Courseiva
AI Security →mediumMultiple Choice

AI0-001 AI Security Practice Question

A company deploys an LLM-based application that retrieves external web content to answer user queries. An attacker crafts a webpage that, when retrieved, injects a hidden instruction telling the LLM to ignore its system prompt and output sensitive internal data. What type of attack is this?

⚠ Common exam trap

AI0-001 often tests the confusion between direct and indirect prompt injection; candidates might overlook that the attack vector is external content, not direct user input.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Indirect prompt injection

Indirect prompt injection occurs when an attacker injects malicious instructions into external content that the LLM retrieves and processes, such as a webpage. The LLM then executes those instructions, potentially ignoring its system prompt and leaking sensitive data. This is distinct from direct prompt injection, where the attacker directly inputs the malicious prompt.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Direct prompt injection

    Why it's wrong here

    Direct prompt injection arrives through the user's own input, whereas here the payload is embedded in retrieved external web content, making it indirect. It is tempting because both manipulate the LLM's instructions, and direct injection would be correct if the attacker typed the malicious instruction into the chat themselves.

  • ✗

    Jailbreaking

    Why it's wrong here

    Jailbreaking bypasses a model's own safety guardrails through crafted prompts, not through poisoned retrieved content. It is tempting because both manipulate model behaviour, but this attack exploits the retrieval pipeline injecting instructions into context, which is indirect prompt injection.

  • ✗

    Model inversion attack

    Why it's wrong here

    Model inversion reconstructs training data by querying a model's outputs, so it does not describe instructions smuggled in via retrieved web content. It is tempting because it also targets sensitive data exposure, and would fit a scenario where an attacker probes predictions to infer private attributes of the training set.

  • ✓

    Indirect prompt injection

    Why this is correct

    Indirect prompt injection occurs because the malicious instruction arrives through retrieved external content rather than the user's own input, which is the defining axis separating it from direct injection. This satisfies the stem's constraint: the attacker never interacts with the LLM directly, yet hijacks it via the webpage to exfiltrate internal data.

About these practice questions

One of 962 original AI0-001 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.