AI0-001 AI Security Practice Question
An LLM-based chatbot is being deployed for customer support. The security team wants to prevent the bot from generating toxic or harmful responses. Which defense is MOST appropriate?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Output filtering and guardrails
Output filtering and guardrails can block harmful content before it reaches the user. Input validation sanitizes inputs, red teaming identifies vulnerabilities, and rate limiting prevents abuse but not toxic content.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Input validation and sanitization
Why it's wrong here
Sanitising prompts filters user-supplied text, but toxic output can be generated from benign input, so the model's own completions remain unfiltered. It is tempting because input validation is the standard defence against injection, and it would be correct for blocking prompt-injection payloads or disallowed request content before inference.
- ✗
Rate limiting on API requests
Why it's wrong here
Rate limiting caps request volume per client, addressing abuse and cost, but a single well-formed request can still yield a toxic completion. It is tempting because it is a cheap, familiar API gateway control, and it would be correct for throttling traffic, preventing denial-of-service or controlling token spend.
- ✓
Output filtering and guardrails
Why this is correct
Output filtering inspects the model's generated text before it reaches the user, blocking toxic or harmful content regardless of how the prompt was phrased. Guardrails enforce policy at that boundary, satisfying the requirement to prevent harmful responses rather than merely discouraging them through input sanitisation.
- ✗
Red teaming the AI system
Why it's wrong here
Red teaming is a periodic adversarial assessment that discovers weaknesses and informs remediation; it does not block a response at inference time. It is tempting because it directly targets harmful outputs, and it would be correct for validating guardrail coverage or measuring residual risk before and after deployment.
About these practice questions
This AI0-001 question is part of Courseiva's 962-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.