CompTIA PenTest+ (PT0-003)Attacks and ExploitsHard

A pilot program deploys an AI chatbot that can browse and summarize web pages for users. A tester embeds hidden instructions in the HTML of a webpage, invisible to human readers, directing the model to reveal the user's active session token when the page is summarized. Which type of attack does this represent?

  1. AAdversarial perturbation
  2. BModel inversion attack
  3. CDirect prompt injection
  4. DIndirect prompt injection
Show answer & explanation

Correct answer: D. Indirect prompt injection

Indirect prompt injection occurs when malicious instructions are embedded in external content (such as a webpage) that the AI model later processes, causing it to execute unintended actions. Direct prompt injection involves the attacker typing malicious input straight into the chat interface, model inversion attempts to extract training data, and adversarial perturbation manipulates model input (often images) to cause misclassification.

Why the other options are wrong

  • A. Adversarial perturbation manipulates input data to fool classifiers, not text-based instruction hijacking.
  • B. Model inversion aims to reconstruct training data, unrelated to this scenario.
  • C. Direct injection means the attacker interacts with the prompt directly, not through external content.

Indirect Prompt Injection

An AI attack where malicious instructions are hidden in external data sources (webpages, documents, emails) that an LLM later processes, causing unintended behavior.

  • Payload is hidden in content, not typed directly by the attacker
  • Exploits AI agents that browse/summarize/process external data
  • Can lead to data exfiltration or unauthorized actions

Memory trick: 'Indirect injection hides in the page, waiting for the bot to read it'

More Attacks and Exploits questions