacker probes predictions to infer private attributes of the training set.
- ✓
Indirect prompt injection
Why this is correct
Indirect prompt injection occurs because the malicious instruction arrives through retrieved external content rather than the user's own input, which is the defining axis separating it from direct injection. This satisfies the stem's constraint: the attacker never interacts with the LLM directly, yet hijacks it via the webpage to exfiltrate internal data.
About these practice questions
One of 962 original AI0-001 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.