Month End Special 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: budy75

CY0-001 CompTIA SecAI+ v1 Exam Questions and Answers

Questions 4

During a model validation procedure, an engineer notices that a model performs well during training but poorly during testing.

Which of the following best describes the reason?

Options:

A.

Fine-tuning

B.

Overfitting

C.

Regularization

D.

Inference

Buy Now
Questions 5

A data set containing medical information is put into a machine learning (ML) model that is designed to predict specific illnesses for a population. In the process of verifying the reliability of the system, the compliance officer realizes that the system cannot reliably predict illnesses for certain segments of the population.

Which of the following types of risk is most applicable to this case?

Options:

A.

Bias

B.

Consistency

C.

Transparency

D.

Inclusiveness

Buy Now
Questions 6

A security team is using an AI-based tool to try to bypass organizational boundaries. The team uses AI to look at the current state and suggest different attack vectors based on the outcome of the previous ones.

Which of the following techniques is the team most likely using?

Options:

A.

Manual signature matching

B.

Code quality testing

C.

Fraud detection

D.

Automated penetration testing

Buy Now
Questions 7

An organization wants to reduce vulnerabilities after deployment. The organization decides to incorporate an AI-assisted early detection and vulnerability identification process in its development workflow.

Which of the following AI-assisted functions is the best option?

Options:

A.

Code linting

B.

Incident management

C.

Automated deployment/rollback

D.

System auditing

Buy Now
Questions 8

Which of the following attacks would be the best to automate with AI during dynamic application software testing (DAST)?

Options:

A.

Distributed denial-of-service (DDoS)

B.

Data poisoning

C.

Payload creation

D.

Threat modeling

Buy Now
Questions 9

As a compliance requirement, a large language model (LLM) application requires setting up guardrails.

Which of the following resources is most appropriate to use?

Options:

A.

Retrieval-augmented generation (RAG)

B.

Open Worldwide Application Security Project (OWASP)

C.

LLM libraries

D.

Security incident and event management (SIEM)

Buy Now
Questions 10

A team of data scientists is ready to release a model for enterprise use. The team wants to protect the model from unintentional changes or tampering.

Which of the following is the most appropriate action?

Options:

A.

Change the model to a large language model (LLM) for interactive features with guardrails.

B.

Provide secure copies of the model for local runtime usage.

C.

Restrict access to only IT professionals in the organization.

D.

Integrate an application programming interface (API) with identity and access management (IAM) roles to interact with the model.

Buy Now
Questions 11

Which of the following requires developers to harden infrastructure to protect AI systems?

Options:

A.

Intake processes

B.

Acceptable use policies

C.

Development guidelines

D.

Configuration standards

Buy Now
Questions 12

Which of the following International Organization for Standardization (ISO) standards contains compliance requirements for building an AI management system?

Options:

A.

20000

B.

27001

C.

27018

D.

42001

Buy Now
Questions 13

A security analyst receives an alert about an AI system and is investigating the following output:

CY0-001 Question 13

Which of the following is the most appropriate control the analyst should recommend?

Options:

A.

Integrating data sanitization

B.

Implementing user input validation

C.

Monitoring logs for attack words from the system

D.

Hardening the Model Context Protocol server

Buy Now
Questions 14

An AI security administrator receives an inquiry about an unusually high monthly bill from the AI solution provider. The administrator thinks the majority of staff might be using the most powerful model available.

Which of the following AI measures should the administrator implement to lower costs?

Options:

A.

Storage monitoring

B.

Modality types

C.

Prompt firewalls

D.

Token limits

Buy Now
Questions 15

A recent release of an AI software update exposes confidential customer information due to storage misconfiguration.

Which of the following data security controls will help maintain confidentiality despite the data leak?

Options:

A.

Model encryption

B.

Encryption in transit

C.

Encryption in use

D.

Encryption at rest

Buy Now
Questions 16

A security analyst is preparing a presentation for the sales team that describes the most common vulnerabilities that are specific to AI applications.

Which of the following is the best source for the analyst to consult?

Options:

A.

International Organization for Standards (ISO) 27001

B.

Common Weakness Enumeration (CWE)

C.

Open Worldwide Application Security Project (OWASP)

D.

National Institute of Technologies Risk Management Framework (NIST-RMF)

Buy Now
Questions 17

Which of the following would most likely be used to prove that an image is AI generated?

Options:

A.

Human validation

B.

Guardrails

C.

Diffusion

D.

Watermarking

Buy Now
Questions 18

An architect is creating a threat model for an agentic system.

Which of the following should the architect do first?

Options:

A.

Apply compensating controls based on exposure findings.

B.

Identify the trust boundary between the components.

C.

Calculate the risk to resources based on data sensitivity.

D.

Scan for vulnerabilities from the Open Worldwide Application Security Project (OWASP) Top 10.

Buy Now
Questions 19

A human resources officer is using AI to evaluate resumes and help select candidates that meet minimum criteria. To improve the results, the human resources officer adjusts the query parameters and includes an example resume that matches a successful candidate.

Which of the following best describes this query?

Options:

A.

Distillation

B.

Prompt template

C.

One-shot prompting

D.

System role

Buy Now
Questions 20

A security administrator needs to improve an AI model. During an initial investigation, the administrator notices that two successive login failures are recorded every day, and then a successful login occurs after a specific time interval. All the successful login attempts have been during office hours.

Which of the following techniques should the administrator use to improve the AI model ' s security?

Options:

A.

Access management

B.

Pattern recognition

C.

Signature matching

D.

Vulnerability analysis

Buy Now
Questions 21

A short AI-generated video shows a celebrity ' s likeness talking about a fake public security event.

Which of the following was used to create this video?

Options:

A.

Statistical analysis

B.

Convolutional neural network

C.

Machine learning (ML) classifier

D.

Random forest

Buy Now
Questions 22

Users report that the output of a generative AI application seems unrelated to the prompts and contains offensive content. A security team investigates and determines that there was an on-path attack.

Which of the following is the most likely attack method?

Options:

A.

Application server hijacking

B.

Session hijacking

C.

Domain hijacking

D.

Model hijacking

Buy Now
Questions 23

An organization deploys an application programming interface (API) to allow external customers to perform tasks supported by internally developed AI models. Some customers require limited use of sensitive data. After the API is deployed, customers report that the API returns sensitive data to all customers. Which of the following is the best action to take with the API?

Options:

A.

Reconfigure the API to use different models.

B.

Retrain the models on the correct data.

C.

Relocate the model to a virtual private cloud (VPC).

D.

Implement role-based access control.

Buy Now
Questions 24

A cybersecurity analyst must use pattern recognition on a data set containing unstructured data.

Which of the following models is the best for this task?

Options:

A.

Long short-term memory

B.

Convolutional neural network

C.

Decision tree

D.

Logistic regression

Buy Now
Questions 25

Which of the following is the primary purpose of validating data for an AI system?

Options:

A.

To automate the process

B.

To reduce consumption of resources

C.

To optimize the storage databases

D.

To ensure bias-free outcomes

Buy Now
Questions 26

A security analyst reviews a recently released chatbot ' s log and discovers that outputs sometimes include personally identifiable information (PII) from other chatbot users.

Which of the following corrective actions should the security analyst take first to resolve this issue?

Options:

A.

Take the chatbot offline and restore it from a backup.

B.

Disable memory from the chat history for all users.

C.

Ask all users to refrain from using PII with the chatbot.

D.

Require users to label the sensitivity of their requests.

Buy Now
Questions 27

A team of engineers builds an application using a large language model (LLM). The application is built on Linux and is hosted on a virtual server. Users must create an account in order to access and use the platform.

Which of the following should the team do to protect the account credentials?

Options:

A.

Patch the model with the latest data set.

B.

Update the Linux and virtual servers.

C.

Implement hashing and encryption.

D.

Deploy an authenticated application programming interface (API).

Buy Now
Questions 28

A disgruntled employee changed the company policies that a chatbot references in order to create confusion and disrupt the business.

Which of the following AI-generated vulnerabilities is the employee exploiting?

Options:

A.

Data reduction

B.

Data masking

C.

Data poisoning

D.

Data leaking

Buy Now
Questions 29

A group of security engineers is developing a SIEM system that will be able to ingest data from multiple structured and unstructured sources, have a chatbot integrated with an LLM that the security analyst can interact with, and provide insights from the SIEM alert data.

Which of the following techniques should the security engineers consider before collecting the data from the respective sources?

Options:

A.

Balancing

B.

Verification

C.

Cleansing

D.

Vector storage

Buy Now
Questions 30

A company launches an AI application to monitor cloud misconfiguration and compliance. The AI application is shutting down development servers and opening ports during a client demonstration. Which of the following actions should the company take to return to normal operations and prevent future issues?

Options:

A.

Restarting the servers

B.

Disabling the cloud monitoring

C.

Reconfiguring the firewall

D.

Implementing human-in-the-loop

Buy Now
Questions 31

A data scientist investigates reports that a production machine learning (ML) model no longer performs with accuracy.

The data scientist finds the following pipeline log entries:

CY0-001 Question 31

Which of the following should the security team do to mitigate future occurrences?

Options:

A.

Add static code scanning tooling to the runner job.

B.

Enable human review and approval workflows in the repository.

C.

Retrain the model on using increased data and epochs.

D.

Keep multiple copies of the model for restoration.

Buy Now
Questions 32

A developer is proposing a new AI application for human resources systems. Which of the following are the most important considerations?

Options:

A.

Geniality and appeal

B.

Privacy and security

C.

Graphics and design

D.

Brevity and summarization

Buy Now
Questions 33

A manufacturing company wants to use AI within its operations to improve the efficiency and accuracy of its processes.

Which of the following should the organization do first to enable adoption and achieve the business objectives?

Options:

A.

Achieve International Organization for Standardization (ISO) 42001 certification.

B.

Hire a data and AI architect.

C.

Select a large language model (LLM).

D.

Introduce a generative adversarial network (GAN).

Buy Now
Questions 34

A security analyst needs to conduct a security assessment of the output from an AI-enabled development tool.

Which of the following should the analyst do first?

Options:

A.

Remove hard-coded secrets from the source code.

B.

Enforce strict access controls for code repositories.

C.

Enable sensitive data discovery on code repositories.

D.

Perform a source code review.

Buy Now
Questions 35

Security analysts want to track potential user behavior anomalies over time. Which of the following is the most comprehensive approach?

Options:

A.

Using an AI-enabled scanner to compare user permissions to other users in the department

B.

Using an agentic large language model (LLM) to search for multiple instances of a username in logs

C.

Leveraging browser plug-ins that monitor for uncommon sites visited by a user

D.

Running automated playbooks that monitor standard deviations from a user baseline

Buy Now
Questions 36

An airline corporation wants to implement a chatbot application using a large language model (LLM) so its customers can ask questions and receive answers about flight details and have the option to upload files.

Which of the following security controls should the airline use to protect against malicious input and unauthorized use beyond the service-level agreement? (Choose two.)

Options:

A.

Prompt guardrails

B.

Role-based access controls

C.

Firewall rules

D.

Model token quotas

Buy Now
Questions 37

Which of the following is the best example of an AI model that is trained to identify multiple points from input using a neural network to provide output for authentication?

Options:

A.

Facial recognition

B.

Encryption key

C.

Open Authorization (OAuth)

D.

Bounding box

Buy Now
Questions 38

A critical AI system cannot be shut down and must remain secure. Which of the following actions should be performed to apply controls?

Options:

A.

Removing the data encryption

B.

Patching critical vulnerabilities

C.

Scanning logs to detect anomalies

D.

Redeploying the production models

Buy Now
Questions 39

After the latest software update, a developer receives reports that the system no longer requires reauthentication to display account balances because this issue was present in a previous release. Which of the following should the developer do to best mitigate the risk of recurrence?

Options:

A.

Ensure that AI approvals are required to push changes into production.

B.

Implement AI regression testing into the continuous integration/continuous deployment (CI/CD) pipeline.

C.

Deploy an AI-assisted change management system to schedule and track feature releases.

D.

Use code commit automation to perform AI-assisted static application security testing (SAST) scans.

Buy Now
Questions 40

A security operations center (SOC) analyst needs to automate multiple security tasks by breaking them down into smaller parts.

Which of the following AI tools is the best for this task?

Options:

A.

Agentic AI

B.

Retrieval-augmented generation (RAG) AI

C.

Generative AI

D.

Chatbot

Buy Now
Exam Code: CY0-001
Exam Name: CompTIA SecAI+ v1 Exam
Last Update: Aug 29, 2026
Questions: 134

PDF + Testing Engine

$140

Testing Engine

$105

PDF (Q&A)

$90