AI0-001 AI Security Practice Question
An LLM-powered application occasionally generates factual-sounding but incorrect information. Users rely on this output for decision-making. Which risk does this primarily represent?
⚠ Common exam trap
CompTIA often tests the distinction between inherent model flaws (hallucinations) and external attacks (prompt injection), so candidates may confuse the two because both involve unexpected outputs, but the root cause differs—internal generation vs. external manipulation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Hallucinations and over-reliance
The scenario describes an LLM generating plausible but incorrect information (hallucination) and users relying on it for decisions (over-reliance). This directly matches the combined risk of hallucinations and over-reliance, as the model's confident but false outputs can lead to poor decision-making without proper verification.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Hallucinations and over-reliance
Why this is correct
Hallucinations occur when an LLM generates fluent, plausible content unsupported by its training data or any grounding source. Because users act on this fabricated output for decisions, the risk compounds into over-reliance: misplaced trust in confident-sounding text. This directly matches the stem's constraint of factual-sounding but incorrect information driving decision-making.
- ✗
Sensitive information disclosure
Why it's wrong here
Sensitive information disclosure concerns the model revealing confidential training or user data, not fabricating falsehoods. The stem describes hallucination: confident, incorrect output used for decisions. Disclosure would be correct if the application exposed personal or proprietary data it should have withheld.
- ✗
Model denial of service
Why it's wrong here
Model denial of service covers resource exhaustion or degraded availability from excessive or crafted requests, not factual inaccuracy. The scenario describes hallucinated content influencing decisions. Model DoS would be the answer if the application became unresponsive or its inference capacity were consumed.
- ✗
Prompt injection
Why it's wrong here
Prompt injection is an adversarial input that hijacks model instructions, producing attacker-directed output rather than accidental falsehoods. Hallucination — plausible but fabricated content — is the risk here. Prompt injection would be the answer if untrusted input were overriding system prompts or leaking tool access.
About these practice questions
One of 962 original AI0-001 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.