AI0-001 AI Security Practice Question
A large enterprise is developing an internal LLM-powered assistant that can access the internet and execute code. To mitigate risks from excessive agency (e.g., the model performing unauthorized actions), which THREE security measures should be implemented?
⚠ Common exam trap
The AI0-001 exam often tests the distinction between detection controls (like monitoring) and prevention controls (like human approval), leading candidates to select monitoring as a security measure for excessive agency when it only provides visibility, not restriction.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Require human-in-the-loop approval for code execution and write operations
Option B is correct because requiring human-in-the-loop approval for code execution and write operations directly constrains excessive agency by ensuring a human authorizes high-impact actions before the model can perform them. Option C is correct because least-privilege API tokens limit the blast radius of any tool or external access the model invokes, so even a misused token can only perform the minimum permitted operations. Option D is correct because input validation and sanitization reduce prompt-injection vectors that could otherwise hijack the model into issuing unauthorized tool calls or code, which is a primary enabler of excessive agency. Option A is not among the marked answers because monitoring anomalous input patterns is detective and does not by itself prevent unauthorized model actions. Option E is not among the marked answers because output filtering addresses data leakage in responses rather than constraining the model's ability to take unauthorized actions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Deploy monitoring for anomalous input patterns
Why it's wrong here
Monitoring input patterns detects prompt-injection attempts, not excessive agency, which stems from the assistant's own tool permissions and execution scope. It is tempting because input monitoring genuinely addresses prompt-injection and jailbreak risks, so it would be correct where the threat is adversarial manipulation of model inputs rather than unauthorised tool invocation.
- ✓
Require human-in-the-loop approval for code execution and write operations
Why this is correct
Human-in-the-loop approval inserts a person before code execution or write operations, so no unauthorised action occurs without explicit consent. This directly constrains excessive agency, satisfying the stem's requirement to prevent the assistant acting autonomously on destructive or irreversible operations.
- ✓
Use least-privilege API tokens for external tool access
Why this is correct
Least-privilege API tokens restrict each external tool call to only the permissions required, so a compromised or manipulated assistant cannot exceed its granted scope. This limits excessive agency by capping blast radius, satisfying the stem's requirement to prevent unauthorised actions.
- ✓
Implement input validation and sanitization to prevent prompt injection
Why this is correct
Input validation and sanitisation targets prompt injection, where crafted inputs hijack the model's instructions and trigger unauthorised tool calls. This directly constrains excessive agency by blocking the manipulation vector that lets an internet-connected, code-executing assistant act beyond its intended scope, satisfying the stem's requirement to prevent the model performing unauthorised actions.
- ✗
Apply output filtering to block sensitive data in responses
Why it's wrong here
Output filtering masks sensitive data leaving the model, addressing data leakage rather than excessive agency. It is tempting because it is a recognised LLM guardrail, but it would be correct when preventing PII exposure in responses; limiting unauthorised actions needs least-privilege tool scoping, human approval and action logging.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
About these practice questions
Courseiva writes every AI0-001 question from scratch — 962 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.