Courseiva
AI Security →easyMultiple Choice

AI0-001 AI Security Practice Question

An AI security analyst is reviewing the OWASP LLM Top 10. Which of the following is listed as the top vulnerability?

⚠ Common exam trap

The AI0-001 exam often tests the OWASP LLM Top 10 by making candidates confuse the most common vulnerability (prompt injection) with the most severe consequence (sensitive information disclosure), leading them to pick Option A instead of D.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Prompt injection

Prompt injection is listed as the top vulnerability in the OWASP LLM Top 10 because it directly exploits the way large language models process and execute user-supplied input. By crafting malicious prompts, an attacker can override the model's intended behavior, bypass safety guardrails, and cause the LLM to execute unauthorized actions or leak sensitive data. This vulnerability is considered the most critical due to its ease of exploitation and the severe impact it can have on LLM-integrated applications.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Sensitive information disclosure

    Why it's wrong here

    Sensitive information disclosure ranks sixth in the OWASP LLM Top 10, not first. It is tempting because it describes real leakage of training data, PII or credentials through model responses, and would be correct if the question asked which vulnerability covers unintended data exposure rather than the top-ranked one.

  • ✗

    Supply chain vulnerabilities

    Why it's wrong here

    Supply chain vulnerabilities rank lower in the OWASP LLM Top 10; the top entry is prompt injection. It tempts because model and dependency compromise is a genuine LLM risk, but the list's first item concerns manipulating model behaviour through crafted input.

  • ✗

    Insecure output handling

    Why it's wrong here

    Insecure output handling sits at LLM05 in the OWASP LLM Top 10, not first. It is tempting because it genuinely covers downstream injection risks when model output reaches browsers, shells or databases without validation, and would be the answer if the question asked about a mid-list entry rather than the top-ranked vulnerability.

  • ✓

    Prompt injection

    Why this is correct

    Prompt injection ranks first in the OWASP LLM Top 10 because manipulated input can override model instructions and cascade into every downstream risk. It satisfies the stem's constraint of identifying the highest-listed vulnerability in that framework.

About these practice questions

One of 962 original AI0-001 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.