Courseiva
AI Security →hardMultiple Choice

AI0-001 AI Security Practice Question

An AI system is designed to automatically execute actions on behalf of users, such as sending emails. The security team is concerned about excessive agency. Which mitigation is most effective?

⚠ Common exam trap

AI0-001 often tests the misconception that a 'bigger model' or 'more context' improves safety — candidates pick B or D, but the correct mitigation is always least-privilege tool scoping plus human approval.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Restrict the functions the model can call and require human approval for sensitive actions

Excessive agency is mitigated by least-privilege scoping of the tools/functions the model can invoke and inserting human-in-the-loop approval for high-impact actions like sending emails. Restricting callable functions and requiring approval directly limits the blast radius of a compromised or misaligned agent.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Disable output filtering

    Why it's wrong here

    Disabling output filtering removes a control that inspects or blocks harmful model output, worsening the exposure rather than limiting the agent's authority. It is tempting because filtering is sometimes seen as latency overhead, but the mitigation for excessive agency is restricting tool permissions and requiring confirmation before actions execute.

  • ✗

    Increase the model's context window

    Why it's wrong here

    A larger context window only lets the model process more tokens; it does not restrict which tools or actions the agent may invoke. It is tempting because context size is a common tuning lever for capability, but excessive agency is mitigated by scoping permissions, limiting available tools and adding human approval before execution.

  • ✓

    Restrict the functions the model can call and require human approval for sensitive actions

    Why this is correct

    Excessive agency arises when a model can invoke tools or actions beyond what the task requires. Restricting callable functions to a minimal allowlist and gating sensitive operations such as sending emails behind human approval directly limits the blast radius, satisfying the security team's concern about autonomous action.

  • ✗

    Use a larger model

    Why it's wrong here

    Model size does not constrain what actions the agent may take; a larger model can still send emails or invoke tools unchecked. It is tempting because scaling models improves capability and reasoning, but excessive agency is bounded by permission scoping, human approval gates and least-privilege tool access, not parameter count.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

Courseiva writes every AI0-001 question from scratch — 962 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.