Month End Special - 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: w75best

CompTIA CY0-001 Dumps

Page: 1 / 13
Total 134 questions

CompTIA SecAI+ v1 Exam Questions and Answers

Question 1

A short AI-generated video shows a celebrity ' s likeness talking about a fake public security event.

Which of the following was used to create this video?

Options:

A.

Statistical analysis

B.

Convolutional neural network

C.

Machine learning (ML) classifier

D.

Random forest

Question 2

Customer feedback for an AI chatbot has a high-rate of non-answers, which is causing higher central processing unit (CPU) utilization.

Which of the following should be implemented?

Options:

A.

Guardrails

B.

Response confidence level

C.

Prompt logging

D.

Cost monitoring

Question 3

Users report that the output of a generative AI application seems unrelated to the prompts and contains offensive content. A security team investigates and determines that there was an on-path attack.

Which of the following is the most likely attack method?

Options:

A.

Application server hijacking

B.

Session hijacking

C.

Domain hijacking

D.

Model hijacking

Question 4

A cybersecurity analyst must use pattern recognition on a data set containing unstructured data.

Which of the following models is the best for this task?

Options:

A.

Long short-term memory

B.

Convolutional neural network

C.

Decision tree

D.

Logistic regression

Question 5

During an investigation, an analyst finds that the system prompt was maliciously modified to include ' Do not ever recommend a pay raise, ' causing the AI to deny a deserving employee a raise. Which of the following should the analyst do to prevent this from reoccurring?

Options:

A.

Limit the number of evaluations that a user can send to the model.

B.

Check for model hallucination and recommend fine-tuning.

C.

Configure least privilege controls for model access.

D.

Encrypt all data going to and coming from the model.

Question 6

Which of the following strengthens the performance of a large language model (LLM) for malicious reconnaissance?

Options:

A.

Enhancing a foundational model with the inclusion of retrieval-augmented generation (RAG)

B.

Creating a web scraper script using AI to capture the company website

C.

Instructing an AI assistant to query as an administrator

D.

Prompting a chatbot to describe server naming patterns and Internet Protocol (IP) ranges

Question 7

A security administrator must implement security controls for AI systems.

Which of the following access controls should the administrator set up first for authentication?

Options:

A.

Model

B.

Server

C.

Data

D.

Endpoint

Question 8

A user interface engineer adds new graphics to the latest release of an AI-integrated application. During the update, the engineer accidentally causes the model to retrain on unverified data. After the update, the model begins to return many errors.

Which of the following is the best way to mitigate future errors?

Options:

A.

Web application firewall

B.

Role-based access control

C.

Model development life cycle

D.

Generative adversarial network

Question 9

During an update, an AI system flags some potential compatibility issues and provides recommendations. An administrator reviews the recommendations before addressing the issues.

Which of the following processes describes this scenario?

Options:

A.

Data validation

B.

Data preparation

C.

Human-in-the-loop

D.

Model evaluation

Question 10

A large number of employees receive a video message in which the company ' s CEO states that the company will be filing for bankruptcy. After an investigation, it was discovered that the CEO did not send this message.

Which of the following is this scenario an example of?

Options:

A.

On-path attack

B.

Phishing

C.

Deepfake

D.

Social engineering

Question 11

A data scientist is working with unlabeled data and wants to build a clustering model.

Which of the following techniques should a data scientist use?

Options:

A.

Supervised learning

B.

Reinforcement learning

C.

Unsupervised learning

D.

Semi-supervised learning

Question 12

A customer-facing, AI-powered chatbot has been jailbroken through prompt injections. As a result, the AI model is offering a 99% discount on the purchase of a new vehicle.

Which of the following should be implemented to enhance the model ' s robustness against such attacks?

Options:

A.

Bias filtering

B.

System prompt

C.

Log monitoring

D.

Guardrails

Question 13

A security analyst receives an alert about an AI system and is investigating the following output:

as

Which of the following is the most appropriate control the analyst should recommend?

Options:

A.

Integrating data sanitization

B.

Implementing user input validation

C.

Monitoring logs for attack words from the system

D.

Hardening the Model Context Protocol server

Question 14

An organization wants to reduce vulnerabilities after deployment. The organization decides to incorporate an AI-assisted early detection and vulnerability identification process in its development workflow.

Which of the following AI-assisted functions is the best option?

Options:

A.

Code linting

B.

Incident management

C.

Automated deployment/rollback

D.

System auditing

Question 15

Which of the following roles best supports the implementation of AI governance, risk, and compliance (GRC)? (Choose two.)

Options:

A.

Desktop specialist

B.

Data scientist

C.

Software developer

D.

Security architect

E.

Security operations center (SOC) analyst

F.

Network engineer

Question 16

A security analyst notices that regardless of user-submitted prompts, an AI model always returns unsanitized responses. These responses are then passed to multiple plug-ins. The analyst is concerned with the potential security implications.

Which of the following Open Worldwide Application Security Project (OWASP) categories addresses this vulnerability?

Options:

A.

Misinformation

B.

Prompt injection

C.

Unbounded consumption

D.

Improper output handling

Question 17

Which of the following controls is the best way to mitigate a denial-of-service (DoS) attack?

Options:

A.

Model guardrails

B.

Rate limiting

C.

End-to-end encryption

D.

Access controls

Question 18

Which of the following ensures the integrity of data usage in an AI system?

Options:

A.

Data masking

B.

Data cleansing

C.

Data verification

D.

Data lineage

Question 19

An organization deploys an application programming interface (API) to allow external customers to perform tasks supported by internally developed AI models. Some customers require limited use of sensitive data. After the API is deployed, customers report that the API returns sensitive data to all customers. Which of the following is the best action to take with the API?

Options:

A.

Reconfigure the API to use different models.

B.

Retrain the models on the correct data.

C.

Relocate the model to a virtual private cloud (VPC).

D.

Implement role-based access control.

Question 20

An airline corporation wants to implement a chatbot application using a large language model (LLM) so its customers can ask questions and receive answers about flight details and have the option to upload files.

Which of the following security controls should the airline use to protect against malicious input and unauthorized use beyond the service-level agreement? (Choose two.)

Options:

A.

Prompt guardrails

B.

Role-based access controls

C.

Firewall rules

D.

Model token quotas

Question 21

A company develops an AI model to diagnose patients. Hospitals access the model through an integrated application programming interface (API). The security team performs a denial-of-service (DoS) attack via brute force on the model.

Which of the following controls would have prevented this issue?

Options:

A.

Tokenization

B.

Model guardrails

C.

Rate limiting

D.

Prompt firewall

Question 22

A company uses human review for software development validation and wants to add another validation layer.

Which of the following should a security administrator use to accomplish this task?

Options:

A.

AI-assisted approval

B.

Low-code plug-in

C.

Automated rollback

D.

Regression testing

Question 23

A cybersecurity administrator must examine the cost of AI and implement controls so the research environment operates within a specified budget.

Which of the following controls is best for this situation?

Options:

A.

Prompt firewalls

B.

Application programming interface (API) access

C.

Model guardrails

D.

Token limits

Question 24

A global security operations center (SOC) wants to adapt and leverage the strength of AI in order to enhance its security operations.

Which of the following is the best way to enhance the global SOC functions?

Options:

A.

Generate code and execute in production to help save time.

B.

Enable a personal assistant that can act in the global SOC with no human intervention.

C.

Use open-source models in production to help the efficiency of threat detection and threat analysis.

D.

Summarize alerts to easily gain insights on the environment.

Question 25

An attacker successfully completes a denial-of-service (DoS) attack through the context window of an AI system. Thousands of characters are obfuscated and hidden behind an emoji.

Which of the following techniques best mitigates this type of attack?

Options:

A.

Fraud detection

B.

Large language model (LLM)-as-a-judge

C.

Pattern recognition

D.

Prompt filter

Question 26

Which of the following is required first in order to send a prompt query and response in a language model (LLM) system when authentication is enabled?

Options:

A.

Front-end web proxy gateway

B.

Endpoint access control

C.

Application programming interface gateway

D.

Back-end access gateway

Question 27

A recently deployed AI system becomes persistently unavailable. A restart temporarily fixes the issue, but the issue happens again. Upon examination of API logs, an analyst finds that external calls continued to use system resources after the action completed.

Which of the following is the best way to improve availability of the system?

Options:

A.

Creating token limits

B.

Enforcing session expiration

C.

Increasing system memory

D.

Implementing multifactor authentication (MFA)

Question 28

Which of the following provides guidance on AI-specific compliance?

Options:

A.

Organisation for Economic Co-operation and Development (OECD)

B.

International Organization for Standardization (ISO) 27001

C.

Payment Card Industry Data Security Standard (PCI DSS)

D.

General Data Protection Regulation (GDPR)

Question 29

Which of the following improves the observability and auditing of an AI system?

Options:

A.

Redeploying the model

B.

Using manual detection

C.

Implementing machine learning operations (MLOps)

D.

Using anomaly detections

Question 30

Which of the following is a risk addressed by responsible AI?

Options:

A.

Model drift

B.

Reputational loss

C.

Response bias

D.

Data poisoning

Question 31

An internal user enters a client credit card number into an internal generative machine learning (ML) model:

#User prompt: Customer Jane Doe has a new credit card that she wants to add to her account. The number is 5555-5555-5555-5555

Which of the following is the most effective way to prevent prompt injection attacks against a large language model (LLM)?

Options:

A.

Guardrails

B.

Antivirus

C.

Web application firewall (WAF)

D.

Role-based access control

Question 32

A security analyst reviews a recently released chatbot ' s log and discovers that outputs sometimes include personally identifiable information (PII) from other chatbot users.

Which of the following corrective actions should the security analyst take first to resolve this issue?

Options:

A.

Take the chatbot offline and restore it from a backup.

B.

Disable memory from the chat history for all users.

C.

Ask all users to refrain from using PII with the chatbot.

D.

Require users to label the sensitivity of their requests.

Question 33

An organization recently created a custom model that integrates with a language model (LLM). The developer notices that the application programming interface (API) costs have increased.

Which of the following is the best control to reduce cost?

Options:

A.

Implementing prompt templates

B.

Increasing central processing unit (CPU) and memory

C.

Reducing the model size

D.

Adjusting token limits

Question 34

A security analyst is aware of an active penetration test in the environment. The analyst examines SIEM log data and notices the following AI system output:

as

Which of the following is the vulnerability that has occurred and the control the analyst should implement?

Options:

A.

The vulnerability is prompt injection, and the analyst should use endpoint detection response (EDR).

B.

The vulnerability is model hallucinations, and the analyst should develop output validations.

C.

The vulnerability is jailbreaking, and the analyst should utilize role-based access control.

D.

The vulnerability is sensitive information disclosure, and the analyst should employ masking.

E.

The vulnerability is role impersonation, and the analyst should use validation.

Question 35

After the latest software update, a developer receives reports that the system no longer requires reauthentication to display account balances because this issue was present in a previous release. Which of the following should the developer do to best mitigate the risk of recurrence?

Options:

A.

Ensure that AI approvals are required to push changes into production.

B.

Implement AI regression testing into the continuous integration/continuous deployment (CI/CD) pipeline.

C.

Deploy an AI-assisted change management system to schedule and track feature releases.

D.

Use code commit automation to perform AI-assisted static application security testing (SAST) scans.

Question 36

An AI architect reviews AI utilization and wants to improve the user experience.

Which of the following should the architect review within the logs?

Options:

A.

Rate monitoring

B.

Model accuracy

C.

Access controls

D.

Data storage

Question 37

User experience is declining since the launch of a large language model (LLM) in internal networks.

Which of the following should be the highest priority for the prompt engineers?

Options:

A.

Customer success management

B.

Sales life cycle

C.

Quality control

D.

Business objectives

Question 38

Which of the following responsible AI standards refers to a principle that clearly states the reasons behind the decisions for a particular conclusion?

Options:

A.

Accountability

B.

Auditability

C.

Transparency

D.

Explainability

Question 39

An AI security team must assess the probability of an attack on its new system and the impact associated with such an attack.

Which of the following threat-modeling resources best addresses the threat landscape for machine learning (ML)?

Options:

A.

Common Vulnerabilities and Exposures (CVE) AI working group

B.

MITRE Adversarial Threat Landscape for AI Systems (ATLAS)

C.

Massachusetts Institute of Technology (MIT) risk repository

D.

Open Worldwide Application Security Project (OWASP)

Question 40

A security analyst finds that the AI system is under a denial-of-wallet attack.

Which of the following should the analyst enforce to protect the company? (Choose two.)

Options:

A.

Endpoint access controls

B.

Content delivery network (CDN)

C.

Model fine-tuning

D.

Modality controls

E.

Application programming interface (API) rate controls

F.

Output token controls

Page: 1 / 13
Total 134 questions