Question 9

Domain 2 — AI Operations, Lifecycle, and Control Environment

An auditor evaluates a large language model deployment and discovers the system uses Retrieval-Augmented Generation with a vector database containing proprietary company documents. Security testing reveals that carefully crafted prompts can extract verbatim passages from the vector database that should not be disclosed to certain user groups. Which OWASP Top 10 for LLM risk category does this vulnerability represent? (Select one!)