Courseiva
AI Concepts and Techniques →mediumMultiple Select

AI0-001 AI Concepts and Techniques Practice Question

A company is deploying a chatbot using a large language model. They want to mitigate the risk of prompt injection attacks. Which TWO measures should be implemented?

⚠ Common exam trap

CompTIA often tests the misconception that fine-tuning or output limits can prevent prompt injection, when in fact these measures do not address the root cause of untrusted input being processed as instructions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement input validation and sanitisation

Option A is correct because input validation and sanitisation directly strip or neutralise adversarial payloads (e.g., embedded instructions, delimiter-breaking characters, or encoded jailbreak strings) before they reach the LLM, reducing the attack surface for prompt injection. Option B is correct because a strict system prompt establishes immutable behavioural boundaries and instruction hierarchy, making it harder for user-supplied text to override the model's intended role or exfiltrate system instructions. Option C is not a reliable mitigation because fine-tuning on safe examples does not prevent novel injection payloads at inference time and can even be undone by adversarial prompting. Option D is irrelevant, since a larger context window merely allows more tokens to be processed and does not filter or constrain malicious instructions. Option E only caps response size and does nothing to stop an injected prompt from altering the model's behaviour or leaking data.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Implement input validation and sanitisation

    Why this is correct

    Input validation and sanitisation strip or escape injected instructions before they reach the model, blocking attempts to override system prompts. This constrains untrusted user input at the application boundary, mitigating prompt injection without altering the model itself.

  • ✓

    Use a system prompt that strictly defines the chatbot's behavior

    Why this is correct

    A system prompt that strictly defines the chatbot's behaviour constrains the model's permitted scope, so injected instructions in user or retrieved content cannot easily redirect its role. This directly satisfies the stem's requirement to mitigate prompt injection by establishing an authoritative instruction layer the model prioritises over untrusted input.

  • ✗

    Fine-tune the model on safe conversational examples

    Why it's wrong here

    Fine-tuning on safe examples shapes tone and refusal style but does not stop adversarial instructions injected at inference time. It is tempting because safety training reduces harmful outputs, and fine-tuning would be the correct choice when a model must consistently adopt a domain-specific response format.

  • ✗

    Use a larger context window

    Why it's wrong here

    A larger context window lets the model ingest more text; it provides no mechanism to separate trusted instructions from untrusted user content. It is tempting because prompt injection often arrives buried in long inputs, and a larger window would be the correct choice when summarising lengthy documents.

  • ✗

    Limit the maximum output token length

    Why it's wrong here

    Capping output tokens truncates responses but does not prevent an injected instruction from altering the model's behaviour. It is tempting because it bounds cost and latency, and limiting output length would be the correct choice when responses must fit a fixed downstream display or API payload.

About these practice questions

One of 962 original AI0-001 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.