Study. uk . com
  1. Home
  2. All questions
  3. Question 472

CISSP study material · question 472 of 500

A team asks whether prompt injection against a language model falls inside the OWASP web application injection category. What is the position in the 2025 list?

  1. It is included in the injection category as a new weakness type.
  2. It is out of scope for OWASP entirely.
  3. It is included in the insecure design category instead.
  4. It is a related class handled separately in OWASP's list for large language models.
Show the answer

Answer: D. It is a related class handled separately in OWASP's list for large language models.

The 2025 injection entry notes a related class of injection vulnerabilities has become common in large language models and that these are discussed separately in OWASP's own list for them.

Source: OWASP Top 10 A05:2025 (OWASP) — OWASP Top 10:2025 A05 Injection > Description

Challenge yourself on this topic → Study as cards