Courseiva
AI Security →mediumMultiple Select

AI0-001 AI Security Practice Question

A company is deploying an LLM-based system that can execute API calls on behalf of users. Which TWO measures should they implement to prevent excessive agency?

⚠ Common exam trap

Candidates often confuse security measures (like input filtering or rate limiting) with agency control measures. The question specifically targets preventing excessive agency—limiting the actions the LLM can perform—not just securing the inputs/outputs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Restrict the LLM to read-only or low-risk actions

Option B is correct because limiting the LLM's permissions to read-only or low-risk API operations directly constrains the scope of actions the model can autonomously perform, which is the core defense against excessive agency (least-privilege enforcement). Option D is correct because requiring human-in-the-loop approval for high-risk actions ensures that consequential API calls cannot be executed solely on the model's initiative, adding a human authorization gate before damage can occur. Options A and E address prompt injection and unsafe content at the input/output layer, but they do not limit what actions the agent is authorized to take, so they do not mitigate excessive agency. Option C, rate limiting, only throttles the volume or frequency of API calls; it does not prevent a single unauthorized or high-impact action from being executed, so it is not a primary control for excessive agency.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Implement strict output filtering

    Why it's wrong here

    Output filtering screens generated text for harmful or sensitive content; it does not constrain which API calls the agent executes. It is tempting because filtering appears to bound model behaviour, but excessive agency is prevented by least-privilege permissions and human approval before consequential actions, not post-generation text screening.

  • ✓

    Restrict the LLM to read-only or low-risk actions

    Why this is correct

    Restricting the LLM to read-only or low-risk actions directly limits the blast radius of any excessive agency, satisfying the stem's requirement to prevent harmful autonomous API execution. By removing write and destructive capabilities, even a manipulated or hallucinating model cannot mutate data or trigger high-impact operations, enforcing least privilege at the action tier.

  • ✗

    Apply rate limiting to API calls

    Why it's wrong here

    Rate limiting caps call volume, addressing denial-of-service and cost abuse rather than the scope of actions an agent may take. It is tempting because it constrains runaway loops, but excessive agency is prevented by least-privilege permissions and human approval of high-impact actions, not throughput throttling.

  • ✓

    Require human-in-the-loop approval for high-risk actions

    Why this is correct

    Human-in-the-loop approval places a person between the model's proposed action and its execution, so high-risk API calls cannot run autonomously. This directly caps excessive agency by constraining the system's independent decision-making authority, satisfying the requirement to prevent unchecked actions on users' behalf.

  • ✗

    Use input validation to sanitize user prompts

    Why it's wrong here

    Input validation sanitises prompts against injection, protecting data and instructions rather than limiting which actions the agent may perform. It is tempting because prompt injection often triggers harmful tool calls, but excessive agency is prevented by least-privilege scoping and human confirmation of consequential API actions.

About these practice questions

Courseiva writes every AI0-001 question from scratch — 962 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.