Spring Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70percent

CompTIA CY0-001 CompTIA SecAI+ v1 Exam Exam Practice Test

Demo: 36 questions
Total 126 questions

CompTIA SecAI+ v1 Exam Questions and Answers

Question 1

A security analyst receives an alert about an AI system and is investigating the following output:

Which of the following is the most appropriate control the analyst should recommend?

Options:

A.

Integrating data sanitization

B.

Implementing user input validation

C.

Monitoring logs for attack words from the system

D.

Hardening the Model Context Protocol server

Question 2

Customer feedback for an AI chatbot has a high-rate of non-answers, which is causing higher central processing unit (CPU) utilization.

Which of the following should be implemented?

Options:

A.

Guardrails

B.

Response confidence level

C.

Prompt logging

D.

Cost monitoring

Question 3

An employee wants a consulting company to procure a data set that contains age, ethnicity, and diabetes status. During development, the employer wants to ensure the integrity of the data.

Which of the following is the best strategy to accomplish this task?

Options:

A.

Implementing checksums

B.

Conducting human evaluation

C.

Querying the model

D.

Enabling log monitoring

Question 4

A financial organization implements a new AI-based fraud detection system to flag suspicious transactions. A security analyst discovers that it occasionally blocks legitimate transactions.

Which of the following is the best recommendation?

Options:

A.

Retraining the model with more data and recent transaction patterns

B.

Implementing AI token usage and rate limits

C.

Encrypting all the data processed by AI and applying further access controls

D.

Rolling back the model and using a traditional fraud detection system

Question 5

A security administrator needs to improve an AI model. During an initial investigation, the administrator notices that two successive login failures are recorded every day, and then a successful login occurs after a specific time interval. All the successful login attempts have been during office hours.

Which of the following techniques should the administrator use to improve the AI model ' s security?

Options:

A.

Access management

B.

Pattern recognition

C.

Signature matching

D.

Vulnerability analysis

Question 6

Which of the following describes the number of training cycles used in an AI model for threat detection?

Options:

A.

k-means clustering

B.

Tokens

C.

Temperature

D.

Epoch

Question 7

A security consultant must summarize the impact of posture management on a machine learning (ML) use case.

Which of the following is the most appropriate reference for this purpose?

Options:

A.

Organization for Economic Co-operation and Development (OECD) standards

B.

National Institute of Standards and Technology (NIST) AI Risk Management Framework (RMF)

C.

European Union AI Act

D.

Generative adversarial network (GAN)

Question 8

Which of the following responsible AI standards refers to a principle that clearly states the reasons behind the decisions for a particular conclusion?

Options:

A.

Accountability

B.

Auditability

C.

Transparency

D.

Explainability

Question 9

A multinational company wants to implement an AI-assisted job screening solution.

Which of the following should the company reference to reduce the risk of incurring compliance-related fines?

Options:

A.

International Organization for Standardization (ISO) AI standards

B.

European Union (EU) AI Act

C.

Corporate policy

D.

National Institute of Standards and Technology (NIST) AI Risk Management Framework (RMF)

Question 10

An organization implements a domain-specific AI chatbot. After operating normally for weeks, the model returns contextually incorrect responses — treating ' worm ' as a biological pest rather than a computer worm when answering a cybersecurity question.

Which of the following should the organization do to address the issue?

Options:

A.

Configure guardrails.

B.

Encrypt the weights at rest.

C.

Apply model access controls.

D.

Deploy prompt templates.

Question 11

An AI architect reviews AI utilization and wants to improve the user experience.

Which of the following should the architect review within the logs?

Options:

A.

Rate monitoring

B.

Model accuracy

C.

Access controls

D.

Data storage

Question 12

Which of the following technologies is used in deepfake?

Options:

A.

Generative adversarial network (GAN)

B.

Multi-shot prompting

C.

Prompt engineering

D.

Transfer learning

Question 13

A data scientist is working with unlabeled data and wants to build a clustering model.

Which of the following techniques should a data scientist use?

Options:

A.

Supervised learning

B.

Reinforcement learning

C.

Unsupervised learning

D.

Semi-supervised learning

Question 14

Instructions: Use the drop-down menus to define two appropriate security controls for each component of the AI system. Each control may be used only once.

An engineer is deploying a new AI system and wants to integrate it into the core system through an API.

Options:

Question 15

Which of the following is the primary security risk when deploying AI models in production?

Options:

A.

Graphics processing unit (GPU) acceleration

B.

Model overfitting

C.

Model encryption

D.

Data exposure

Question 16

A management team is concerned about an unexpected cost increase for a public-facing AI chatbot.

Which of the following should a security administrator examine first to determine the root cause?

Options:

A.

Firewall logs

B.

Web application firewall (WAF) rules

C.

Vector database input/output operations per second performance

D.

Model token usage

Question 17

Which of the following attacks would be the best to automate with AI during dynamic application software testing (DAST)?

Options:

A.

Distributed denial-of-service (DDoS)

B.

Data poisoning

C.

Payload creation

D.

Threat modeling

Question 18

A security analyst is preparing a presentation for the sales team that describes the most common vulnerabilities that are specific to AI applications.

Which of the following is the best source for the analyst to consult?

Options:

A.

International Organization for Standards (ISO) 27001

B.

Common Weakness Enumeration (CWE)

C.

Open Worldwide Application Security Project (OWASP)

D.

National Institute of Technologies Risk Management Framework (NIST-RMF)

Question 19

During a model validation procedure, an engineer notices that a model performs well during training but poorly during testing.

Which of the following best describes the reason?

Options:

A.

Fine-tuning

B.

Overfitting

C.

Regularization

D.

Inference

Question 20

A security operations center (SOC) has a very high volume of logs and alerts. The manager proposes the implementation of a machine learning (ML) system to help with triage.

Which of the following tasks is most suitable?

Options:

A.

Applying filters on specific alerts

B.

Automatically patching vulnerable systems

C.

Identifying and classifying alerts

D.

Summarizing the content of alerts

Question 21

Which of the following helps in managing potential security issues related to model training?

Options:

A.

National Institute of Standards and Technology (NIST) AI Risk Management Framework (RMF)

B.

International Organization for Standardization (ISO) 27001

C.

Organization for Economic Co-operation and Development (OECD)

D.

General Data Protection Regulation (GDPR)

Question 22

Which of the following is most resistant to AI manipulation?

Options:

A.

Payloads

B.

AI-generated content

C.

Application programming interface (API) gateway

D.

Attack surface reduction

E.

Antivirus

Question 23

A global security operations center (SOC) wants to adapt and leverage the strength of AI in order to enhance its security operations.

Which of the following is the best way to enhance the global SOC functions?

Options:

A.

Generate code and execute in production to help save time.

B.

Enable a personal assistant that can act in the global SOC with no human intervention.

C.

Use open-source models in production to help the efficiency of threat detection and threat analysis.

D.

Summarize alerts to easily gain insights on the environment.

Question 24

A large number of employees receive a video message in which the company ' s CEO states that the company will be filing for bankruptcy. After an investigation, it was discovered that the CEO did not send this message.

Which of the following is this scenario an example of?

Options:

A.

On-path attack

B.

Phishing

C.

Deepfake

D.

Social engineering

Question 25

A security analyst is aware of an active penetration test in the environment. The analyst examines SIEM log data and notices the following AI system output:

Which of the following is the vulnerability that has occurred and the control the analyst should implement?

Options:

A.

The vulnerability is prompt injection, and the analyst should use endpoint detection response (EDR).

B.

The vulnerability is model hallucinations, and the analyst should develop output validations.

C.

The vulnerability is jailbreaking, and the analyst should utilize role-based access control.

D.

The vulnerability is sensitive information disclosure, and the analyst should employ masking.

E.

The vulnerability is role impersonation, and the analyst should use validation.

Question 26

A detection engineering team wants to use AI to automatically prevent vulnerable code from reaching production.

Which of the following is the most effective way to accomplish this task?

Options:

A.

Deploying an integrated development environment (IDE) plug-in that will warn developers of dangerous code before compiling

B.

Using a security orchestration, automation, and response (SOAR) with a machine learning (ML) model to classify code

C.

Implementing a large language model (LLM) in the continuous integration and continuous deployment (CI/CD) runner to examine code and pass or fail build jobs

D.

Developing an agentic penetration testing tool to validate potential vulnerable code

Question 27

An administrator, who works for a financial institution, is required to implement data security controls for data at rest within AI systems that involve data disclosure.

Which of the following is the most suitable control?

Options:

A.

Data lineage

B.

Rate limits

C.

Encryption

D.

Masking

Question 28

An organization recently created a custom model that integrates with a language model (LLM). The developer notices that the application programming interface (API) costs have increased.

Which of the following is the best control to reduce cost?

Options:

A.

Implementing prompt templates

B.

Increasing central processing unit (CPU) and memory

C.

Reducing the model size

D.

Adjusting token limits

Question 29

An administrator must conduct generative AI cost monitoring for use in the healthcare industry.

Which of the following criteria is the best way to calculate this cost?

Options:

A.

Connection access and exchange gateway

B.

Encryption and decryption processing

C.

Storage retrieval and prompt processing

D.

Catalog servicing and exchange processing

Question 30

A security operations center (SOC) analyst needs to automate multiple security tasks by breaking them down into smaller parts.

Which of the following AI tools is the best for this task?

Options:

A.

Agentic AI

B.

Retrieval-augmented generation (RAG) AI

C.

Generative AI

D.

Chatbot

Question 31

User experience is declining since the launch of a large language model (LLM) in internal networks.

Which of the following should be the highest priority for the prompt engineers?

Options:

A.

Customer success management

B.

Sales life cycle

C.

Quality control

D.

Business objectives

Question 32

A human resources officer is using AI to evaluate resumes and help select candidates that meet minimum criteria. To improve the results, the human resources officer adjusts the query parameters and includes an example resume that matches a successful candidate.

Which of the following best describes this query?

Options:

A.

Distillation

B.

Prompt template

C.

One-shot prompting

D.

System role

Question 33

A data scientist investigates reports that a production machine learning (ML) model no longer performs with accuracy.

The data scientist finds the following pipeline log entries:

Which of the following should the security team do to mitigate future occurrences?

Options:

A.

Add static code scanning tooling to the runner job.

B.

Enable human review and approval workflows in the repository.

C.

Retrain the model on using increased data and epochs.

D.

Keep multiple copies of the model for restoration.

Question 34

Which of the following is a risk addressed by responsible AI?

Options:

A.

Model drift

B.

Reputational loss

C.

Response bias

D.

Data poisoning

Question 35

A customer-facing, AI-powered chatbot has been jailbroken through prompt injections. As a result, the AI model is offering a 99% discount on the purchase of a new vehicle.

Which of the following should be implemented to enhance the model ' s robustness against such attacks?

Options:

A.

Bias filtering

B.

System prompt

C.

Log monitoring

D.

Guardrails

Question 36

A data set containing medical information is put into a machine learning (ML) model that is designed to predict specific illnesses for a population. In the process of verifying the reliability of the system, the compliance officer realizes that the system cannot reliably predict illnesses for certain segments of the population.

Which of the following types of risk is most applicable to this case?

Options:

A.

Bias

B.

Consistency

C.

Transparency

D.

Inclusiveness

Demo: 36 questions
Total 126 questions