A security team is integrating an LLM into an automated vulnerability triage pipeline that ingests scanner output and produces prioritized remediation tickets. The team wants to reduce the risk of the LLM fabricating vulnerability details or misattributing CVEs. Which TWO practices best address this concern? (Choose two.)
Cross-checking CVE identifiers against NVD or a similar authoritative database catches misattributions and invented identifiers before they propagate into remediation workflows. The LLM may confuse similar CVEs or invent plausible identifiers, and an external validation step provides deterministic ground truth. This is a reliable control against hallucinated or mismatched vulnerability references.
Why this answer
Fabrication and misattribution are best controlled by grounding output in verifiable evidence and validating identifiers against authoritative sources. Requiring citations to raw scanner findings forces the model to anchor claims, while NVD validation deterministically catches invented or mismatched CVEs. Higher temperature, fine-tuning, and self-reported confidence scores do not provide ground truth and can increase or fail to reduce the risk of incorrect vulnerability details reaching remediation tickets.
Exam trap
The trap here is treating an LLM's self-reported confidence score or a fine-tuning pass as a factual safeguard, when only external grounding and authoritative validation actually prevent fabricated CVEs.