AI0-001 AI Security Practice Question
A hospital deploys an LLM assistant that answers clinician questions using a retrieval-augmented generation pipeline over internal patient records. Administrators worry that a malicious document placed in the retrieval index could hijack the assistant's behavior. Which control directly mitigates this indirect prompt injection risk?
⚠ Common exam trap
The trap here is assuming that tuning model behavior or securing the data store addresses prompt injection, when the vulnerability is the blending of untrusted retrieved text with instruction context.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Sanitize and validate retrieved content, and isolate it from system instructions in the prompt structure.
Indirect prompt injection exploits the model's tendency to follow instructions embedded in retrieved content. Treating retrieved documents strictly as data, sanitizing them, and separating them from system-level instructions removes the channel the attacker relies on. The other options affect model randomness, domain adaptation, or storage security, none of which prevent injected text from being interpreted as commands.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Fine-tune the LLM on a corpus of approved clinical question-and-answer pairs.
Why it's wrong here
Fine-tuning shapes style and domain knowledge but does not create a reliable boundary between instructions and untrusted retrieved data at inference time. A crafted document in the index can still override behavior, so fine-tuning alone is insufficient for preventing indirect prompt injection in this hospital assistant.
- ✗
Enable encryption of the retrieval index at rest and rotate its access keys.
Why it's wrong here
Encrypting the index and rotating keys protects stored data from unauthorized access, but the attack described assumes a malicious document is already inside the retrieval corpus and gets fetched legitimately. Storage protections do not change how the model interprets retrieved text, so they fail to stop the injection.
- ✓
Sanitize and validate retrieved content, and isolate it from system instructions in the prompt structure.
Why this is correct
Indirect prompt injection occurs when untrusted retrieved text is treated as instructions. Sanitizing retrieved chunks and clearly delimiting them as data, separate from the system prompt, prevents embedded directives from being interpreted as commands. This directly addresses the attack path in the RAG pipeline while preserving the assistant's ability to use patient records as reference material.
- ✗
Increase the model's temperature setting so responses are less deterministic.
Why it's wrong here
Temperature controls sampling randomness and has no bearing on whether retrieved text is treated as instructions. Raising it would make clinical answers less consistent and potentially less safe, while an injected directive in a retrieved document could still be followed. It does not mitigate indirect prompt injection in the retrieval-augmented pipeline.
About these practice questions
One of 962 original AI0-001 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.