Courseiva
AI Security →mediumMultiple Select

AI0-001 AI Security Practice Question

A startup is building a medical diagnosis support system using a large language model. To prevent the model from generating harmful advice due to hallucinations, which TWO measures should they implement as part of their AI security strategy?

⚠ Common exam trap

CompTIA AI often tests the distinction between inference-time security controls (like RAG and output filtering) versus training-time or data-protection measures (like federated learning, adversarial training, or anomaly detection), leading candidates to select options that are valid security techniques but do not directly address the specific threat of hallucinated harmful advice.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Ground the model using Retrieval-Augmented Generation (RAG) with curated medical databases

Option A is correct because Retrieval-Augmented Generation (RAG) grounds the LLM's responses in curated, authoritative medical databases, so the model retrieves verified evidence at inference time rather than relying solely on parametric memory, which directly reduces hallucinated medical advice. Option D is correct because output filtering and content moderation act as a defense-in-depth control that inspects the model's generated text and blocks harmful, unsafe, or unverified medical recommendations before they reach the user. Option B is not correct here because monitoring for anomalous inputs targets data poisoning detection, which protects training-data integrity but does not directly prevent hallucinated outputs. Option C is not correct because federated learning addresses privacy-preserving decentralized training, not hallucination prevention. Option E is not correct because adversarial training improves robustness against adversarial examples, not factual grounding or harmful medical advice generation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Ground the model using Retrieval-Augmented Generation (RAG) with curated medical databases

    Why this is correct

    RAG constrains generation to retrieved, curated medical evidence, so responses are grounded in authoritative sources rather than parametric memory alone. This directly reduces hallucinated advice, satisfying the requirement to prevent harmful output in the diagnosis support system.

  • ✗

    Monitor for anomalous inputs to detect data poisoning attempts

    Why it's wrong here

    Anomalous-input monitoring detects data poisoning, where attackers corrupt training data, not hallucinations arising from the model's own inference. It is tempting because poisoning genuinely threatens model integrity, and this control would be correct when the concern is untrusted training pipelines rather than harmful generated advice.

  • ✗

    Employ federated learning to train on decentralized patient data

    Why it's wrong here

    Federated learning keeps patient data on local devices during training, addressing privacy and data-residency, not hallucinated output. It is tempting because decentralised medical training is a real requirement, and it would be correct when the constraint is avoiding central collection of patient records.

  • ✓

    Implement output filtering and content moderation to block harmful or unverified medical advice

    Why this is correct

    Output filtering intercepts generated text before delivery, blocking harmful or unverified medical advice that grounding alone may miss. This defence-in-depth layer satisfies the requirement to prevent hallucination-driven harm reaching users of the diagnosis support system.

  • ✗

    Use robust training techniques like adversarial training

    Why it's wrong here

    Adversarial training hardens models against crafted inputs that flip predictions, but it does not stop a model fabricating plausible falsehoods from its own parameters. It is tempting because adversarial training is a genuine robustness technique, and it would be correct when defending against evasion attacks on a classifier.

About these practice questions

One of 962 original AI0-001 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.