Courseiva
AI Security →easyMultiple Choice

AI0-001 AI Security Practice Question

A security team is conducting a red team exercise on a new LLM-powered customer support system. Which activity is part of red teaming?

⚠ Common exam trap

CompTIA often tests the distinction between red team (offensive security testing) and blue team (defensive operations) activities, so candidates may confuse tasks like implementing controls or monitoring with red teaming.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Attempting to jailbreak the LLM to bypass safety guardrails

Red teaming in the context of an LLM-powered system involves actively probing for security vulnerabilities, such as attempting to bypass safety guardrails through jailbreak prompts. Option A directly describes this adversarial testing, which is the core activity of a red team exercise to identify weaknesses before malicious actors can exploit them.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Attempting to jailbreak the LLM to bypass safety guardrails

    Why this is correct

    Jailbreaking probes the model's safety guardrails directly, testing whether adversarial prompts can bypass alignment controls. This adversarial prompt-crafting against the deployed LLM is the defining activity of red teaming, satisfying the scenario's requirement to assess the customer support system's resistance to misuse.

  • ✗

    Reviewing the model's training data for bias

    Why it's wrong here

    Bias review is a governance and fairness audit of training data, not adversarial probing. Red teaming actively attacks the deployed system with crafted prompts to expose jailbreaks, data leakage and unsafe outputs. Data bias assessment is correct during model development or compliance review, before deployment.

  • ✗

    Implementing access controls on the model API

    Why it's wrong here

    API access controls are preventive security hardening, applied before and independently of any exercise. Red teaming simulates real adversary behaviour to find exploitable weaknesses, so it tests whether those controls hold rather than implementing them. Access control configuration belongs to normal secure deployment, not red teaming.

  • ✗

    Monitoring system performance metrics

    Why it's wrong here

    Red teaming actively probes the LLM for prompt injection, jailbreaks and harmful outputs; performance monitoring is operational observability, not adversarial testing. Monitoring is tempting because it is part of running a support system, but it detects degradation rather than deliberately eliciting unsafe behaviour.

About these practice questions

One of 962 original AI0-001 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.