Courseiva
AI Security →easyMultiple Choice

AI0-001 AI Security Practice Question

A retail company runs a customer-facing chatbot backed by a large language model. The chatbot has access to a tool that looks up order status by order ID. A penetration tester finds that by typing a crafted sentence, a user can make the chatbot call the order-status tool with an arbitrary order ID belonging to another customer and read the response. Which control most directly prevents this unauthorized tool invocation?

⚠ Common exam trap

The trap here is trusting the language model to enforce access control through instructions, when authorization must live in the tool backend outside the model's control.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enforce authorization checks in the tool backend so it only returns orders belonging to the authenticated user.

The flaw is that the tool performs a lookup based solely on a model-supplied order ID, with no check that the order belongs to the authenticated user. Enforcing authorization in the tool backend removes trust from the model and blocks cross-customer access regardless of how the prompt is crafted. Prompt instructions, temperature changes, and after-the-fact logging do not establish that access boundary.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enforce authorization checks in the tool backend so it only returns orders belonging to the authenticated user.

    Why this is correct

    The vulnerability is that the tool trusts the order ID supplied through the model without verifying ownership. Moving the authorization decision into the tool backend, where it can compare the requested order against the authenticated session's customer ID, ensures that even a manipulated prompt cannot retrieve another customer's data. This is the most direct fix because it removes reliance on the model to enforce access control.

  • ✗

    Add a system prompt instructing the model never to reveal other customers' order details.

    Why it's wrong here

    System prompts are soft guidance and can be overridden by crafted user input, especially with prompt injection techniques. The model may still emit a tool call with an attacker-chosen order ID. Relying on the language model to enforce access control places the security boundary in an untrusted component, which is why this does not reliably prevent the unauthorized lookup.

  • ✗

    Increase the model's temperature setting to make its responses less predictable.

    Why it's wrong here

    Temperature affects sampling randomness and has no bearing on whether the model invokes a tool with an unauthorized parameter. Raising it may make outputs less consistent but does not add any access control. The underlying flaw is missing authorization in the tool backend, so changing sampling behavior leaves the vulnerability intact.

  • ✗

    Log every tool call the chatbot makes and review the logs daily for suspicious order IDs.

    Why it's wrong here

    Logging and review provide detection and forensic value but occur after the data has already been disclosed. An attacker can exfiltrate many records before a daily review catches the pattern. Detection is not prevention, and the question asks for the control that most directly prevents the unauthorized invocation, which requires blocking at the authorization layer.

About these practice questions

One of 962 original AI0-001 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.