CY0-001 CompTIA SecAI+ v1 Exam Questions and Answers
A security analyst receives an alert about an AI system and is investigating the following output:

Which of the following is the most appropriate control the analyst should recommend?
A company deploys an internet-facing chatbot using RAG. Logs show that an administrator can retrieve employee names and usernames while an employee receives ' information not available. ' Which of the following is reducing the risk of sensitive data exposure in this scenario?
An organization recently developed an AI-powered product and discovers that it is vulnerable to attacks in which malicious actors can alter the input, causing the system to recommend inappropriate information.
Which of the following techniques is the most effective way to secure the system against manipulation attacks?
An administrator must conduct generative AI cost monitoring for use in the healthcare industry.
Which of the following criteria is the best way to calculate this cost?
Instructions: Use the drop-down menus to define two appropriate security controls for each component of the AI system. Each control may be used only once.
An engineer is deploying a new AI system and wants to integrate it into the core system through an API.

A security analyst notices that regardless of user-submitted prompts, an AI model always returns unsanitized responses. These responses are then passed to multiple plug-ins. The analyst is concerned with the potential security implications.
Which of the following Open Worldwide Application Security Project (OWASP) categories addresses this vulnerability?
An IT company implements an adaptable chatbot that learns from user prompts. Based on the conversation shown — where User 2 injected false information about a company acquisition that caused the chatbot to give incorrect responses to User 3 — which of the following compensating controls should an administrator implement to mitigate the issue?
Which of the following is an example of how a security analyst uses generative AI in the triage process?
As a compliance requirement, a large language model (LLM) application requires setting up guardrails.
Which of the following resources is most appropriate to use?
A healthcare organization plans to deploy a chatbot for appointment scheduling and patient records.
Which of the following is the first step a security administrator should take?
A company uses human review for software development validation and wants to add another validation layer.
Which of the following should a security administrator use to accomplish this task?
Which of the following is the most concerning risk for a company that allows corporate end users to use public-facing large language models (LLMs)?
A management team is concerned about an unexpected cost increase for a public-facing AI chatbot.
Which of the following should a security administrator examine first to determine the root cause?
A customer-facing, AI-powered chatbot has been jailbroken through prompt injections. As a result, the AI model is offering a 99% discount on the purchase of a new vehicle.
Which of the following should be implemented to enhance the model ' s robustness against such attacks?
An organization is concerned with the exposure of sensitive data.
Which of the following is the most relevant security concern?
Which of the following describes the number of training cycles used in an AI model for threat detection?
A security alert triggers an agentic system. An analyst notices the following payload in the logs. The alert includes multiple shell commands that are not typically run as part of any hardening:

Which of the following is the most effective control to implement?
An employee wants a consulting company to procure a data set that contains age, ethnicity, and diabetes status. During development, the employer wants to ensure the integrity of the data.
Which of the following is the best strategy to accomplish this task?
An architect is using the firm ' s recommended large language model (LLM) to find an internal solution for content management.
Given the following:

Which of the following controls is the best for mitigating this issue?
A social media company with more than a million lines of code wants to reduce the mean time to fix bugs and issues.
Which of the following is the most balanced AI strategy to automate the vulnerability management flow?
A security analyst needs to conduct a security assessment of the output from an AI-enabled development tool.
Which of the following should the analyst do first?
A security consultant needs to detect attacks across a large language model (LLM) firewall.
Which of the following techniques should the consultant use?
User experience is declining since the launch of a large language model (LLM) in internal networks.
Which of the following should be the highest priority for the prompt engineers?
Which of the following controls is the best way to mitigate a denial-of-service (DoS) attack?
A cybersecurity administrator must examine the cost of AI and implement controls so the research environment operates within a specified budget.
Which of the following controls is best for this situation?
A penetration tester is assessing the controls of a deployed AI system that is designed to search and return the contents of files.
The tester runs the following:

Which of the following is the best control to prevent abuse of the system?
A data scientist is working with unlabeled data and wants to build a clustering model.
Which of the following techniques should a data scientist use?
A data scientist investigates reports that a production machine learning (ML) model no longer performs with accuracy.
The data scientist finds the following pipeline log entries:

Which of the following should the security team do to mitigate future occurrences?
Part 1: Use drop-down menu to select the most appropriate protocol or cipher for each system component.
Part 2: Use the drop-down menu to select the most appropriate technique to apply to the modified data.
An engineer is analyzing findings from a penetration test that indicate insufficient data encryption. The engineer must implement data security.

An airline corporation wants to implement a chatbot application using a large language model (LLM) so its customers can ask questions and receive answers about flight details and have the option to upload files.
Which of the following security controls should the airline use to protect against malicious input and unauthorized use beyond the service-level agreement? (Choose two.)




