Courseiva
AI Security →hardMultiple Select

AI0-001 AI Security Practice Question

A large enterprise is developing an internal LLM-powered assistant that can access the internet and execute code. To mitigate risks from excessive agency (e.g., the model performing unauthorized actions), which THREE security measures should be implemented?

⚠ Common exam trap

The AI0-001 exam often tests the distinction between detection controls (like monitoring) and prevention controls (like human approval), leading candidates to select monitoring as a security measure for excessive agency when it only provides visibility, not restriction.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Require human-in-the-loop approval for code execution and write operations

Option B is correct because requiring human-in-the-loop approval for code execution and write operations directly constrains excessive agency by ensuring a human authorizes high-impact actions before the model can perform them. Option C is correct because least-privilege API tokens limit the blast radius of any tool or external access the model invokes, so even a misused token can only perform the minimum permitted operations. Option D is correct because input validation and sanitization reduce prompt-injection vectors that could otherwise hijack the model into issuing unauthorized tool calls or code, which is a primary enabler of excessive agency. Option A is not among the marked answers because monitoring anomalous input patterns is detective and does not by itself prevent unauthorized model actions. Option E is not among the marked answers because output filtering addresses data leakage in responses rather than constraining the model's ability to take unauthorized actions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Deploy monitoring for anomalous input patterns

    Why it's wrong here

    Monitoring input patterns detects prompt-injection attempts, not excessive agency, which stems from the assistant's own tool permissions and execution scope. It is tempting because input monitoring genuinely addresses prompt-injection and jailbreak risks, so it would be correct where the threat is adversarial manipulation of model inputs rather than unauthorised tool invocation.

  • ✓

    Require human-in-the-loop approval for code execution and write operations

    Why this is correct

    Human-in-the-loop approval inserts a person before code execution or write operations, so no unauthorised action occurs without explicit consent. This directly constrains excessive agency, satisfying the stem's requirement to prevent the assistant acting autonomously on destructive or irreversible operations.

  • ✓

    Use least-privilege API tokens for external tool access

    Why this is correct

    Least-privilege API tokens restrict each external tool call to only the permissions required, so a compromised or manipulated assistant cannot exceed its granted scope. This limits excessive agency by capping blast radius, satisfying the stem's requirement to prevent unauthorised actions.

  • ✓

    Implement input validation and sanitization to prevent prompt injection

    Why this is correct

    Input validation and sanitisation targets prompt injection, where crafted inputs hijack the model's instructions and trigger unauthorised tool calls. This directly constrains excessive agency by blocking the manipulation vector that lets an internet-connected, code-executing assistant act beyond its intended scope, satisfying the stem's requirement to prevent the model performing unauthorised actions.

  • ✗

    Apply output filtering to block sensitive data in responses

    Why it's wrong here

    Output filtering masks sensitive data leaving the model, addressing data leakage rather than excessive agency. It is tempting because it is a recognised LLM guardrail, but it would be correct when preventing PII exposure in responses; limiting unauthorised actions needs least-privilege tool scoping, human approval and action logging.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

Courseiva writes every AI0-001 question from scratch — 962 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.