AI0-001 AI Security Practice Question
A company is developing a chatbot that helps users write code. They are concerned about the chatbot being used to generate malicious code. Which defense should they implement to reduce this risk?
⚠ Common exam trap
The trap is choosing input validation because it sounds like the 'first line of defense' — but for code assistants, input filtering is both impractical (code needs special characters) and ineffective against a model that can generate harmful output from innocuous prompts.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Output filtering and guardrails to detect malicious code patterns
Output filtering and guardrails inspect the model's generated response before it reaches the user, catching malicious code patterns such as reverse shells, credential stealers, or exploit payloads. This directly addresses the risk of the chatbot producing harmful code, regardless of what the user asked. Guardrails can combine pattern matching, classifiers, and policy rules to block or sanitize dangerous outputs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Output filtering and guardrails to detect malicious code patterns
Why this is correct
Output filtering inspects generated code before it reaches the user, blocking patterns matching malicious constructs such as reverse shells or credential harvesters. Guardrails therefore reduce the risk of the chatbot emitting harmful code, satisfying the stated concern.
- ✗
Input validation to block special characters
Why it's wrong here
Blocking special characters cannot reliably prevent malicious code generation, since harmful output can be produced from ordinary words and punctuation is essential for legitimate code. Input validation of this kind suits blocking injection attacks such as SQL or script payloads, not moderating a model's generated content.
- ✗
Data poisoning prevention during training
Why it's wrong here
Data poisoning prevention protects the training pipeline from corrupted or manipulated datasets, so it cannot stop a deployed model from emitting malicious code at inference time. It would be correct if the concern were attackers tampering with training data to skew the model's learned behaviour.
- ✗
Red teaming the model before deployment
Why it's wrong here
Red teaming probes a deployed model for weaknesses but does not block malicious code generation at inference time; it is a pre-deployment assurance activity. It would suit validating safety posture before launch, yet the scenario needs runtime filtering that refuses harmful coding requests.
About these practice questions
One of 962 original AI0-001 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.