AI0-001 AI Security Practice Question
A company uses a third-party LLM API to power its customer support chatbot. To prevent prompt injection attacks, which defense is MOST effective at the application layer?
⚠ Common exam trap
The trap is choosing output filtering because it sounds like a safety net — but the question asks for the MOST effective application-layer defense, and prevention (input validation) beats detection (output filtering) for prompt injection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Input validation and sanitization
Input validation and sanitization at the application layer is the most effective defense against prompt injection because it stops malicious instructions from ever reaching the LLM. By filtering, escaping, or rejecting inputs that contain injection patterns (e.g., 'ignore previous instructions', role-play overrides, or embedded system-prompt delimiters), the application prevents the model from being manipulated. This is a preventive control applied before inference, which is stronger than detective controls applied after the model responds.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Differential privacy during training
Why it's wrong here
Differential privacy adds noise during model training to protect individual records in the training set; it does nothing about malicious instructions embedded in runtime prompts. It is tempting because it is a genuine privacy defence, and would be correct if the requirement were preventing training-data memorisation rather than blocking injection.
- ✓
Input validation and sanitization
Why this is correct
Sanitising and validating input strips or neutralises injected instructions before they reach the model, directly blocking the untrusted-data-to-instruction pathway. Because the constraint is application-layer defence against prompt injection, this control sits in front of the third-party API and needs no model retraining or vendor change.
- ✗
Rate limiting API calls
Why it's wrong here
Rate limiting caps request volume; it does nothing to stop injected instructions inside user or retrieved content. It is tempting because rate limiting is a standard API abuse control, and would be correct when defending against brute-force or denial-of-service traffic rather than adversarial prompt content.
- ✗
Output filtering of model responses
Why it's wrong here
Filtering responses catches leaked output but cannot stop injected instructions from altering the model's behaviour or triggering tool calls, since the malicious input is processed before any output exists. It is tempting because output filtering genuinely mitigates harmful or sensitive content generation, which is a different problem from instruction hijacking.
About these practice questions
Courseiva writes every AI0-001 question from scratch — 962 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.