Courseiva
AI Security →easyMultiple Select

AI0-001 AI Security Practice Question

A security team is auditing an AI system and identifies risks related to the OWASP LLM Top 10. Which TWO risks are directly associated with data handling and privacy? (Select two.)

⚠ Common exam trap

CompTIA AI often tests the distinction between risks that affect data integrity/privacy (like poisoning and disclosure) versus those affecting availability, trust, or supply chain, so candidates mistakenly select overreliance or supply chain vulnerabilities because they seem related to data but are actually about user behavior or third-party dependencies.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Training data poisoning

Option D (Training data poisoning) is correct because it directly concerns the integrity of the data used to train or fine-tune an LLM: attackers can inject malicious or manipulated samples into the training corpus, corrupting model behavior and compromising the confidentiality, integrity, and trustworthiness of the underlying data pipeline. Option E (Sensitive information disclosure) is correct because it is the OWASP LLM Top 10 risk specifically covering leakage of PII, credentials, proprietary text, or other private data through model outputs, often due to memorization of training data, inadequate output filtering, or prompt-based extraction. The other options do not belong: A (Supply chain vulnerabilities) targets third-party models, datasets, and dependencies rather than data privacy itself; B (Model denial of service) is an availability/resource-exhaustion risk; and C (Overreliance) is a human-factors risk of trusting incorrect model output, not a data-handling or privacy issue.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Supply chain vulnerabilities

    Why it's wrong here

    Supply chain vulnerabilities concern compromised third-party models, plugins, or training data sources, not the handling or exposure of personal data within prompts and outputs. It is tempting because training data provenance overlaps with privacy, and it would be the correct selection for questions about untrusted dependencies, model provenance, or plugin integrity.

  • ✗

    Model denial of service

    Why it's wrong here

    Model denial of service concerns resource exhaustion and degraded availability from flooding or costly queries, not the confidentiality or handling of data. It is tempting because it is a genuine OWASP LLM Top 10 entry, and it would be correct for questions about availability, rate limiting, or context-window flooding attacks.

  • ✗

    Overreliance

    Why it's wrong here

    Overreliance concerns users trusting incorrect model output without verification, a human-factors and accuracy risk rather than a data handling or privacy one. It is tempting because it involves the model's outputs, and it would be correct for questions about hallucination impact, inadequate human oversight, or decision-making without validation.

  • ✓

    Training data poisoning

    Why this is correct

    Training data poisoning corrupts the model's learned parameters by injecting manipulated samples during training, directly compromising the integrity of data handling. It appears in the OWASP LLM Top 10 as LLM04, satisfying the stem's requirement for a risk tied to how training data is sourced, curated and protected.

  • ✓

    Sensitive information disclosure

    Why this is correct

    Sensitive information disclosure maps to LLM06 in the OWASP LLM Top 10, covering leakage of confidential data through model outputs. It directly concerns privacy, since training data, prompts or context can be exposed to unauthorised users, breaching confidentiality obligations.

About these practice questions

Courseiva writes every AI0-001 question from scratch — 962 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.