Courseiva

AI0-001 Implementing AI Solutions Practice Question

An organization runs a customer-support LLM that calls internal tools to look up order status and issue refunds. Security testing reveals that a user can paste text into the chat that causes the model to invoke the refund tool with an attacker-controlled amount. The team wants to reduce this prompt-injection risk without removing tool functionality. Which control is MOST effective?

⚠ Common exam trap

The trap here is assuming prompt-level defenses such as system instructions or fine-tuning can serve as a security boundary for tool calls, when enforceable controls belong in the backend.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enforce authorization and parameter validation in the tool backend so refund requests are validated against the authenticated user's entitlements and business limits.

Prompt injection cannot be fully solved at the model layer, so the durable control is to enforce authorization and business rules in the tool backend where the model cannot influence them. Validating the authenticated user's entitlements and refund limits means a manipulated model still cannot perform unauthorized actions. Prompt instructions, temperature changes, and fine-tuning all rely on model compliance and fail as security boundaries.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enforce authorization and parameter validation in the tool backend so refund requests are validated against the authenticated user's entitlements and business limits.

    Why this is correct

    Placing authorization and validation in the tool backend creates a deterministic control that the model cannot talk its way past, because the refund service independently checks the caller's identity, order ownership, and amount limits. This defense-in-depth approach assumes the LLM may be manipulated and ensures that even a successful injection cannot exceed the user's actual entitlements, which is the standard pattern for agentic AI.

  • ✗

    Fine-tune the model on a curated dataset of injection attempts so it learns to recognize and refuse malicious prompts.

    Why it's wrong here

    Fine-tuning can improve refusal behavior on known patterns but cannot cover the open-ended space of injection techniques, and new bypasses emerge continuously. It also does not prevent a successful novel injection from reaching the refund tool. Treating model behavior as the security boundary leaves the financial action unprotected whenever the model is fooled.

  • ✗

    Increase the model's temperature to zero so that responses become deterministic and injection attempts produce consistent refusals.

    Why it's wrong here

    Lowering temperature changes sampling variability, not the model's susceptibility to instruction injection. A deterministic model will simply produce the same injected behavior every time, which is worse for security because the exploit becomes reliable. Determinism also does not create any authorization check between the model's request and the refund tool's execution.

  • ✗

    Add a system prompt instruction telling the model to ignore any user instructions that attempt to change its tool-use policy.

    Why it's wrong here

    System prompt hardening is easily bypassed by adversarial inputs and offers no deterministic guarantee, especially when untrusted text is interpreted as instructions. Because the model's compliance is probabilistic, a single successful injection still results in an unauthorized refund. This control reduces casual abuse but does not provide the enforceable boundary needed to protect a financial action.

About these practice questions

Courseiva writes every AI0-001 question from scratch — 962 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.