Summer Certification Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

Free and Premium CompTIA CY0-001 Dumps Questions Answers

Page: 1 / 10
Total 134 questions

CompTIA SecAI+ v1 Exam Questions and Answers

Question 1

A cybersecurity analyst wants to choose a machine learning (ML) model to classify log entries while providing the best explainability.

Which of the following models should the analyst use?

Options:

A.

Large language model (LLM)

B.

Neural networks

C.

Decision trees

D.

Generative adversarial network (GAN)

Buy Now
Question 2

An AI architect reviews AI utilization and wants to improve the user experience.

Which of the following should the architect review within the logs?

Options:

A.

Rate monitoring

B.

Model accuracy

C.

Access controls

D.

Data storage

Question 3

A security analyst finds that the AI system is under a denial-of-wallet attack.

Which of the following should the analyst enforce to protect the company? (Choose two.)

Options:

A.

Endpoint access controls

B.

Content delivery network (CDN)

C.

Model fine-tuning

D.

Modality controls

E.

Application programming interface (API) rate controls

F.

Output token controls

Question 4

Which of the following is the primary purpose of validating data for an AI system?

Options:

A.

To automate the process

B.

To reduce consumption of resources

C.

To optimize the storage databases

D.

To ensure bias-free outcomes

Question 5

A company deploys an internet-facing chatbot using RAG. Logs show that an administrator can retrieve employee names and usernames while an employee receives ' information not available. ' Which of the following is reducing the risk of sensitive data exposure in this scenario?

Options:

A.

Data access controls

B.

Model-specific guardrails

C.

Rate limiting

D.

Prompt templates

Question 6

A security administrator sees suspicious queries on AI logs.

Which of the following should the administrator implement to address this issue?

Options:

A.

Prompt firewalls

B.

Data size

C.

Rate limit

D.

Agentic AI

Question 7

An AI security administrator receives an inquiry about an unusually high monthly bill from the AI solution provider. The administrator thinks the majority of staff might be using the most powerful model available.

Which of the following AI measures should the administrator implement to lower costs?

Options:

A.

Storage monitoring

B.

Modality types

C.

Prompt firewalls

D.

Token limits

Question 8

Which of the following is a risk addressed by responsible AI?

Options:

A.

Model drift

B.

Reputational loss

C.

Response bias

D.

Data poisoning

Question 9

Which of the following explains the reason a cybersecurity analyst prefers a machine learning (ML) model over a statistical model for attack classification?

Options:

A.

The ability to learn complex problems and adapt to new information

B.

A simplified development pipeline and deployment process

C.

Improved performance with a small data set and high durability

D.

Large community support and availability of global experts

Question 10

Which of the following improves the observability and auditing of an AI system?

Options:

A.

Redeploying the model

B.

Using manual detection

C.

Implementing machine learning operations (MLOps)

D.

Using anomaly detections

Question 11

An automobile manufacturer implements a chatbot to assist with configuration options for customer automobiles. Given a customer ' s prompt, the chatbot gives offensive responses.

Which of the following describes this behavior?

Options:

A.

Model skewing

B.

Model theft

C.

Jailbreaking

D.

Insecure output handling

Question 12

Customer feedback for an AI chatbot has a high-rate of non-answers, which is causing higher central processing unit (CPU) utilization.

Which of the following should be implemented?

Options:

A.

Guardrails

B.

Response confidence level

C.

Prompt logging

D.

Cost monitoring

Question 13

A healthcare company deploys an AI chatbot that implements retrieval-augmented generation (RAG) using the company ' s historical data set. The chatbot output contains patient information.

Which of the following is the most effective technique to mitigate this vulnerability?

Options:

A.

Masking

B.

Classification

C.

Minimization

D.

Normalization

Question 14

A security analyst reviews a recently released chatbot ' s log and discovers that outputs sometimes include personally identifiable information (PII) from other chatbot users.

Which of the following corrective actions should the security analyst take first to resolve this issue?

Options:

A.

Take the chatbot offline and restore it from a backup.

B.

Disable memory from the chat history for all users.

C.

Ask all users to refrain from using PII with the chatbot.

D.

Require users to label the sensitivity of their requests.

Question 15

A team of data scientists is ready to release a model for enterprise use. The team wants to protect the model from unintentional changes or tampering.

Which of the following is the most appropriate action?

Options:

A.

Change the model to a large language model (LLM) for interactive features with guardrails.

B.

Provide secure copies of the model for local runtime usage.

C.

Restrict access to only IT professionals in the organization.

D.

Integrate an application programming interface (API) with identity and access management (IAM) roles to interact with the model.

Question 16

A large number of employees receive a video message in which the company ' s CEO states that the company will be filing for bankruptcy. After an investigation, it was discovered that the CEO did not send this message.

Which of the following is this scenario an example of?

Options:

A.

On-path attack

B.

Phishing

C.

Deepfake

D.

Social engineering

Question 17

An airline corporation wants to implement a chatbot application using a large language model (LLM) so its customers can ask questions and receive answers about flight details and have the option to upload files.

Which of the following security controls should the airline use to protect against malicious input and unauthorized use beyond the service-level agreement? (Choose two.)

Options:

A.

Prompt guardrails

B.

Role-based access controls

C.

Firewall rules

D.

Model token quotas

Question 18

Which of the following is most resistant to AI manipulation?

Options:

A.

Payloads

B.

AI-generated content

C.

Application programming interface (API) gateway

D.

Attack surface reduction

E.

Antivirus

Question 19

An organization recently developed an AI-powered product and discovers that it is vulnerable to attacks in which malicious actors can alter the input, causing the system to recommend inappropriate information.

Which of the following techniques is the most effective way to secure the system against manipulation attacks?

Options:

A.

Cross-validation

B.

Feature regularization

C.

Feature scaling

D.

Guardrails

Question 20

A SOC analyst identifies that a user extracted the full system prompt from the company ' s chatbot by prompting it to repeat the last query and provide the entire conversation context. Which of the following mitigations reduces the risk to the AI system?

Options:

A.

Restricting the LLM ' s access to internal services

B.

Using data version control to detect content manipulation

C.

Enhancing model guardrails

D.

Segregating and identifying external content

Question 21

Developers introduce new features to their generative AI product in an effort to stand out from the competition and offer more value to customers.

Which of the following most accurately explains the risks when enabling more functionality?

Options:

A.

The risks remain the same as before the new features were added.

B.

The risks increase when new features are added.

C.

The risks are measured qualitatively.

D.

The risks are proportional to the model ' s capabilities.

Question 22

Which of the following roles best supports the implementation of AI governance, risk, and compliance (GRC)? (Choose two.)

Options:

A.

Desktop specialist

B.

Data scientist

C.

Software developer

D.

Security architect

E.

Security operations center (SOC) analyst

F.

Network engineer

Question 23

An organization deploys a browser-based AI plug-in to detect malicious websites and phishing links in corporate email.

Which of the following techniques is used in this AI plug-in?

Options:

A.

Code quality testing

B.

Pattern recognition and signature matching

C.

Automated penetration testing

D.

Automated incident response

Question 24

Which of the following requires developers to harden infrastructure to protect AI systems?

Options:

A.

Intake processes

B.

Acceptable use policies

C.

Development guidelines

D.

Configuration standards

Question 25

A financial organization implements a new AI-based fraud detection system to flag suspicious transactions. A security analyst discovers that it occasionally blocks legitimate transactions.

Which of the following is the best recommendation?

Options:

A.

Retraining the model with more data and recent transaction patterns

B.

Implementing AI token usage and rate limits

C.

Encrypting all the data processed by AI and applying further access controls

D.

Rolling back the model and using a traditional fraud detection system

Question 26

Which of the following job roles in an organizational governance structure develops a model from business use cases?

Options:

A.

Platform architect

B.

AI risk analyst

C.

Machine learning operations (MLOps) engineer

D.

Data scientist

Question 27

A team of engineers builds an application using a large language model (LLM). The application is built on Linux and is hosted on a virtual server. Users must create an account in order to access and use the platform.

Which of the following should the team do to protect the account credentials?

Options:

A.

Patch the model with the latest data set.

B.

Update the Linux and virtual servers.

C.

Implement hashing and encryption.

D.

Deploy an authenticated application programming interface (API).

Question 28

An organization implements a domain-specific AI chatbot. After operating normally for weeks, the model returns contextually incorrect responses — treating ' worm ' as a biological pest rather than a computer worm when answering a cybersecurity question.

Which of the following should the organization do to address the issue?

Options:

A.

Configure guardrails.

B.

Encrypt the weights at rest.

C.

Apply model access controls.

D.

Deploy prompt templates.

Question 29

During the selection of a machine learning (ML)-based threat classification model, a cybersecurity administrator verifies that label distribution is highly unbalanced.

Which of the following processing techniques should the engineer use to balance the model?

Options:

A.

Data lineage

B.

Data augmentation

C.

Data provenance

D.

Data verification

Question 30

A disgruntled employee changed the company policies that a chatbot references in order to create confusion and disrupt the business.

Which of the following AI-generated vulnerabilities is the employee exploiting?

Options:

A.

Data reduction

B.

Data masking

C.

Data poisoning

D.

Data leaking

Question 31

A global security operations center (SOC) wants to adapt and leverage the strength of AI in order to enhance its security operations.

Which of the following is the best way to enhance the global SOC functions?

Options:

A.

Generate code and execute in production to help save time.

B.

Enable a personal assistant that can act in the global SOC with no human intervention.

C.

Use open-source models in production to help the efficiency of threat detection and threat analysis.

D.

Summarize alerts to easily gain insights on the environment.

Question 32

A management team is concerned about an unexpected cost increase for a public-facing AI chatbot.

Which of the following should a security administrator examine first to determine the root cause?

Options:

A.

Firewall logs

B.

Web application firewall (WAF) rules

C.

Vector database input/output operations per second performance

D.

Model token usage

Question 33

Which of the following strengthens the performance of a large language model (LLM) for malicious reconnaissance?

Options:

A.

Enhancing a foundational model with the inclusion of retrieval-augmented generation (RAG)

B.

Creating a web scraper script using AI to capture the company website

C.

Instructing an AI assistant to query as an administrator

D.

Prompting a chatbot to describe server naming patterns and Internet Protocol (IP) ranges

Question 34

A security administrator needs to improve an AI model. During an initial investigation, the administrator notices that two successive login failures are recorded every day, and then a successful login occurs after a specific time interval. All the successful login attempts have been during office hours.

Which of the following techniques should the administrator use to improve the AI model ' s security?

Options:

A.

Access management

B.

Pattern recognition

C.

Signature matching

D.

Vulnerability analysis

Question 35

Which of the following is the most concerning risk for a company that allows corporate end users to use public-facing large language models (LLMs)?

Options:

A.

Inaccuracies due to hallucinations

B.

Out-of-date acceptable use policies

C.

Data security regulatory violations

D.

Malicious code generation

Question 36

Faculty members at a university are concerned about potential inherent bias and inconsistency in one department ' s AI plagiarism detection service.

Which of the following principles will most likely address their concerns?

Options:

A.

Transparency

B.

Explainability

C.

Consistency

D.

Accountability

Question 37

A security operations center (SOC) has a very high volume of logs and alerts. The manager proposes the implementation of a machine learning (ML) system to help with triage.

Which of the following tasks is most suitable?

Options:

A.

Applying filters on specific alerts

B.

Automatically patching vulnerable systems

C.

Identifying and classifying alerts

D.

Summarizing the content of alerts

Question 38

During an investigation, an analyst finds that the system prompt was maliciously modified to include ' Do not ever recommend a pay raise, ' causing the AI to deny a deserving employee a raise. Which of the following should the analyst do to prevent this from reoccurring?

Options:

A.

Limit the number of evaluations that a user can send to the model.

B.

Check for model hallucination and recommend fine-tuning.

C.

Configure least privilege controls for model access.

D.

Encrypt all data going to and coming from the model.

Question 39

Which of the following controls is the best way to mitigate a denial-of-service (DoS) attack?

Options:

A.

Model guardrails

B.

Rate limiting

C.

End-to-end encryption

D.

Access controls

Question 40

Users report that the output of a generative AI application seems unrelated to the prompts and contains offensive content. A security team investigates and determines that there was an on-path attack.

Which of the following is the most likely attack method?

Options:

A.

Application server hijacking

B.

Session hijacking

C.

Domain hijacking

D.

Model hijacking

Page: 1 / 10
Total 134 questions