Courseiva
AI Security →easyMultiple Choice

AI0-001 AI Security Practice Question

Which OWASP LLM Top 10 vulnerability involves an attacker manipulating the LLM through crafted inputs that override the system's intended instructions?

⚠ Common exam trap

CompTIA often tests candidates' ability to distinguish between the attack vector (prompt injection) and its potential outcomes (e.g., sensitive information disclosure), leading them to incorrectly select the consequence rather than the root vulnerability.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Prompt injection

Prompt injection (Option B) is the correct answer because it directly describes an attack where crafted inputs override the system's intended instructions, causing the LLM to execute unauthorized actions or reveal restricted information. This vulnerability exploits the LLM's inability to distinguish between user-supplied content and system-level directives, effectively hijacking the model's behavior.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Sensitive information disclosure

    Why it's wrong here

    Sensitive information disclosure concerns the model revealing confidential data in its output, not overriding system instructions. It is tempting because both involve harmful outputs, but prompt injection is the vulnerability where crafted inputs hijack the model's intended behaviour; disclosure applies when training or context data leaks.

  • ✓

    Prompt injection

    Why this is correct

    Prompt injection occurs when crafted input overrides the model's system instructions, hijacking its behaviour. It differs from insecure output handling or training-data poisoning, which target downstream execution or model weights rather than instruction hierarchy, directly matching the stem's override scenario.

  • ✗

    Supply chain vulnerabilities

    Why it's wrong here

    Supply chain vulnerabilities concern compromised models, datasets or dependencies introduced before deployment, not runtime instruction override. It is tempting because third-party LLM components genuinely can inject malicious behaviour, making it the right answer when the stem describes a poisoned model or library rather than crafted user input.

  • ✗

    Model denial of service

    Why it's wrong here

    Model denial of service covers resource exhaustion or unbounded consumption that degrades availability, not instruction override. It is tempting because both stem from malicious input, but prompt injection is the vulnerability where crafted prompts replace the system's intended instructions; denial of service applies to flooding or costly queries.

About these practice questions

One of 962 original AI0-001 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.