Courseiva

AI0-001 AI Security, Ethics and Governance Practice Question

A cybersecurity analyst monitors an AI chatbot that frequently produces offensive responses when given specific prompts. The development team suspects an adversarial attack. Which mitigation strategy is most effective against such prompt injection attacks?

⚠ Common exam trap

The AI0-001 exam often tests the misconception that retraining or model size adjustments can fix security vulnerabilities, when in fact the issue lies in input handling and trust boundaries, not the model's training data or architecture.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement input validation and sanitization

Prompt injection attacks exploit the model's inability to distinguish between user input and system instructions. Input validation and sanitization (e.g., filtering special characters, enforcing strict schema checks, and using allowlists) directly neutralize malicious payloads before they reach the model's inference engine, preventing the model from executing unintended commands.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Retrain the model on a larger, curated dataset

    Why it's wrong here

    Retraining on a curated corpus shapes the model's learned behaviour but leaves it vulnerable to novel adversarial prompts at inference time, since no dataset covers every injection. It is tempting because curated data reduces harmful outputs generally — the right choice for improving baseline safety, not for blocking runtime prompt injection.

  • ✗

    Encrypt all communication between users and the chatbot

    Why it's wrong here

    Transport encryption protects data in transit from interception or tampering, but the chatbot still processes the malicious prompt and generates the offensive reply. It is tempting because encryption is a baseline control for user-to-service traffic — the correct choice when the threat is eavesdropping on the wire, not manipulation of model input.

  • ✗

    Reduce the model's number of parameters

    Why it's wrong here

    Parameter count governs model capacity and generalisation, not input filtering; reducing it does not stop crafted prompts from steering outputs. It is tempting because smaller models are cheaper and less prone to memorising harmful text — the right lever when overfitting or resource constraints, not adversarial prompt manipulation.

  • ✓

    Implement input validation and sanitization

    Why this is correct

    Input validation and sanitisation filter or neutralise malicious prompt content before it reaches the model, directly blocking injected instructions that trigger offensive outputs. This addresses the root cause at the input boundary rather than attempting post-hoc output filtering, satisfying the requirement to mitigate prompt injection.

About these practice questions

Courseiva writes every AI0-001 question from scratch — 962 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.