Summer Certification Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

Free and Premium CompTIA CY0-001 Dumps Questions Answers

Page: 1 / 9
Total 126 questions

CompTIA SecAI+ v1 Exam Questions and Answers

Question 1

A security administrator wants to prevent prompt injection attacks and ensure responses have sanitized output.

Which of the following provides a primary compensating control for these requirements?

Options:

A.

Least privilege

B.

Encryption

C.

A large language model (LLM) firewall

D.

Rate limiting

Buy Now
Question 2

A disgruntled employee changed the company policies that a chatbot references in order to create confusion and disrupt the business.

Which of the following AI-generated vulnerabilities is the employee exploiting?

Options:

A.

Data reduction

B.

Data masking

C.

Data poisoning

D.

Data leaking

Question 3

Which of the following technologies is used in deepfake?

Options:

A.

Generative adversarial network (GAN)

B.

Multi-shot prompting

C.

Prompt engineering

D.

Transfer learning

Question 4

A global security operations center (SOC) wants to adapt and leverage the strength of AI in order to enhance its security operations.

Which of the following is the best way to enhance the global SOC functions?

Options:

A.

Generate code and execute in production to help save time.

B.

Enable a personal assistant that can act in the global SOC with no human intervention.

C.

Use open-source models in production to help the efficiency of threat detection and threat analysis.

D.

Summarize alerts to easily gain insights on the environment.

Question 5

A healthcare company deploys an AI chatbot that implements retrieval-augmented generation (RAG) using the company ' s historical data set. The chatbot output contains patient information.

Which of the following is the most effective technique to mitigate this vulnerability?

Options:

A.

Masking

B.

Classification

C.

Minimization

D.

Normalization

Question 6

Which of the following requires developers to harden infrastructure to protect AI systems?

Options:

A.

Intake processes

B.

Acceptable use policies

C.

Development guidelines

D.

Configuration standards

Question 7

A developer is selecting authentication controls for an AI system.

Which of the following is the best way to prevent threat actor replay attacks?

Options:

A.

Identity provider (IdP) federation

B.

Secure Shell (SSH)-based certificate authentication

C.

Expiring session tokens

D.

Identity and access management access keys

Question 8

A security administrator sees suspicious queries on AI logs.

Which of the following should the administrator implement to address this issue?

Options:

A.

Prompt firewalls

B.

Data size

C.

Rate limit

D.

Agentic AI

Question 9

A security architect performs threat modeling of an AI system. The architect needs to determine which attacks can be performed against the system.

Which of the following actions should the architect take next?

Options:

A.

Leverage a large language model (LLM) to map likely attack paths based on the code base.

B.

Quantify the risk of known vulnerabilities identified in the AI system.

C.

Identify trust boundaries and perform threat modeling with Open Worldwide Application Security Project (OWASP) Top 10.

D.

Analyze MITRE Adversarial Threat Landscape for AI Systems (ATLAS) for tactics, techniques, and procedures (TTPs).

Question 10

Which of the following is the most impactful security risk associated with the use of a generative AI chatbot?

Options:

A.

Overly permissive access

B.

Data leakage

C.

Weak encryption

D.

Model validation

Question 11

A security analyst reviews a recently released chatbot ' s log and discovers that outputs sometimes include personally identifiable information (PII) from other chatbot users.

Which of the following corrective actions should the security analyst take first to resolve this issue?

Options:

A.

Take the chatbot offline and restore it from a backup.

B.

Disable memory from the chat history for all users.

C.

Ask all users to refrain from using PII with the chatbot.

D.

Require users to label the sensitivity of their requests.

Question 12

An organization develops a chatbot that does not provide harmful or explicit responses, must use clean and professional language, and ensures that responses are accurate.

Which of the following should the organization conduct after the chatbot is fully developed but before a customer-facing deployment?

Options:

A.

Data labeling and classification

B.

Model auditing and evaluation

C.

Guardrail testing and validation

D.

Regression modeling and minimization

Question 13

Users report that the output of a generative AI application seems unrelated to the prompts and contains offensive content. A security team investigates and determines that there was an on-path attack.

Which of the following is the most likely attack method?

Options:

A.

Application server hijacking

B.

Session hijacking

C.

Domain hijacking

D.

Model hijacking

Question 14

Which of the following is the most concerning risk for a company that allows corporate end users to use public-facing large language models (LLMs)?

Options:

A.

Inaccuracies due to hallucinations

B.

Out-of-date acceptable use policies

C.

Data security regulatory violations

D.

Malicious code generation

Question 15

Which of the following responsible AI standards refers to a principle that clearly states the reasons behind the decisions for a particular conclusion?

Options:

A.

Accountability

B.

Auditability

C.

Transparency

D.

Explainability

Question 16

A data set containing medical information is put into a machine learning (ML) model that is designed to predict specific illnesses for a population. In the process of verifying the reliability of the system, the compliance officer realizes that the system cannot reliably predict illnesses for certain segments of the population.

Which of the following types of risk is most applicable to this case?

Options:

A.

Bias

B.

Consistency

C.

Transparency

D.

Inclusiveness

Question 17

Which of the following roles best supports the implementation of AI governance, risk, and compliance (GRC)? (Choose two.)

Options:

A.

Desktop specialist

B.

Data scientist

C.

Software developer

D.

Security architect

E.

Security operations center (SOC) analyst

F.

Network engineer

Question 18

A security analyst is aware of an active penetration test in the environment. The analyst examines SIEM log data and notices the following AI system output:

Which of the following is the vulnerability that has occurred and the control the analyst should implement?

Options:

A.

The vulnerability is prompt injection, and the analyst should use endpoint detection response (EDR).

B.

The vulnerability is model hallucinations, and the analyst should develop output validations.

C.

The vulnerability is jailbreaking, and the analyst should utilize role-based access control.

D.

The vulnerability is sensitive information disclosure, and the analyst should employ masking.

E.

The vulnerability is role impersonation, and the analyst should use validation.

Question 19

An attacker successfully completes a denial-of-service (DoS) attack through the context window of an AI system. Thousands of characters are obfuscated and hidden behind an emoji.

Which of the following techniques best mitigates this type of attack?

Options:

A.

Fraud detection

B.

Large language model (LLM)-as-a-judge

C.

Pattern recognition

D.

Prompt filter

Question 20

Which of the following explains the reason a cybersecurity analyst prefers a machine learning (ML) model over a statistical model for attack classification?

Options:

A.

The ability to learn complex problems and adapt to new information

B.

A simplified development pipeline and deployment process

C.

Improved performance with a small data set and high durability

D.

Large community support and availability of global experts

Question 21

A data scientist is working with unlabeled data and wants to build a clustering model.

Which of the following techniques should a data scientist use?

Options:

A.

Supervised learning

B.

Reinforcement learning

C.

Unsupervised learning

D.

Semi-supervised learning

Question 22

User experience is declining since the launch of a large language model (LLM) in internal networks.

Which of the following should be the highest priority for the prompt engineers?

Options:

A.

Customer success management

B.

Sales life cycle

C.

Quality control

D.

Business objectives

Question 23

Which of the following attacks would be the best to automate with AI during dynamic application software testing (DAST)?

Options:

A.

Distributed denial-of-service (DDoS)

B.

Data poisoning

C.

Payload creation

D.

Threat modeling

Question 24

Which of the following is a risk addressed by responsible AI?

Options:

A.

Model drift

B.

Reputational loss

C.

Response bias

D.

Data poisoning

Question 25

During the selection of a machine learning (ML)-based threat classification model, a cybersecurity administrator verifies that label distribution is highly unbalanced.

Which of the following processing techniques should the engineer use to balance the model?

Options:

A.

Data lineage

B.

Data augmentation

C.

Data provenance

D.

Data verification

Question 26

Which of the following should an auditor reference when reviewing a company ' s human resources AI systems for legal non-compliance?

Options:

A.

Organization for Economic Cooperation and Development (OECD) standard

B.

National Institute of Standards and Technology (NIST) AI Risk Management Framework (RMF)

C.

European Union (EU) AI Act

D.

International Organization for Standardization (ISO)

Question 27

A detection engineering team wants to use AI to automatically prevent vulnerable code from reaching production.

Which of the following is the most effective way to accomplish this task?

Options:

A.

Deploying an integrated development environment (IDE) plug-in that will warn developers of dangerous code before compiling

B.

Using a security orchestration, automation, and response (SOAR) with a machine learning (ML) model to classify code

C.

Implementing a large language model (LLM) in the continuous integration and continuous deployment (CI/CD) runner to examine code and pass or fail build jobs

D.

Developing an agentic penetration testing tool to validate potential vulnerable code

Question 28

A cybersecurity analyst must use pattern recognition on a data set containing unstructured data.

Which of the following models is the best for this task?

Options:

A.

Long short-term memory

B.

Convolutional neural network

C.

Decision tree

D.

Logistic regression

Question 29

Customer feedback for an AI chatbot has a high-rate of non-answers, which is causing higher central processing unit (CPU) utilization.

Which of the following should be implemented?

Options:

A.

Guardrails

B.

Response confidence level

C.

Prompt logging

D.

Cost monitoring

Question 30

Faculty members at a university are concerned about potential inherent bias and inconsistency in one department ' s AI plagiarism detection service.

Which of the following principles will most likely address their concerns?

Options:

A.

Transparency

B.

Explainability

C.

Consistency

D.

Accountability

Question 31

A data scientist investigates reports that a production machine learning (ML) model no longer performs with accuracy.

The data scientist finds the following pipeline log entries:

Which of the following should the security team do to mitigate future occurrences?

Options:

A.

Add static code scanning tooling to the runner job.

B.

Enable human review and approval workflows in the repository.

C.

Retrain the model on using increased data and epochs.

D.

Keep multiple copies of the model for restoration.

Question 32

A short AI-generated video shows a celebrity ' s likeness talking about a fake public security event.

Which of the following was used to create this video?

Options:

A.

Statistical analysis

B.

Convolutional neural network

C.

Machine learning (ML) classifier

D.

Random forest

Question 33

Which of the following International Organization for Standardization (ISO) standards contains compliance requirements for building an AI management system?

Options:

A.

20000

B.

27001

C.

27018

D.

42001

Question 34

A security administrator needs to improve an AI model. During an initial investigation, the administrator notices that two successive login failures are recorded every day, and then a successful login occurs after a specific time interval. All the successful login attempts have been during office hours.

Which of the following techniques should the administrator use to improve the AI model ' s security?

Options:

A.

Access management

B.

Pattern recognition

C.

Signature matching

D.

Vulnerability analysis

Question 35

A security consultant must summarize the impact of posture management on a machine learning (ML) use case.

Which of the following is the most appropriate reference for this purpose?

Options:

A.

Organization for Economic Co-operation and Development (OECD) standards

B.

National Institute of Standards and Technology (NIST) AI Risk Management Framework (RMF)

C.

European Union AI Act

D.

Generative adversarial network (GAN)

Question 36

Which of the following would most likely be used to prove that an image is AI generated?

Options:

A.

Human validation

B.

Guardrails

C.

Diffusion

D.

Watermarking

Question 37

A management team is concerned about an unexpected cost increase for a public-facing AI chatbot.

Which of the following should a security administrator examine first to determine the root cause?

Options:

A.

Firewall logs

B.

Web application firewall (WAF) rules

C.

Vector database input/output operations per second performance

D.

Model token usage

Page: 1 / 9
Total 126 questions