AI0-001 AI Security Practice Question
A security engineer is hardening an LLM-based API against OWASP LLM Top 10 risks. Which THREE risks should the engineer prioritize for mitigation?
⚠ Common exam trap
CompTIA often tests the distinction between general web application risks (like insecure deserialization) and LLM-specific risks (like prompt injection), so candidates mistakenly select D because they confuse the OWASP Top 10 for web apps with the OWASP LLM Top 10.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Insecure output handling
Insecure output handling (A) is a core OWASP LLM Top 10 risk because LLM output passed to downstream systems without validation or sanitization can lead to XSS, SSRF, or remote code execution, so it must be prioritized. Training data poisoning (B) is also on the OWASP LLM Top 10 list, as manipulated or unvetted training/fine-tuning data can embed backdoors, bias, or malicious behavior into the model, directly threatening API integrity. Prompt injection (C) is the top-ranked OWASP LLM risk, since attackers can override system instructions or exfiltrate data through crafted inputs, making it essential for an LLM API hardening effort. Insecure deserialization (D) belongs to the OWASP Top 10 for web applications, not the LLM Top 10, and model quantization errors (E) are a model-performance/implementation concern rather than a recognized OWASP LLM Top 10 risk.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Insecure output handling
Why this is correct
Insecure output handling occurs when LLM responses are passed to downstream interpreters without validation, enabling cross-site scripting, command injection or SSRF. Mitigating it is a priority because the API's output crosses a trust boundary into other systems, a core OWASP LLM Top 10 risk.
- ✓
Training data poisoning
Why this is correct
Training data poisoning corrupts the model's learned behaviour at its source, so mitigations must cover data provenance, curation and integrity checks. It is a recognised OWASP LLM Top 10 risk and warrants prioritisation for an LLM-based API.
- ✓
Prompt injection
Why this is correct
Prompt injection manipulates model behaviour by embedding adversarial instructions in inputs, potentially bypassing safeguards and exposing data. It is a core OWASP LLM Top 10 risk, so prioritising mitigation for an LLM-based API is warranted.
- ✗
Insecure deserialization
Why it's wrong here
Insecure deserialization is a classic web application risk, absent from the OWASP LLM Top 10, which covers prompt injection, insecure output handling, training-data poisoning and similar model-layer threats. It would be the right focus for a conventional API deserialising untrusted objects, not an LLM endpoint.
- ✗
Model quantization errors
Why it's wrong here
Quantization errors degrade model accuracy and are a performance concern, not an OWASP LLM Top 10 security risk. It is tempting because quantization is a genuine LLM deployment topic, but the Top 10 addresses adversarial inputs, data leakage and excessive agency, not numerical precision loss.
About these practice questions
This AI0-001 question is part of Courseiva's 962-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.