Courseiva

AI0-001 · topic practice

AI Security practice questions

This domain covers securing AI systems across their lifecycle: defending against adversarial inputs, preventing data leakage and memorization, enforcing content safety at the application layer, and mitigating prompt injection in retrieval-augmented LLM applications. Questions present realistic deployment scenarios and ask you to select the most effective control for the stated threat.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: AI Security

What the exam tests

What to know about AI Security

You must match each AI security threat to the correct control: adversarial training for adversarial examples, differential privacy for memorization, layered filtering for jailbreaks, and retrieval sanitization for indirect prompt injection. The single most important thing is identifying where the attack enters the pipeline.

Adversarial example defenses such as adversarial training and input preprocessing for image models

Privacy techniques including differential privacy and regularization to prevent training-data memorization

Application-layer LLM safeguards like input filtering, output moderation, and system prompt hardening

Indirect prompt injection mitigation for RAG chatbots using retrieved external database content

Watch out for

Common AI Security exam traps

  • ▸Choosing model retraining as a defense against prompt injection when the attack occurs through retrieved external content at inference time.
  • ▸Confusing differential privacy with encryption or access control; differential privacy adds noise to training or outputs to limit individual record influence.
  • ▸Assuming a system prompt alone stops jailbreaks; layered input and output filtering is needed at the application layer.

Practice set

AI Security questions

20 questions · select your answer, then reveal the explanation

Question 1hardmultiple choice
Read the full AI Security explanation →

A security team is threat modeling an AI system that recommends financial products. They want to analyze threats unique to the ML pipeline using STRIDE. Which threat is LEAST applicable to the data collection and preprocessing stage?

Question 2hardmultiple choice
Read the full AI Security explanation →

A financial firm deploys an LLM for automated trading advice. To prevent over-reliance, which combination of guardrails should be implemented? (Assume multiple options but choose the MOST comprehensive single approach.)

Question 3easymultiple choice
Read the full AI Security explanation →

An organization deploys a large language model (LLM) to summarize confidential emails. They are concerned about sensitive information being exposed through the model's responses. Which attack should they be MOST worried about?

Question 4hardmultiple choice
Read the full AI Security explanation →

A machine learning engineer notices that a fraud detection model's false positive rate has increased significantly over the past week. The model was retrained two weeks ago with new data. Which attack is MOST likely responsible?

A security team is threat modeling an AI-powered recommendation system. Using STRIDE, which THREE threats are MOST relevant to the model's training data pipeline?

Question 6easymultiple choice
Read the full AI Security explanation →

An organization uses a third-party pre-trained model for a medical diagnosis system. Which supply chain security measure is MOST critical to verify before deployment?

Question 7mediummultiple choice
Read the full AI Security explanation →

An AI chatbot is being developed to assist with customer support. The team is concerned about prompt injection attacks where malicious users try to override the system's instructions. Which defense is MOST effective against direct prompt injection?

Question 8mediummultiple choice
Read the full AI Security explanation →

A developer is building an AI-powered code completion tool. They want to ensure that the tool does not inadvertently suggest insecure code patterns. Which practice is MOST effective for reducing this risk?

Question 9easymultiple choice
Read the full AI Security explanation →

During a penetration test, a security analyst crafts a prompt that tricks an LLM into revealing its system prompt. Which OWASP LLM Top 10 vulnerability does this exploit?

A security team is reviewing an LLM-powered application that can execute SQL queries based on user requests. They want to implement defenses against prompt injection that could lead to unauthorized database access. Which TWO controls are MOST effective? (Select two.)

Question 11mediummultiple choice
Read the full AI Security explanation →

A developer is building an LLM-powered code assistant. They want to prevent the model from generating insecure code. Which OWASP LLM Top 10 category is most relevant to this risk?

Question 12hardmultiple choice
Read the full AI Security explanation →

A company deploys a chatbot that frequently gives outdated information. They want to implement a defense against prompt injection that also ensures responses are based on verified knowledge. Which approach is best?

An organization is deploying an LLM-based customer support agent. They want to protect against prompt injection attacks. Which THREE measures should they implement? (Select THREE.)

Question 14mediummultiple choice
Read the full AI Security explanation →

A security analyst at a fintech company is alerted to anomalous API requests to their deployed LLM chatbot. The requests contain carefully crafted inputs that cause the model to generate responses that include internal system prompts. Which type of attack is MOST likely occurring?

Question 15mediummulti select
Read the full AI Security explanation →

A cybersecurity team is red-teaming their internal LLM-powered code assistant. They want to test the model's resistance to jailbreaking techniques that bypass safety guardrails. Which TWO of the following should they include in their red teaming exercise to effectively evaluate jailbreak resilience?

A financial institution is deploying a machine learning model for credit scoring. The security team is concerned about adversarial attacks that could cause the model to misclassify loan applications. Which two of the following are effective defenses against evasion attacks during inference? (Choose two.)

Question 17easymultiple choice
Read the full AI Security explanation →

A software team is integrating a third-party LLM API into an internal knowledge assistant. Before launch, the security lead wants to verify that the provider's model has not been tampered with and that the deployed artifact matches what was evaluated. Which practice BEST supports this verification?

Question 18hardmultiple choice
Read the full AI Security explanation →

A cybersecurity firm is using an AI model to detect network intrusions. An attacker attempts to poison the training data by injecting malicious samples that are labeled as benign. Which technique can the firm use to detect and mitigate this poisoning attack during training?

Question 19mediummultiple choice
Read the full AI Security explanation →

A security analyst is evaluating adversarial threats to a deployed image classifier. Which attack involves making tiny, often imperceptible changes to input images to cause misclassification?

Question 20mediummultiple choice
Read the full AI Security explanation →

A company uses a third-party LLM API to power its customer support chatbot. To prevent prompt injection attacks, which defense is MOST effective at the application layer?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused AI Security sessions

Start a AI Security only practice session

Every question in these sessions is drawn from the AI Security domain — nothing else.

Related practice questions

Related AI0-001 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the AI0-001 exam test about AI Security?
You must match each AI security threat to the correct control: adversarial training for adversarial examples, differential privacy for memorization, layered filtering for jailbreaks, and retrieval sanitization for indirect prompt injection. The single most important thing is identifying where the attack enters the pipeline.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just AI Security questions in a focused session?
Yes — the session launcher on this page draws every question from the AI Security domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other AI0-001 topics?
Use the topic links above to move to related areas, or go back to the AI0-001 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the AI0-001 exam covers. They are not copied from any real exam or dump site.