Courseiva
AI Security →mediumMultiple Choice

AI0-001 AI Security Practice Question

An LLM-powered application occasionally generates factual-sounding but incorrect information. Users rely on this output for decision-making. Which risk does this primarily represent?

⚠ Common exam trap

CompTIA often tests the distinction between inherent model flaws (hallucinations) and external attacks (prompt injection), so candidates may confuse the two because both involve unexpected outputs, but the root cause differs—internal generation vs. external manipulation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Hallucinations and over-reliance

The scenario describes an LLM generating plausible but incorrect information (hallucination) and users relying on it for decisions (over-reliance). This directly matches the combined risk of hallucinations and over-reliance, as the model's confident but false outputs can lead to poor decision-making without proper verification.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Hallucinations and over-reliance

    Why this is correct

    Hallucinations occur when an LLM generates fluent, plausible content unsupported by its training data or any grounding source. Because users act on this fabricated output for decisions, the risk compounds into over-reliance: misplaced trust in confident-sounding text. This directly matches the stem's constraint of factual-sounding but incorrect information driving decision-making.

  • ✗

    Sensitive information disclosure

    Why it's wrong here

    Sensitive information disclosure concerns the model revealing confidential training or user data, not fabricating falsehoods. The stem describes hallucination: confident, incorrect output used for decisions. Disclosure would be correct if the application exposed personal or proprietary data it should have withheld.

  • ✗

    Model denial of service

    Why it's wrong here

    Model denial of service covers resource exhaustion or degraded availability from excessive or crafted requests, not factual inaccuracy. The scenario describes hallucinated content influencing decisions. Model DoS would be the answer if the application became unresponsive or its inference capacity were consumed.

  • ✗

    Prompt injection

    Why it's wrong here

    Prompt injection is an adversarial input that hijacks model instructions, producing attacker-directed output rather than accidental falsehoods. Hallucination — plausible but fabricated content — is the risk here. Prompt injection would be the answer if untrusted input were overriding system prompts or leaking tool access.

About these practice questions

One of 962 original AI0-001 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.