All templates
Developer & Engineering

LLM Prompt Injection Awareness & Mitigation Practices Survey

Measures developer awareness of prompt injection threats, captures current security mitigation practices, and identifies gaps in LLM application defense. Designed for engineering teams building or evaluating LLM-integrated features.

Sample questions

A preview of what’s in the template. Every question is editable before you launch.

24 questions · ~11 min
Q01
Message

Welcome! Thank you for participating in this survey about your experiences with LLM application development and security. Your participation is entirely voluntary, and you may stop at any time. There are no right or wrong answers — we are interested in your honest perspectives and practices. All responses are confidential and will be reported only in aggregate. This survey takes approximately 6–8 minutes to complete.

Q02
Multiple Choice

Which area best describes your primary role?

  • Back-end engineering
  • Front-end engineering
  • Full-stack engineering
  • Machine learning / data science
  • DevOps / SRE
  • Security engineering
  • QA / Test automation
  • Other (please specify)
Q03
Opinion Scale

How confident are you in your personal understanding of prompt injection risks and mitigations?

Scale: 17
Min:Not at all confidentMax:Extremely confident
Q04
Multiple Choice

Which of the following threat vectors do you consider when designing or reviewing LLM features? Select all that apply.

  • Prompt injection (malicious instructions in user input)
  • Indirect prompt injection via external content sources
  • Jailbreaks / model override of system policies
  • Data exfiltration or leakage via prompts or responses
  • Tool misuse or over-permissioned agent actions
  • Training data poisoning
  • Prompt leakage or system prompt version exposure
  • None of these
Q05
Multiple Choice

Which of the following prompt injection mitigations has your team adopted? Select all that apply.

  • Input validation and sanitization of user prompts
  • System prompt hardening (e.g., instruction hierarchy, delimiters)
  • Output filtering or content safety checks
  • Role-based access controls for LLM tool/action permissions
  • Monitoring and logging of LLM interactions
  • Canary tokens or honeypots in system prompts
  • Sandboxing or isolation of LLM execution environments
  • None of these
  • Not sure
Q06
Multiple Choice

In the last 6 months, have you encountered suspected prompt injection or jailbreak activity in your systems?

  • Yes — confirmed incident
  • Possibly — suspicious behavior, not confirmed
  • No
Q07
Ranking

Rank the following metrics by how much you prioritize them when evaluating prompt injection mitigations (top = highest priority).

  1. False positive rate (legitimate inputs incorrectly blocked)
  2. Detection rate (malicious inputs correctly caught)
  3. Latency impact on user experience
  4. Ease of implementation and maintenance
  5. Coverage across attack types
Drag to rank
Q08
AI Interview

We'd like to explore your experience with LLM security practices in a bit more depth. An AI moderator will ask a couple of follow-up questions based on your earlier responses.

Q09
Multiple Choice

How many years of professional software development experience do you have?

  • Less than 1 year
  • 1–3 years
  • 4–6 years
  • 7–10 years
  • More than 10 years
Q10
Message

Thank you for completing this survey! Your responses will contribute to a better understanding of LLM security practices across the developer community and help improve secure development guidance.

Q11
Multiple Choice

Which of the following best describes your current involvement with LLM-integrated features?

  • I currently build or maintain LLM-integrated features
  • I am planning to integrate LLMs in the next 6 months
  • I am not currently working with LLMs
Q12
Opinion Scale

How well-prepared is your team or organization to defend against prompt injection attacks on your LLM-integrated applications?

Scale: 17
Min:Not at all preparedMax:Extremely well-prepared
Q13
Ranking

Rank the following LLM security concerns from highest to lowest priority for your work.

  1. Direct prompt injection via user input
  2. Indirect prompt injection via external content
  3. Data leakage via prompts or responses
  4. Over-permissive tool or agent actions
  5. Model override / jailbreak to bypass policies
Drag to rank
Q14
Multiple Choice

How often does your team evaluate for prompt injection or jailbreak risks?

  • Weekly or more often
  • Every 2–3 weeks
  • Monthly
  • Quarterly
  • Less often or never
Q15
Long Text

Briefly describe the incident and how it was handled. Please omit any sensitive or proprietary information.

Q16
Long Text

What is your biggest obstacle to managing prompt injection risk today?

Q17
Long Text

Based on your responses in this survey, please share any additional thoughts or experiences related to LLM security and prompt injection that we haven't covered. (Optional)

Q18
Multiple Choice

Approximately how many employees are in your organization?

  • 1–10
  • 11–50
  • 51–200
  • 201–1,000
  • 1,001–5,000
  • 5,001+
Q19
Multiple Choice

Where have you learned about prompt injection risks and mitigations? Select all that apply.

  • Vendor or framework documentation
  • OWASP Top 10 for LLM Applications
  • Academic papers or preprints
  • Security blogs or newsletters
  • Conference talks or workshops
  • Internal training or peer guidance
  • Social media or forums
  • I have not sought out information on this topic
Q20
Multiple Choice

Which methods does your team use to test for prompt injection vulnerabilities? Select all that apply.

  • Adversarial red teaming by engineers
  • Automated evaluation suites or checklists
  • Unit or integration tests for prompts
  • Canary or honeytoken detection
  • Shadow deployment with monitoring and alerts
  • External penetration testing
  • We do not currently test for this
Q21
Multiple Choice

Where are you primarily located?

  • Africa
  • Asia
  • Europe
  • Latin America
  • Middle East
  • North America
  • Oceania
Q22
Multiple Choice

What is your team's default response policy when LLM input may be unsafe?

  • Allow but sanitize or validate content
  • Block and ask the user for clarification
  • Escalate to human review
  • Varies by context or risk level
  • Not sure
Q23
Multiple Choice

Which industry best describes your organization?

  • Technology / Software
  • Finance / Banking
  • Healthcare
  • Retail / E-commerce
  • Manufacturing
  • Education
  • Government / Nonprofit
  • Other (please specify)
Q24
Multiple Choice

Which types of tools or platforms does your team use to mitigate prompt injection risks? Select all that apply.

  • LLM gateway or proxy with policy enforcement
  • Content moderation or safety APIs
  • Vector database with filtering or access controls
  • Open-source guardrails libraries (e.g., Guardrails AI, NeMo Guardrails)
  • Cloud provider built-in safety features
  • Custom internal middleware or services
  • None

What’s included

  • AI follow-ups

    Adaptive probes on open-ended answers that pull out detail a static form would miss.

  • Attention checks

    Built-in safeguards against rushed answers and low-quality respondents.

  • AI-drafted copy

    Wording, ordering, and branching written by the AI — tuned to your research goal.

  • Auto report

    Themes, quotes, and a plain-English summary write themselves once responses come in.

How it compares

We reviewed the closest templates from other survey tools. Here’s what they do well — and where this template goes further.

Why this template

  • Purpose-built for LLM prompt injection risk, covering awareness, current mitigations (input validation, output filtering, sandboxing, etc.), testing cadence, and tooling adoption specific to LLM-integrated features.
  • Includes an AI follow-up interview segment that can adaptively probe on reported incidents or gaps, rather than relying solely on fixed-choice questions.
  • Combines quantitative signals (opinion scales on confidence/preparedness, ranked prioritization of security concerns and metrics) with open-text incident descriptions and obstacle narratives for richer qualitative context.
  • Captures organizational context (role, team involvement, org size, industry, experience) alongside technical practice questions, enabling segmented analysis of prompt injection readiness across engineering teams.

Jotform

Security Awareness Survey Form Template

A general information-security awareness survey template, not tailored to LLM or prompt injection risks. It's a ready-to-field static form built for broad security topics like phishing and password hygiene rather than AI-specific threat vectors. Useful as a starting point but requires heavy customization to address LLM application security.

What it does well

  • Ready-to-use drag-and-drop form builder for quick deployment
  • Broad applicability across general security awareness topics
  • Likely integrates with Jotform's wider form/workflow ecosystem

Where it falls short

  • No LLM or prompt injection-specific question content
  • Static question set with no adaptive AI follow-up interviewing
  • No automated per-response quality scoring or transparent AI prompt methodology

SurveyMonkey

Security Awareness Survey Template

A generic security awareness survey template aimed at general workforce training topics, not LLM-integrated engineering teams or prompt injection specifically. It offers a standard fixed-question format typical of SurveyMonkey's template library. Teams would need to build custom questions from scratch to capture LLM security practices.

What it does well

  • Established survey platform with strong distribution and reporting tools
  • Simple template structure for fast setup
  • Benchmarking and analytics features typical of SurveyMonkey's suite

Where it falls short

  • No content addressing prompt injection, jailbreaks, or LLM-specific mitigations
  • Fixed-form design lacks adaptive or voice AI interviewing capability
  • No transparent AI prompt disclosure or automated quality scoring per response

Ready to launch?

Open this template in the editor. Every part is yours to change before the first respondent sees it.

Related templates

More studies from the same category.

See all
Developer & Engineering

OpenTelemetry Adoption & Readiness Assessment

Measures developer familiarity, adoption stage, blockers, and rollout priorities for OpenTelemetry across engineering teams to inform instrumentation strategy and resource planning.

View template
Developer & Engineering

Open Source Contributor Experience & Governance Survey

Measures contribution path clarity, governance transparency, maintainer responsiveness, and improvement priorities for open-source projects. Designed for project maintainers seeking to improve contributor satisfaction and retention.

View template
Developer & Engineering

Developer Open-Source License Compliance Experience Survey

Measures how developers navigate open-source license compliance, including confidence levels, tooling satisfaction, workflow clarity, and key barriers. Designed for engineering teams and developer-tool organizations seeking to improve compliance processes and SBOM adoption.

View template
Developer & Engineering

Observability Stack ROI Assessment

Measures perceived return on investment from logs, metrics, tracing, and monitoring tools across DevOps and SRE teams, identifying high-impact areas for investment and key barriers to value realization.

View template
Developer & Engineering

Developer Productivity & AI Tooling Adoption Survey

Measures developer productivity, AI coding tool adoption and barriers, code quality practices, and professional growth for engineering teams. Designed for 6–8 minute completion with branching logic for AI tool users vs. non-users.

View template
Developer & Engineering

Developer Experience Survey: Docs, Samples & Events

Measures developer satisfaction and outcomes across documentation, code samples, and community events to surface actionable improvement priorities for developer relations and product teams.

View template