AI0-001 AI Security Practice Question
Which OWASP LLM Top 10 category describes the risk when an LLM's output is not validated and leads to server-side request forgery or remote code execution?
⚠ Common exam trap
CompTIA often tests the distinction between input-side attacks (Prompt Injection) and output-side risks (Insecure Output Handling), so candidates may confuse the two because both involve injection-like behavior, but the key is whether the vulnerability originates from the input to the LLM or from the LLM's output to downstream systems.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Insecure output handling
Insecure output handling (D) is correct because it directly addresses the risk when an LLM's output is not validated or sanitized before being passed to downstream systems. This can lead to server-side request forgery (SSRF) if the output contains URLs that are fetched by the backend, or remote code execution (RCE) if the output is interpreted as code or commands. The OWASP LLM Top 10 defines this category as failing to properly handle model outputs, which can enable injection attacks beyond the LLM itself.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Model denial of service
Why it's wrong here
Model denial of service concerns resource exhaustion that degrades or halts the model's availability, not execution of malicious output. It is tempting because flooding an LLM with costly queries is a real risk, yet the scenario describes output-driven SSRF and code execution rather than service unavailability.
- ✗
Sensitive information disclosure
Why it's wrong here
Sensitive information disclosure covers leakage of confidential data through model output, not execution of attacker-controlled instructions. It is tempting because unvalidated output can expose secrets, yet the SSRF and remote code execution described stem from the model's output being trusted and executed by downstream systems.
- ✗
Prompt injection
Why it's wrong here
Prompt injection manipulates model input to alter behaviour, not unvalidated output flowing into downstream execution. The stem describes insecure output handling, where LLM responses reach SSRF or RCE sinks without sanitisation. Prompt injection would be the answer if the question concerned adversarial instructions embedded in retrieved content hijacking the model's actions.
- ✓
Insecure output handling
Why this is correct
Insecure output handling describes failing to validate or sanitise LLM output before passing it downstream. Untrusted model text reaching interpreters or request functions enables server-side request forgery and remote code execution, satisfying the scenario's described consequence.
About these practice questions
One of 962 original AI0-001 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.