Courseiva
AI Security →mediumMultiple Choice

AI0-001 AI Security Practice Question

A company develops an internal LLM-based tool that queries a vector database containing confidential customer data. Which security measure should be implemented to prevent the LLM from revealing sensitive information in its responses?

⚠ Common exam trap

The exam often tests the distinction between input controls (like sanitization) and output controls (like filtering), and the trap here is that candidates mistakenly choose input validation (Option B) thinking it prevents data leakage, when in fact the leak occurs in the LLM's output, not the user's input.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Output filtering with regex and moderation classifiers

Output filtering with regex and moderation classifiers (Option D) is the correct security measure because it directly inspects the LLM's generated responses for sensitive data patterns (e.g., credit card numbers, PII) and blocks or redacts them before delivery. This prevents the LLM from inadvertently leaking confidential customer data retrieved from the vector database, even if the model's training or prompt injection causes it to include such information in its output.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Rate limiting on API calls

    Why it's wrong here

    Rate limiting caps request volume per client, which throttles abuse and cost but does nothing to stop a permitted query returning confidential customer data in its answer. It is tempting because it genuinely mitigates denial-of-service and runaway consumption scenarios, where controlling call frequency is the actual objective.

  • ✗

    Input validation and sanitization

    Why it's wrong here

    Input validation and sanitisation filter what enters the prompt, yet the leak originates from retrieved vector-database content embedded in the model's output, which sanitising user input never inspects. It is tempting because it correctly defends against prompt injection and malformed requests, where untrusted input is the attack vector.

  • ✗

    Audit logging of AI interactions

    Why it's wrong here

    Audit logging records interactions after data has already been exposed, so it cannot block the LLM from emitting confidential content. It is tempting because logging supports forensic review, compliance evidence and incident investigation — the right control when the requirement is post-hoc traceability rather than real-time prevention of disclosure.

  • ✓

    Output filtering with regex and moderation classifiers

    Why this is correct

    Output filtering inspects the model's generated response before it reaches the user, catching sensitive data such as customer records that the LLM might surface from the vector database. Regex and moderation classifiers enforce this at the egress point, satisfying the requirement to prevent disclosure.

About these practice questions

This AI0-001 question is part of Courseiva's 962-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.