Summer Certification Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: cramtick70

CY0-001 CompTIA SecAI+ v1 Exam Questions and Answers

Questions 4

A financial organization implements a new AI-based fraud detection system to flag suspicious transactions. A security analyst discovers that it occasionally blocks legitimate transactions.

Which of the following is the best recommendation?

Options:

A.

Retraining the model with more data and recent transaction patterns

B.

Implementing AI token usage and rate limits

C.

Encrypting all the data processed by AI and applying further access controls

D.

Rolling back the model and using a traditional fraud detection system

Buy Now
Questions 5

Which of the following requires developers to harden infrastructure to protect AI systems?

Options:

A.

Intake processes

B.

Acceptable use policies

C.

Development guidelines

D.

Configuration standards

Buy Now
Questions 6

Which of the following is the best example of an AI model that is trained to identify multiple points from input using a neural network to provide output for authentication?

Options:

A.

Facial recognition

B.

Encryption key

C.

Open Authorization (OAuth)

D.

Bounding box

Buy Now
Questions 7

A human resources officer is using AI to evaluate resumes and help select candidates that meet minimum criteria. To improve the results, the human resources officer adjusts the query parameters and includes an example resume that matches a successful candidate.

Which of the following best describes this query?

Options:

A.

Distillation

B.

Prompt template

C.

One-shot prompting

D.

System role

Buy Now
Questions 8

An internal user enters a client credit card number into an internal generative machine learning (ML) model:

#User prompt: Customer Jane Doe has a new credit card that she wants to add to her account. The number is 5555-5555-5555-5555

Which of the following is the most effective way to prevent prompt injection attacks against a large language model (LLM)?

Options:

A.

Guardrails

B.

Antivirus

C.

Web application firewall (WAF)

D.

Role-based access control

Buy Now
Questions 9

A company develops an AI model to diagnose patients. Hospitals access the model through an integrated application programming interface (API). The security team performs a denial-of-service (DoS) attack via brute force on the model.

Which of the following controls would have prevented this issue?

Options:

A.

Tokenization

B.

Model guardrails

C.

Rate limiting

D.

Prompt firewall

Buy Now
Questions 10

An airline corporation wants to implement a chatbot application using a large language model (LLM) so its customers can ask questions and receive answers about flight details and have the option to upload files.

Which of the following security controls should the airline use to protect against malicious input and unauthorized use beyond the service-level agreement? (Choose two.)

Options:

A.

Prompt guardrails

B.

Role-based access controls

C.

Firewall rules

D.

Model token quotas

Buy Now
Questions 11

A company introduces a large language model (LLM) in an application in order to monitor for a potential denial-of-service attack.

Which of the following should the company use to measure the utilization of the LLM?

Options:

A.

Token

B.

Transformer

C.

Chain of thoughts

D.

Prompt

Buy Now
Questions 12

A recent release of an AI software update exposes confidential customer information due to storage misconfiguration.

Which of the following data security controls will help maintain confidentiality despite the data leak?

Options:

A.

Model encryption

B.

Encryption in transit

C.

Encryption in use

D.

Encryption at rest

Buy Now
Questions 13

Which of the following is required first in order to send a prompt query and response in a language model (LLM) system when authentication is enabled?

Options:

A.

Front-end web proxy gateway

B.

Endpoint access control

C.

Application programming interface gateway

D.

Back-end access gateway

Buy Now
Questions 14

A short AI-generated video shows a celebrity ' s likeness talking about a fake public security event.

Which of the following was used to create this video?

Options:

A.

Statistical analysis

B.

Convolutional neural network

C.

Machine learning (ML) classifier

D.

Random forest

Buy Now
Questions 15

A group of security engineers is developing a SIEM system that will be able to ingest data from multiple structured and unstructured sources, have a chatbot integrated with an LLM that the security analyst can interact with, and provide insights from the SIEM alert data.

Which of the following techniques should the security engineers consider before collecting the data from the respective sources?

Options:

A.

Balancing

B.

Verification

C.

Cleansing

D.

Vector storage

Buy Now
Questions 16

An AI security administrator notices that the information referenced by the model is incorrectly formatted and missing values.

Which of the following job roles would most likely be responsible for correcting this error?

Options:

A.

Platform engineer

B.

Machine learning operations (MLOps) engineer

C.

Data engineer

D.

AI architect

Buy Now
Questions 17

A developer is proposing a new AI application for human resources systems. Which of the following are the most important considerations?

Options:

A.

Geniality and appeal

B.

Privacy and security

C.

Graphics and design

D.

Brevity and summarization

Buy Now
Questions 18

A security analyst is aware of an active penetration test in the environment. The analyst examines SIEM log data and notices the following AI system output:

Which of the following is the vulnerability that has occurred and the control the analyst should implement?

Options:

A.

The vulnerability is prompt injection, and the analyst should use endpoint detection response (EDR).

B.

The vulnerability is model hallucinations, and the analyst should develop output validations.

C.

The vulnerability is jailbreaking, and the analyst should utilize role-based access control.

D.

The vulnerability is sensitive information disclosure, and the analyst should employ masking.

E.

The vulnerability is role impersonation, and the analyst should use validation.

Buy Now
Questions 19

Which of the following is the primary purpose of validating data for an AI system?

Options:

A.

To automate the process

B.

To reduce consumption of resources

C.

To optimize the storage databases

D.

To ensure bias-free outcomes

Buy Now
Questions 20

Which of the following should an auditor reference when reviewing a company ' s human resources AI systems for legal non-compliance?

Options:

A.

Organization for Economic Cooperation and Development (OECD) standard

B.

National Institute of Standards and Technology (NIST) AI Risk Management Framework (RMF)

C.

European Union (EU) AI Act

D.

International Organization for Standardization (ISO)

Buy Now
Questions 21

Users report that the output of a generative AI application seems unrelated to the prompts and contains offensive content. A security team investigates and determines that there was an on-path attack.

Which of the following is the most likely attack method?

Options:

A.

Application server hijacking

B.

Session hijacking

C.

Domain hijacking

D.

Model hijacking

Buy Now
Questions 22

A security operations center (SOC) has a very high volume of logs and alerts. The manager proposes the implementation of a machine learning (ML) system to help with triage.

Which of the following tasks is most suitable?

Options:

A.

Applying filters on specific alerts

B.

Automatically patching vulnerable systems

C.

Identifying and classifying alerts

D.

Summarizing the content of alerts

Buy Now
Questions 23

Which of the following is an example of how a security analyst uses generative AI in the triage process?

Options:

A.

To predict the next attack target with higher accuracy

B.

To use statistical analysis for malicious code assessment

C.

To summarize security findings by category

D.

To tag malware using machine learning (ML) algorithms

Buy Now
Questions 24

Which of the following attacks is most enabled by AI-generated content?

Options:

A.

Model poisoning

B.

Phishing

C.

Ransomware

D.

Remote code execution

Buy Now
Questions 25

A cybersecurity administrator generates patching reports using AI, but the process takes a long time. Which of the following is the best way to increase performance?

Options:

A.

Deploy a Model Context Protocol (MCP) server to delegate several versions of this query to the back-end LLM simultaneously.

B.

Have the AI download the full CVE database first to prevent multiple similar external queries.

C.

Configure the AI system prompt to specify summarization algorithms.

D.

Increase the amount of model tokens available to eliminate time-consuming session restarts.

Buy Now
Questions 26

A recently deployed AI system becomes persistently unavailable. A restart temporarily fixes the issue, but the issue happens again. Upon examination of API logs, an analyst finds that external calls continued to use system resources after the action completed.

Which of the following is the best way to improve availability of the system?

Options:

A.

Creating token limits

B.

Enforcing session expiration

C.

Increasing system memory

D.

Implementing multifactor authentication (MFA)

Buy Now
Questions 27

An organization is developing and implementing AI features into a customer service application.

Which of the following practices should the organization put in place before releasing the application for customer trials?

Options:

A.

Data masking and sanitization

B.

External compliance audits

C.

Approved AI vendor lists

D.

Third-party risk management

Buy Now
Questions 28

A data scientist investigates reports that a production machine learning (ML) model no longer performs with accuracy.

The data scientist finds the following pipeline log entries:

Which of the following should the security team do to mitigate future occurrences?

Options:

A.

Add static code scanning tooling to the runner job.

B.

Enable human review and approval workflows in the repository.

C.

Retrain the model on using increased data and epochs.

D.

Keep multiple copies of the model for restoration.

Buy Now
Questions 29

A developer is selecting authentication controls for an AI system.

Which of the following is the best way to prevent threat actor replay attacks?

Options:

A.

Identity provider (IdP) federation

B.

Secure Shell (SSH)-based certificate authentication

C.

Expiring session tokens

D.

Identity and access management access keys

Buy Now
Questions 30

A security analyst notices that regardless of user-submitted prompts, an AI model always returns unsanitized responses. These responses are then passed to multiple plug-ins. The analyst is concerned with the potential security implications.

Which of the following Open Worldwide Application Security Project (OWASP) categories addresses this vulnerability?

Options:

A.

Misinformation

B.

Prompt injection

C.

Unbounded consumption

D.

Improper output handling

Buy Now
Questions 31

Which of the following is most resistant to AI manipulation?

Options:

A.

Payloads

B.

AI-generated content

C.

Application programming interface (API) gateway

D.

Attack surface reduction

E.

Antivirus

Buy Now
Questions 32

A team of engineers builds an application using a large language model (LLM). The application is built on Linux and is hosted on a virtual server. Users must create an account in order to access and use the platform.

Which of the following should the team do to protect the account credentials?

Options:

A.

Patch the model with the latest data set.

B.

Update the Linux and virtual servers.

C.

Implement hashing and encryption.

D.

Deploy an authenticated application programming interface (API).

Buy Now
Questions 33

A penetration tester is assessing the controls of a deployed AI system that is designed to search and return the contents of files.

The tester runs the following:

Which of the following is the best control to prevent abuse of the system?

Options:

A.

Implementing custom detection rules for anomalous model behavior

B.

Segmenting the workload into a separate virtual private cloud (VPC)

C.

Adding a large language model (LLM) guardrails library to the application code

D.

Reducing the privilege scope of the service account

Buy Now
Questions 34

An organization deploys a browser-based AI plug-in to detect malicious websites and phishing links in corporate email.

Which of the following techniques is used in this AI plug-in?

Options:

A.

Code quality testing

B.

Pattern recognition and signature matching

C.

Automated penetration testing

D.

Automated incident response

Buy Now
Questions 35

During the selection of a machine learning (ML)-based threat classification model, a cybersecurity administrator verifies that label distribution is highly unbalanced.

Which of the following processing techniques should the engineer use to balance the model?

Options:

A.

Data lineage

B.

Data augmentation

C.

Data provenance

D.

Data verification

Buy Now
Questions 36

A line of business wants to onboard an application that uses a custom AI model for employee assessments. The Chief Information Officer (CIO) agrees to allow the engagement to proceed but first wants a threat model.

Which of the following is the most appropriate to use for an AI threat model?

Options:

A.

Responsible AI

B.

Adversarial Threat Landscape for AI Systems (ATLAS)

C.

Organization for Economic Co-operation and Development (OECD)

D.

International Organization for Standardization (ISO)

Buy Now
Questions 37

Which of the following attacks would be the best to automate with AI during dynamic application software testing (DAST)?

Options:

A.

Distributed denial-of-service (DDoS)

B.

Data poisoning

C.

Payload creation

D.

Threat modeling

Buy Now
Questions 38

Which of the following ensures the integrity of data usage in an AI system?

Options:

A.

Data masking

B.

Data cleansing

C.

Data verification

D.

Data lineage

Buy Now
Questions 39

Which of the following provides guidance on AI-specific compliance?

Options:

A.

Organisation for Economic Co-operation and Development (OECD)

B.

International Organization for Standardization (ISO) 27001

C.

Payment Card Industry Data Security Standard (PCI DSS)

D.

General Data Protection Regulation (GDPR)

Buy Now
Questions 40

A security analyst is preparing a presentation for the sales team that describes the most common vulnerabilities that are specific to AI applications.

Which of the following is the best source for the analyst to consult?

Options:

A.

International Organization for Standards (ISO) 27001

B.

Common Weakness Enumeration (CWE)

C.

Open Worldwide Application Security Project (OWASP)

D.

National Institute of Technologies Risk Management Framework (NIST-RMF)

Buy Now
Exam Code: CY0-001
Exam Name: CompTIA SecAI+ v1 Exam
Last Update: Aug 20, 2026
Questions: 134
CY0-001 pdf

CY0-001 PDF

$25.5  $84.99
CY0-001 Engine

CY0-001 Testing Engine

$30  $99.99
CY0-001 PDF + Engine

CY0-001 PDF + Testing Engine

$40.5  $134.99