0301
During an authorized retail-company assessment (RET-LAB-M01-301), which action most directly controls the risk related to "prompt injection against AI systems"?
View answer choices
- Give plugins domain-administrator privileges.
- Treat every model response as trusted executable code.
- Separate trusted instructions from untrusted content, minimize tool privileges, validate outputs, and require approval for sensitive actions.
- Disable logging so prompts cannot be reviewed.