AI0-001 AI Security Practice Question
A company uses an AI model to generate personalized marketing emails. They want to prevent the model from leaking the system prompt used to configure its behavior. Which attack should they guard against?
⚠ Common exam trap
CompTIA often tests the distinction between attacks on training data (model inversion, membership inference, data poisoning) versus attacks on the inference-time configuration (prompt leaking), so candidates mistakenly choose a training-data attack when the question explicitly targets the system prompt.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Prompt leaking
Prompt leaking is an attack where an adversary crafts inputs to trick the model into revealing its system prompt or hidden instructions. Since the system prompt defines the model's behavior and often contains proprietary or sensitive configuration details, preventing its disclosure is critical. Guarding against prompt leaking directly addresses the goal of keeping the system prompt confidential.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Prompt leaking
Why this is correct
Prompt leaking is the extraction of the hidden system prompt through crafted queries, so the model reveals its configuration instructions. Guarding against it directly addresses the stated goal of preventing disclosure of the system prompt that shapes the model's behaviour.
- ✗
Model inversion
Why it's wrong here
Model inversion reconstructs training-data features from outputs, not the configuration prompt. It tempts because both are inference-time confidentiality attacks, but it would be correct when the risk is recovering sensitive attributes of the training dataset rather than disclosing instructions.
- ✗
Membership inference
Why it's wrong here
Membership inference attacks aim to determine whether a specific data point was part of the training set, not to extract the system prompt. The scenario requires guarding against prompt leakage, which is a form of model inversion or extraction attack targeting the instruction layer, not the training data. This option is tempting because membership inference is a common privacy concern in AI, and it would be the correct choice if the question asked about protecting the confidentiality of individual customer records used in training the marketing model.
- ✗
Data poisoning
Why it's wrong here
Data poisoning corrupts training data to skew model outputs, so it cannot extract a system prompt at inference time. It is tempting because it targets model integrity, and would be the correct concern when an attacker can influence the training corpus or fine-tuning dataset.
About these practice questions
One of 962 original AI0-001 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.