Weekend Sale Special - 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: fifty75ct

CY0-001 CompTIA SecAI+ v1 Exam Questions and Answers

Questions 4

An internal user enters a client credit card number into an internal generative machine learning (ML) model:

#User prompt: Customer Jane Doe has a new credit card that she wants to add to her account. The number is 5555-5555-5555-5555

Which of the following is the most effective way to prevent prompt injection attacks against a large language model (LLM)?

Options:

A.

Guardrails

B.

Antivirus

C.

Web application firewall (WAF)

D.

Role-based access control

Buy Now
Questions 5

A social media company with more than a million lines of code wants to reduce the mean time to fix bugs and issues.

Which of the following is the most balanced AI strategy to automate the vulnerability management flow?

Options:

A.

Using AI to triage discovered issues and create tickets, but having a software engineer merge software

B.

Having security analysts triage discovered issues and create tickets, but using AI to merge software

C.

Having security analysts triage discovered issues and create tickets, but having a software engineer merge software

D.

Using AI to triage discovered issues, create tickets, and merge software fixes

Buy Now
Questions 6

Which of the following improves the observability and auditing of an AI system?

Options:

A.

Redeploying the model

B.

Using manual detection

C.

Implementing machine learning operations (MLOps)

D.

Using anomaly detections

Buy Now
Questions 7

Which of the following provides guidance on AI-specific compliance?

Options:

A.

Organisation for Economic Co-operation and Development (OECD)

B.

International Organization for Standardization (ISO) 27001

C.

Payment Card Industry Data Security Standard (PCI DSS)

D.

General Data Protection Regulation (GDPR)

Buy Now
Questions 8

A security administrator must implement security controls for AI systems.

Which of the following access controls should the administrator set up first for authentication?

Options:

A.

Model

B.

Server

C.

Data

D.

Endpoint

Buy Now
Questions 9

During a model validation procedure, an engineer notices that a model performs well during training but poorly during testing.

Which of the following best describes the reason?

Options:

A.

Fine-tuning

B.

Overfitting

C.

Regularization

D.

Inference

Buy Now
Questions 10

A threat intelligence team wants to automate the analysis and summary of its in-depth reports for multiple target audiences. Which of the following is the best solution?

Options:

A.

Implementing natural language processing (NLP) to analyze sentiment

B.

Developing a k-means clustering model that highlights threat groups

C.

Deploying a classifier model using regression to predict with multiple values

D.

Using a large language model (LLM) with a retrieval-augmented generation (RAG) architecture and updated data

Buy Now
Questions 11

A global security operations center (SOC) wants to adapt and leverage the strength of AI in order to enhance its security operations.

Which of the following is the best way to enhance the global SOC functions?

Options:

A.

Generate code and execute in production to help save time.

B.

Enable a personal assistant that can act in the global SOC with no human intervention.

C.

Use open-source models in production to help the efficiency of threat detection and threat analysis.

D.

Summarize alerts to easily gain insights on the environment.

Buy Now
Questions 12

Which of the following responsible AI standards refers to a principle that clearly states the reasons behind the decisions for a particular conclusion?

Options:

A.

Accountability

B.

Auditability

C.

Transparency

D.

Explainability

Buy Now
Questions 13

An architect is creating a threat model for an agentic system.

Which of the following should the architect do first?

Options:

A.

Apply compensating controls based on exposure findings.

B.

Identify the trust boundary between the components.

C.

Calculate the risk to resources based on data sensitivity.

D.

Scan for vulnerabilities from the Open Worldwide Application Security Project (OWASP) Top 10.

Buy Now
Questions 14

A group of security engineers is developing a SIEM system that will be able to ingest data from multiple structured and unstructured sources, have a chatbot integrated with an LLM that the security analyst can interact with, and provide insights from the SIEM alert data.

Which of the following techniques should the security engineers consider before collecting the data from the respective sources?

Options:

A.

Balancing

B.

Verification

C.

Cleansing

D.

Vector storage

Buy Now
Questions 15

A security analyst needs to conduct a security assessment of the output from an AI-enabled development tool.

Which of the following should the analyst do first?

Options:

A.

Remove hard-coded secrets from the source code.

B.

Enforce strict access controls for code repositories.

C.

Enable sensitive data discovery on code repositories.

D.

Perform a source code review.

Buy Now
Questions 16

A penetration tester is assessing the controls of a deployed AI system that is designed to search and return the contents of files.

The tester runs the following:

Which of the following is the best control to prevent abuse of the system?

Options:

A.

Implementing custom detection rules for anomalous model behavior

B.

Segmenting the workload into a separate virtual private cloud (VPC)

C.

Adding a large language model (LLM) guardrails library to the application code

D.

Reducing the privilege scope of the service account

Buy Now
Questions 17

A critical AI system cannot be shut down and must remain secure. Which of the following actions should be performed to apply controls?

Options:

A.

Removing the data encryption

B.

Patching critical vulnerabilities

C.

Scanning logs to detect anomalies

D.

Redeploying the production models

Buy Now
Questions 18

A cybersecurity administrator generates patching reports using AI, but the process takes a long time. Which of the following is the best way to increase performance?

Options:

A.

Deploy a Model Context Protocol (MCP) server to delegate several versions of this query to the back-end LLM simultaneously.

B.

Have the AI download the full CVE database first to prevent multiple similar external queries.

C.

Configure the AI system prompt to specify summarization algorithms.

D.

Increase the amount of model tokens available to eliminate time-consuming session restarts.

Buy Now
Questions 19

Which of the following technologies is used in deepfake?

Options:

A.

Generative adversarial network (GAN)

B.

Multi-shot prompting

C.

Prompt engineering

D.

Transfer learning

Buy Now
Questions 20

A team of engineers builds an application using a large language model (LLM). The application is built on Linux and is hosted on a virtual server. Users must create an account in order to access and use the platform.

Which of the following should the team do to protect the account credentials?

Options:

A.

Patch the model with the latest data set.

B.

Update the Linux and virtual servers.

C.

Implement hashing and encryption.

D.

Deploy an authenticated application programming interface (API).

Buy Now
Questions 21

An IT company implements an adaptable chatbot that learns from user prompts. Based on the conversation shown — where User 2 injected false information about a company acquisition that caused the chatbot to give incorrect responses to User 3 — which of the following compensating controls should an administrator implement to mitigate the issue?

Options:

A.

Data encryption

B.

Rate-limiting application programming interfaces (APIs)

C.

Transfer learning

D.

Guardrails

Buy Now
Questions 22

Which of the following describes the most significant risk associated with AI agents that make autonomous decisions?

Options:

A.

Increased workload

B.

Accidental data leakage

C.

Overfitting

D.

Output bias

Buy Now
Questions 23

Which of the following is the primary security risk when deploying AI models in production?

Options:

A.

Graphics processing unit (GPU) acceleration

B.

Model overfitting

C.

Model encryption

D.

Data exposure

Buy Now
Questions 24

User experience is declining since the launch of a large language model (LLM) in internal networks.

Which of the following should be the highest priority for the prompt engineers?

Options:

A.

Customer success management

B.

Sales life cycle

C.

Quality control

D.

Business objectives

Buy Now
Questions 25

A large number of employees receive a video message in which the company ' s CEO states that the company will be filing for bankruptcy. After an investigation, it was discovered that the CEO did not send this message.

Which of the following is this scenario an example of?

Options:

A.

On-path attack

B.

Phishing

C.

Deepfake

D.

Social engineering

Buy Now
Questions 26

A cybersecurity analyst must use pattern recognition on a data set containing unstructured data.

Which of the following models is the best for this task?

Options:

A.

Long short-term memory

B.

Convolutional neural network

C.

Decision tree

D.

Logistic regression

Buy Now
Questions 27

An organization wants to reduce vulnerabilities after deployment. The organization decides to incorporate an AI-assisted early detection and vulnerability identification process in its development workflow.

Which of the following AI-assisted functions is the best option?

Options:

A.

Code linting

B.

Incident management

C.

Automated deployment/rollback

D.

System auditing

Buy Now
Questions 28

A recently deployed AI system becomes persistently unavailable. A restart temporarily fixes the issue, but the issue happens again. Upon examination of API logs, an analyst finds that external calls continued to use system resources after the action completed.

Which of the following is the best way to improve availability of the system?

Options:

A.

Creating token limits

B.

Enforcing session expiration

C.

Increasing system memory

D.

Implementing multifactor authentication (MFA)

Buy Now
Questions 29

An organization deploys a browser-based AI plug-in to detect malicious websites and phishing links in corporate email.

Which of the following techniques is used in this AI plug-in?

Options:

A.

Code quality testing

B.

Pattern recognition and signature matching

C.

Automated penetration testing

D.

Automated incident response

Buy Now
Questions 30

Customer feedback for an AI chatbot has a high-rate of non-answers, which is causing higher central processing unit (CPU) utilization.

Which of the following should be implemented?

Options:

A.

Guardrails

B.

Response confidence level

C.

Prompt logging

D.

Cost monitoring

Buy Now
Questions 31

A company is adopting AI and wants to create policies and procedures that include a structure for evaluating, publishing, and approving patterns for AI usage.

Which of the following should the company establish to meet this goal?

Options:

A.

AI center of excellence

B.

AI legal affairs office

C.

AI audit department

D.

AI data science division

Buy Now
Questions 32

Which of the following would most likely be used to prove that an image is AI generated?

Options:

A.

Human validation

B.

Guardrails

C.

Diffusion

D.

Watermarking

Buy Now
Questions 33

An AI security architect needs to conduct a security review of a new AI chatbot. Which of the following resources would the architect most likely rely on to perform a threat assessment and ensure comprehensive coverage during the review?

Options:

A.

National Institute of Standards and Technology (NIST) 42001

B.

Open Worldwide Application Security Project (OWASP) Large Language Model (LLM) Top 10

C.

International Organization for Standardization (ISO) 27001

D.

European Union (EU) AI Act

Buy Now
Questions 34

An AI security administrator notices that the information referenced by the model is incorrectly formatted and missing values.

Which of the following job roles would most likely be responsible for correcting this error?

Options:

A.

Platform engineer

B.

Machine learning operations (MLOps) engineer

C.

Data engineer

D.

AI architect

Buy Now
Questions 35

A data set containing medical information is put into a machine learning (ML) model that is designed to predict specific illnesses for a population. In the process of verifying the reliability of the system, the compliance officer realizes that the system cannot reliably predict illnesses for certain segments of the population.

Which of the following types of risk is most applicable to this case?

Options:

A.

Bias

B.

Consistency

C.

Transparency

D.

Inclusiveness

Buy Now
Questions 36

A security consultant must summarize the impact of posture management on a machine learning (ML) use case.

Which of the following is the most appropriate reference for this purpose?

Options:

A.

Organization for Economic Co-operation and Development (OECD) standards

B.

National Institute of Standards and Technology (NIST) AI Risk Management Framework (RMF)

C.

European Union AI Act

D.

Generative adversarial network (GAN)

Buy Now
Questions 37

Which of the following resources most accurately covers the most widely recognized threat vectors and common vulnerabilities related to large language model (LLM) applications?

Options:

A.

Massachusetts Institute of Technology Risk Repository

B.

Open Worldwide Application Security Project (OWASP)

C.

MITRE Adversarial Threat Landscape for AI Systems (ATLAS)

D.

National Institute of Standards and Technology (NIST) AI Risk Management Framework (RMF)

Buy Now
Questions 38

Which of the following should an auditor reference when reviewing a company ' s human resources AI systems for legal non-compliance?

Options:

A.

Organization for Economic Cooperation and Development (OECD) standard

B.

National Institute of Standards and Technology (NIST) AI Risk Management Framework (RMF)

C.

European Union (EU) AI Act

D.

International Organization for Standardization (ISO)

Buy Now
Questions 39

A line of business wants to onboard an application that uses a custom AI model for employee assessments. The Chief Information Officer (CIO) agrees to allow the engagement to proceed but first wants a threat model.

Which of the following is the most appropriate to use for an AI threat model?

Options:

A.

Responsible AI

B.

Adversarial Threat Landscape for AI Systems (ATLAS)

C.

Organization for Economic Co-operation and Development (OECD)

D.

International Organization for Standardization (ISO)

Buy Now
Questions 40

An attacker successfully completes a denial-of-service (DoS) attack through the context window of an AI system. Thousands of characters are obfuscated and hidden behind an emoji.

Which of the following techniques best mitigates this type of attack?

Options:

A.

Fraud detection

B.

Large language model (LLM)-as-a-judge

C.

Pattern recognition

D.

Prompt filter

Buy Now
Questions 41

As a compliance requirement, a large language model (LLM) application requires setting up guardrails.

Which of the following resources is most appropriate to use?

Options:

A.

Retrieval-augmented generation (RAG)

B.

Open Worldwide Application Security Project (OWASP)

C.

LLM libraries

D.

Security incident and event management (SIEM)

Buy Now
Questions 42

Which of the following controls is the best way to mitigate a denial-of-service (DoS) attack?

Options:

A.

Model guardrails

B.

Rate limiting

C.

End-to-end encryption

D.

Access controls

Buy Now
Questions 43

Instructions: Use the drop-down menus to define two appropriate security controls for each component of the AI system. Each control may be used only once.

An engineer is deploying a new AI system and wants to integrate it into the core system through an API.

Options:

Buy Now
Questions 44

A security analyst is aware of an active penetration test in the environment. The analyst examines SIEM log data and notices the following AI system output:

Which of the following is the vulnerability that has occurred and the control the analyst should implement?

Options:

A.

The vulnerability is prompt injection, and the analyst should use endpoint detection response (EDR).

B.

The vulnerability is model hallucinations, and the analyst should develop output validations.

C.

The vulnerability is jailbreaking, and the analyst should utilize role-based access control.

D.

The vulnerability is sensitive information disclosure, and the analyst should employ masking.

E.

The vulnerability is role impersonation, and the analyst should use validation.

Buy Now
Questions 45

A company introduces a large language model (LLM) in an application in order to monitor for a potential denial-of-service attack. Which of the following should the company use to measure the utilization of the LLM?

Options:

A.

Token

B.

Transformer

C.

Chain of thoughts

D.

Prompt

Buy Now
Questions 46

A multinational company wants to implement an AI-assisted job screening solution.

Which of the following should the company reference to reduce the risk of incurring compliance-related fines?

Options:

A.

International Organization for Standardization (ISO) AI standards

B.

European Union (EU) AI Act

C.

Corporate policy

D.

National Institute of Standards and Technology (NIST) AI Risk Management Framework (RMF)

Buy Now
Questions 47

Which of the following is the primary purpose of validating data for an AI system?

Options:

A.

To automate the process

B.

To reduce consumption of resources

C.

To optimize the storage databases

D.

To ensure bias-free outcomes

Buy Now
Exam Code: CY0-001
Exam Name: CompTIA SecAI+ v1 Exam
Last Update: Oct 5, 2026
Questions: 159
CY0-001 pdf

CY0-001 PDF

$21.25  $84.99
CY0-001 Engine

CY0-001 Testing Engine

$25  $99.99
CY0-001 PDF + Engine

CY0-001 PDF + Testing Engine

$33.75  $134.99