AI0-001 AI Security Practice Question
A company uses an LLM API to generate customer support responses. They want to prevent the LLM from generating harmful content, even when users attempt jailbreaking. Which defense is MOST effective at the application layer?
⚠ Common exam trap
The AI0-001 exam often tests the misconception that input validation is sufficient for LLM security, but the trap here is that jailbreaking exploits the model's generative capabilities, which can only be reliably mitigated by inspecting the output after generation, not just the input.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Output filtering and content moderation
Output filtering and content moderation is the most effective defense at the application layer because it directly inspects the LLM's generated response before it reaches the user. This approach can catch and block harmful content that results from successful jailbreaking attempts, which input validation alone cannot prevent since the model may still produce undesirable outputs even with sanitized inputs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Output filtering and content moderation
Why this is correct
Output filtering and content moderation inspects the model's generated text before it reaches the user, blocking harmful content regardless of how a jailbreak prompt manipulated the model. This satisfies the application-layer constraint by catching unsafe responses post-generation, providing a reliable final safeguard even when prompt-level defences are bypassed.
- ✗
Input validation and sanitization
Why it's wrong here
Input validation and sanitisation filter obvious patterns, but jailbreaks use benign-looking phrasing that passes syntactic checks, so harmful content still reaches the model. It is tempting as a cheap first layer, yet the stem's application-layer requirement is met by output moderation and system-prompt guardrails that inspect generated content.
- ✗
Robust training techniques
Why it's wrong here
Robust training techniques shape model behaviour during development, not at the application layer, and cannot be changed through an API you merely call. They are tempting because alignment training reduces harmful outputs generally, but the stem specifies application-layer defence, where prompt filtering and output moderation operate.
- ✗
Rate limiting
Why it's wrong here
Rate limiting caps request volume per client, addressing abuse and cost rather than content harm, so a single well-crafted jailbreak prompt still succeeds. It is tempting because it is a standard API defence, but its axis is throughput control, not semantic filtering of harmful generations.
About these practice questions
This AI0-001 question is part of Courseiva's 962-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.