AI0-001 AI Security Practice Question
An organization uses an LLM to generate financial reports. They want to ensure the model does not output sensitive customer data that it may have memorized during training. Which technique should be implemented in the AI pipeline to detect and block such outputs?
⚠ Common exam trap
The AI0-001 exam often tests the distinction between input controls (validation) and output controls (filtering), tricking candidates into choosing input validation because they focus on preventing data from entering the system rather than catching data that the model generates from memory.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Output filtering
Output filtering is the correct technique because it operates after the LLM generates a response, scanning the output for sensitive data patterns (e.g., PII, financial account numbers) and blocking or redacting them before delivery. This directly addresses the risk of the model regurgitating memorized customer data from its training set, which input validation cannot catch since the sensitive data appears only in the output.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Input validation
Why it's wrong here
Input validation screens prompts entering the model, so it cannot detect sensitive customer data the model emits from memorised training content. It is tempting because it guards the pipeline boundary, but blocking memorised output requires output filtering or guardrails that inspect and redact generated responses.
- ✓
Output filtering
Why this is correct
Output filtering inspects the model's generated text before it reaches the user, applying pattern matching or classifiers to detect and block sensitive customer data. This directly satisfies the requirement to detect and block memorised data at generation time, unlike training-time techniques that cannot intercept a specific response.
- ✗
Rate limiting
Why it's wrong here
Rate limiting caps request volume per client over a time window; it cannot inspect generated tokens for memorised customer data, so sensitive strings still pass through. It is tempting because it genuinely mitigates abuse and cost overruns, and would be the right control when the concern is throughput or denial-of-service rather than output content filtering.
- ✗
Federated learning
Why it's wrong here
Federated learning trains a shared model across decentralised data without centralising it, which reduces memorisation during training but provides no runtime mechanism to detect or block sensitive strings already emitted by an LLM. It would be correct where training data must remain on-device, not for filtering inference output.
About these practice questions
Courseiva writes every AI0-001 question from scratch — 962 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.