Pre-Summer Sale Discount Flat 70% Offer - Ends in 0d 00h 00m 00s - Coupon code: 70diswrap

CompTIA CY0-001 Dumps

Page: 1 / 13
Total 126 questions

CompTIA SecAI+ v1 Exam Questions and Answers

Question 1

Which of the following is used to train an AI model with unstructured data?

Options:

A.

Statistical learning

B.

Fine-tuning

C.

Supervised learning

D.

Reinforcement training

Question 2

An IT company implements an adaptable chatbot that learns from user prompts. Based on the conversation shown — where User 2 injected false information about a company acquisition that caused the chatbot to give incorrect responses to User 3 — which of the following compensating controls should an administrator implement to mitigate the issue?

Options:

A.

Data encryption

B.

Rate-limiting application programming interfaces (APIs)

C.

Transfer learning

D.

Guardrails

Question 3

An architect is using the firm ' s recommended large language model (LLM) to find an internal solution for content management.

Given the following:

as

Which of the following controls is the best for mitigating this issue?

Options:

A.

Model training

B.

Response validation

C.

Access controls

D.

Integrity monitoring

Question 4

Which of the following requires developers to harden infrastructure to protect AI systems?

Options:

A.

Intake processes

B.

Acceptable use policies

C.

Development guidelines

D.

Configuration standards

Question 5

Which of the following ensures the integrity of data usage in an AI system?

Options:

A.

Data masking

B.

Data cleansing

C.

Data verification

D.

Data lineage

Question 6

Which of the following controls is the best way to mitigate a denial-of-service (DoS) attack?

Options:

A.

Model guardrails

B.

Rate limiting

C.

End-to-end encryption

D.

Access controls

Question 7

A security analyst is aware of an active penetration test in the environment. The analyst examines SIEM log data and notices the following AI system output:

as

Which of the following is the vulnerability that has occurred and the control the analyst should implement?

Options:

A.

The vulnerability is prompt injection, and the analyst should use endpoint detection response (EDR).

B.

The vulnerability is model hallucinations, and the analyst should develop output validations.

C.

The vulnerability is jailbreaking, and the analyst should utilize role-based access control.

D.

The vulnerability is sensitive information disclosure, and the analyst should employ masking.

E.

The vulnerability is role impersonation, and the analyst should use validation.

Question 8

A management team is concerned about an unexpected cost increase for a public-facing AI chatbot.

Which of the following should a security administrator examine first to determine the root cause?

Options:

A.

Firewall logs

B.

Web application firewall (WAF) rules

C.

Vector database input/output operations per second performance

D.

Model token usage

Question 9

User experience is declining since the launch of a large language model (LLM) in internal networks.

Which of the following should be the highest priority for the prompt engineers?

Options:

A.

Customer success management

B.

Sales life cycle

C.

Quality control

D.

Business objectives

Question 10

During a model validation procedure, an engineer notices that a model performs well during training but poorly during testing.

Which of the following best describes the reason?

Options:

A.

Fine-tuning

B.

Overfitting

C.

Regularization

D.

Inference

Question 11

Which of the following is the primary security risk when deploying AI models in production?

Options:

A.

Graphics processing unit (GPU) acceleration

B.

Model overfitting

C.

Model encryption

D.

Data exposure

Question 12

A cybersecurity administrator generates patching reports using AI, but the process takes a long time. Which of the following is the best way to increase performance?

Options:

A.

Deploy a Model Context Protocol (MCP) server to delegate several versions of this query to the back-end LLM simultaneously.

B.

Have the AI download the full CVE database first to prevent multiple similar external queries.

C.

Configure the AI system prompt to specify summarization algorithms.

D.

Increase the amount of model tokens available to eliminate time-consuming session restarts.

Question 13

A cybersecurity analyst must use pattern recognition on a data set containing unstructured data.

Which of the following models is the best for this task?

Options:

A.

Long short-term memory

B.

Convolutional neural network

C.

Decision tree

D.

Logistic regression

Question 14

A global security operations center (SOC) wants to adapt and leverage the strength of AI in order to enhance its security operations.

Which of the following is the best way to enhance the global SOC functions?

Options:

A.

Generate code and execute in production to help save time.

B.

Enable a personal assistant that can act in the global SOC with no human intervention.

C.

Use open-source models in production to help the efficiency of threat detection and threat analysis.

D.

Summarize alerts to easily gain insights on the environment.

Question 15

Which of the following provides guidance on AI-specific compliance?

Options:

A.

Organisation for Economic Co-operation and Development (OECD)

B.

International Organization for Standardization (ISO) 27001

C.

Payment Card Industry Data Security Standard (PCI DSS)

D.

General Data Protection Regulation (GDPR)

Question 16

Which of the following responsible AI standards refers to a principle that clearly states the reasons behind the decisions for a particular conclusion?

Options:

A.

Accountability

B.

Auditability

C.

Transparency

D.

Explainability

Question 17

A security team is using an AI-based tool to try to bypass organizational boundaries. The team uses AI to look at the current state and suggest different attack vectors based on the outcome of the previous ones.

Which of the following techniques is the team most likely using?

Options:

A.

Manual signature matching

B.

Code quality testing

C.

Fraud detection

D.

Automated penetration testing

Question 18

Which of the following is the best example of an AI model that is trained to identify multiple points from input using a neural network to provide output for authentication?

Options:

A.

Facial recognition

B.

Encryption key

C.

Open Authorization (OAuth)

D.

Bounding box

Question 19

A detection engineering team wants to use AI to automatically prevent vulnerable code from reaching production.

Which of the following is the most effective way to accomplish this task?

Options:

A.

Deploying an integrated development environment (IDE) plug-in that will warn developers of dangerous code before compiling

B.

Using a security orchestration, automation, and response (SOAR) with a machine learning (ML) model to classify code

C.

Implementing a large language model (LLM) in the continuous integration and continuous deployment (CI/CD) runner to examine code and pass or fail build jobs

D.

Developing an agentic penetration testing tool to validate potential vulnerable code

Question 20

A security analyst reviews a recently released chatbot ' s log and discovers that outputs sometimes include personally identifiable information (PII) from other chatbot users.

Which of the following corrective actions should the security analyst take first to resolve this issue?

Options:

A.

Take the chatbot offline and restore it from a backup.

B.

Disable memory from the chat history for all users.

C.

Ask all users to refrain from using PII with the chatbot.

D.

Require users to label the sensitivity of their requests.

Question 21

An AI security team must assess the probability of an attack on its new system and the impact associated with such an attack.

Which of the following threat-modeling resources best addresses the threat landscape for machine learning (ML)?

Options:

A.

Common Vulnerabilities and Exposures (CVE) AI working group

B.

MITRE Adversarial Threat Landscape for AI Systems (ATLAS)

C.

Massachusetts Institute of Technology (MIT) risk repository

D.

Open Worldwide Application Security Project (OWASP)

Question 22

An automobile manufacturer implements a chatbot to assist with configuration options for customer automobiles. Given a customer ' s prompt, the chatbot gives offensive responses.

Which of the following describes this behavior?

Options:

A.

Model skewing

B.

Model theft

C.

Jailbreaking

D.

Insecure output handling

Question 23

A company is adopting AI and wants to create policies and procedures that include a structure for evaluating, publishing, and approving patterns for AI usage.

Which of the following should the company establish to meet this goal?

Options:

A.

AI center of excellence

B.

AI legal affairs office

C.

AI audit department

D.

AI data science division

Question 24

A security alert triggers an agentic system. An analyst notices the following payload in the logs. The alert includes multiple shell commands that are not typically run as part of any hardening:

as

Which of the following is the most effective control to implement?

Options:

A.

Adding logic that includes approved strings before running the shell commands

B.

Deprecating model usage and retaining the model with safer parameters

C.

Modifying the application to ignore the SECURITY_UPDATE tag

D.

Using only approved libraries when interacting with agentic systems

Question 25

A security architect performs threat modeling of an AI system. The architect needs to determine which attacks can be performed against the system.

Which of the following actions should the architect take next?

Options:

A.

Leverage a large language model (LLM) to map likely attack paths based on the code base.

B.

Quantify the risk of known vulnerabilities identified in the AI system.

C.

Identify trust boundaries and perform threat modeling with Open Worldwide Application Security Project (OWASP) Top 10.

D.

Analyze MITRE Adversarial Threat Landscape for AI Systems (ATLAS) for tactics, techniques, and procedures (TTPs).

Question 26

An organization is developing and implementing AI features into a customer service application.

Which of the following practices should the organization put in place before releasing the application for customer trials?

Options:

A.

Data masking and sanitization

B.

External compliance audits

C.

Approved AI vendor lists

D.

Third-party risk management

Question 27

A cybersecurity administrator needs a security mechanism that can validate input.

Which of the following controls should the administrator use?

Options:

A.

Prompt firewall

B.

Rate limits

C.

Token limits

D.

Input quantity

Question 28

Which of the following strengthens the performance of a large language model (LLM) for malicious reconnaissance?

Options:

A.

Enhancing a foundational model with the inclusion of retrieval-augmented generation (RAG)

B.

Creating a web scraper script using AI to capture the company website

C.

Instructing an AI assistant to query as an administrator

D.

Prompting a chatbot to describe server naming patterns and Internet Protocol (IP) ranges

Question 29

An organization is concerned with the exposure of sensitive data.

Which of the following is the most relevant security concern?

Options:

A.

Overfitting

B.

Model inversion

C.

Data normalization

D.

Hyperparameter tuning

Question 30

An attacker successfully completes a denial-of-service (DoS) attack through the context window of an AI system. Thousands of characters are obfuscated and hidden behind an emoji.

Which of the following techniques best mitigates this type of attack?

Options:

A.

Fraud detection

B.

Large language model (LLM)-as-a-judge

C.

Pattern recognition

D.

Prompt filter

Question 31

Which of the following is an example of how a security analyst uses generative AI in the triage process?

Options:

A.

To predict the next attack target with higher accuracy

B.

To use statistical analysis for malicious code assessment

C.

To summarize security findings by category

D.

To tag malware using machine learning (ML) algorithms

Question 32

During an update, an AI system flags some potential compatibility issues and provides recommendations. An administrator reviews the recommendations before addressing the issues.

Which of the following processes describes this scenario?

Options:

A.

Data validation

B.

Data preparation

C.

Human-in-the-loop

D.

Model evaluation

Question 33

Which of the following should an auditor reference when reviewing a company ' s human resources AI systems for legal non-compliance?

Options:

A.

Organization for Economic Cooperation and Development (OECD) standard

B.

National Institute of Standards and Technology (NIST) AI Risk Management Framework (RMF)

C.

European Union (EU) AI Act

D.

International Organization for Standardization (ISO)

Question 34

During the selection of a machine learning (ML)-based threat classification model, a cybersecurity administrator verifies that label distribution is highly unbalanced.

Which of the following processing techniques should the engineer use to balance the model?

Options:

A.

Data lineage

B.

Data augmentation

C.

Data provenance

D.

Data verification

Question 35

A company introduces a large language model (LLM) in an application in order to monitor for a potential denial-of-service attack.

Which of the following should the company use to measure the utilization of the LLM?

Options:

A.

Token

B.

Transformer

C.

Chain of thoughts

D.

Prompt

Question 36

A security engineer needs to monitor an AI-based system for runtime operations. The engineer is mostly concerned about the visibility of internal activity.

Which of the following is the most appropriate monitoring solution?

Options:

A.

Deploying a security information and event management (SIEM) tool

B.

Implementing a web application firewall (WAF) with header logging

C.

Relying on vendor model controls and monitoring prompt inputs

D.

Enabling stack call and debugging level traces at the function level

Question 37

A short AI-generated video shows a celebrity ' s likeness talking about a fake public security event.

Which of the following was used to create this video?

Options:

A.

Statistical analysis

B.

Convolutional neural network

C.

Machine learning (ML) classifier

D.

Random forest

Page: 1 / 13
Total 126 questions