AI0-001 AI Security Practice Question
A security team is conducting a red team exercise on a new LLM-powered customer support system. Which activity is part of red teaming?
⚠ Common exam trap
CompTIA often tests the distinction between red team (offensive security testing) and blue team (defensive operations) activities, so candidates may confuse tasks like implementing controls or monitoring with red teaming.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Attempting to jailbreak the LLM to bypass safety guardrails
Red teaming in the context of an LLM-powered system involves actively probing for security vulnerabilities, such as attempting to bypass safety guardrails through jailbreak prompts. Option A directly describes this adversarial testing, which is the core activity of a red team exercise to identify weaknesses before malicious actors can exploit them.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Attempting to jailbreak the LLM to bypass safety guardrails
Why this is correct
Jailbreaking probes the model's safety guardrails directly, testing whether adversarial prompts can bypass alignment controls. This adversarial prompt-crafting against the deployed LLM is the defining activity of red teaming, satisfying the scenario's requirement to assess the customer support system's resistance to misuse.
- ✗
Reviewing the model's training data for bias
Why it's wrong here
Bias review is a governance and fairness audit of training data, not adversarial probing. Red teaming actively attacks the deployed system with crafted prompts to expose jailbreaks, data leakage and unsafe outputs. Data bias assessment is correct during model development or compliance review, before deployment.
- ✗
Implementing access controls on the model API
Why it's wrong here
API access controls are preventive security hardening, applied before and independently of any exercise. Red teaming simulates real adversary behaviour to find exploitable weaknesses, so it tests whether those controls hold rather than implementing them. Access control configuration belongs to normal secure deployment, not red teaming.
- ✗
Monitoring system performance metrics
Why it's wrong here
Red teaming actively probes the LLM for prompt injection, jailbreaks and harmful outputs; performance monitoring is operational observability, not adversarial testing. Monitoring is tempting because it is part of running a support system, but it detects degradation rather than deliberately eliciting unsafe behaviour.
About these practice questions
One of 962 original AI0-001 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.