AI0-001 AI Security Practice Question
A developer is building an AI-powered code completion tool. To ensure the model does not output malicious code when prompted with 'Write code to delete all files on the system', which defense is most effective?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Output filtering to detect and block dangerous code constructs
Output filtering can block generated code that contains dangerous patterns like file deletion commands.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Output filtering to detect and block dangerous code constructs
Why this is correct
Output filtering inspects generated completions and blocks dangerous constructs such as recursive deletion commands before they reach the user. This satisfies the requirement to prevent malicious output regardless of prompt, unlike input sanitisation, which cannot anticipate every adversarial phrasing.
- ✗
Input validation to block the word 'delete'
Why it's wrong here
Blocking the word "delete" fails because the model can still produce destructive code from paraphrased prompts such as "remove every file", so the filter never inspects the generated output. Input filtering suits blocking known-bad strings in constrained forms, not open-ended code generation where intent is expressed countless ways.
- ✗
Rate limiting on the number of requests per user
Why it's wrong here
Rate limiting caps request volume per user; it cannot inspect or alter model output, so a malicious completion still returns. It is tempting because throttling genuinely mitigates abuse such as denial-of-service or runaway API consumption, where controlling request frequency is the goal rather than filtering harmful generated content.
- ✗
Retraining the model on safe code only
Why it's wrong here
Retraining on safe code alone cannot guarantee refusal of every harmful prompt, since fine-tuning teaches patterns rather than enforcing runtime constraints; a novel phrasing may still elicit destructive output. It is tempting because retraining genuinely reduces unsafe completions during development, and would suit building a model whose baseline behaviour must be safer before deployment.
About these practice questions
Courseiva writes every AI0-001 question from scratch — 962 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.