Month End Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: chrismas

Free Practice Questions for the CompTIA SecAI+ CY0-001 Exam (2026 Updated)

At Marks4sure, we are dedicated to providing IT professionals with the most accurate and reliable preparation materials for the CompTIA CY0-001 exam. To support your certification journey, we have made a selection of our premium 2026 CompTIA SecAI+ practice questions and answers available completely free. You can take this practice test as many times as you need. Every question includes a detailed, expertly verified explanation to ensure you fully grasp the core security concepts before test day.

Questions 4

A SOC team has an AI agent that performs web searches and calls to the SOAR solution. The team is concerned about enterprise uptime and case resolution time.

Which of the following is the most appropriate use of the AI agent?

Options:

A.

To analyze and contain offending users or hosts using SOAR playbooks

B.

To perform research using open-source intelligence to enrich the alerts

C.

To aggregate SOC metrics and generate reports for the leadership team

D.

To create tabletop exercises so the team can increase its incident response speed

Buy Now
Questions 5

A security operations center (SOC) has a very high volume of logs and alerts. The manager proposes the implementation of a machine learning (ML) system to help with triage.

Which of the following tasks is most suitable?

Options:

A.

Applying filters on specific alerts

B.

Automatically patching vulnerable systems

C.

Identifying and classifying alerts

D.

Summarizing the content of alerts

Buy Now

CY0-001 Report Card

Questions 6

A cybersecurity administrator must examine the cost of AI and implement controls so the research environment operates within a specified budget.

Which of the following controls is best for this situation?

Options:

A.

Prompt firewalls

B.

Application programming interface (API) access

C.

Model guardrails

D.

Token limits

Buy Now
Questions 7

A company uses human review for software development validation and wants to add another validation layer.

Which of the following should a security administrator use to accomplish this task?

Options:

A.

AI-assisted approval

B.

Low-code plug-in

C.

Automated rollback

D.

Regression testing

Buy Now
Questions 8

Which of the following helps in managing potential security issues related to model training?

Options:

A.

National Institute of Standards and Technology (NIST) AI Risk Management Framework (RMF)

B.

International Organization for Standardization (ISO) 27001

C.

Organization for Economic Co-operation and Development (OECD)

D.

General Data Protection Regulation (GDPR)

Buy Now
Questions 9

A cybersecurity analyst must use pattern recognition on a data set containing unstructured data.

Which of the following models is the best for this task?

Options:

A.

Long short-term memory

B.

Convolutional neural network

C.

Decision tree

D.

Logistic regression

Buy Now
Questions 10

A company launches an AI application to monitor cloud misconfiguration and compliance. The AI application is shutting down development servers and opening ports during a client demonstration. Which of the following actions should the company take to return to normal operations and prevent future issues?

Options:

A.

Restarting the servers

B.

Disabling the cloud monitoring

C.

Reconfiguring the firewall

D.

Implementing human-in-the-loop

Buy Now
Questions 11

A security administrator sees suspicious queries on AI logs.

Which of the following should the administrator implement to address this issue?

Options:

A.

Prompt firewalls

B.

Data size

C.

Rate limit

D.

Agentic AI

Buy Now
Questions 12

An architect is using the firm ' s recommended large language model (LLM) to find an internal solution for content management.

Given the following:

CY0-001 Question 12

Which of the following controls is the best for mitigating this issue?

Options:

A.

Model training

B.

Response validation

C.

Access controls

D.

Integrity monitoring

Buy Now
Questions 13

A recently deployed AI system becomes persistently unavailable. A restart temporarily fixes the issue, but the issue happens again. Upon examination of API logs, an analyst finds that external calls continued to use system resources after the action completed.

Which of the following is the best way to improve availability of the system?

Options:

A.

Creating token limits

B.

Enforcing session expiration

C.

Increasing system memory

D.

Implementing multifactor authentication (MFA)

Buy Now
Questions 14

Users report that the output of a generative AI application seems unrelated to the prompts and contains offensive content. A security team investigates and determines that there was an on-path attack.

Which of the following is the most likely attack method?

Options:

A.

Application server hijacking

B.

Session hijacking

C.

Domain hijacking

D.

Model hijacking

Buy Now
Questions 15

A company is adopting AI and wants to create policies and procedures that include a structure for evaluating, publishing, and approving patterns for AI usage.

Which of the following should the company establish to meet this goal?

Options:

A.

AI center of excellence

B.

AI legal affairs office

C.

AI audit department

D.

AI data science division

Buy Now
Questions 16

A cybersecurity analyst wants to choose a machine learning (ML) model to classify log entries while providing the best explainability.

Which of the following models should the analyst use?

Options:

A.

Large language model (LLM)

B.

Neural networks

C.

Decision trees

D.

Generative adversarial network (GAN)

Buy Now
Questions 17

An AI security administrator notices that the information referenced by the model is incorrectly formatted and missing values.

Which of the following job roles would most likely be responsible for correcting this error?

Options:

A.

Platform engineer

B.

Machine learning operations (MLOps) engineer

C.

Data engineer

D.

AI architect

Buy Now
Questions 18

A healthcare organization plans to deploy a chatbot for appointment scheduling and patient records.

Which of the following is the first step a security administrator should take?

Options:

A.

Implement prompt firewalls.

B.

Enable role-based access management

C.

Conduct a risk assessment.

D.

Use a secure data communication channel for chat.

Buy Now
Questions 19

A security architect performs threat modeling of an AI system. The architect needs to determine which attacks can be performed against the system.

Which of the following actions should the architect take next?

Options:

A.

Leverage a large language model (LLM) to map likely attack paths based on the code base.

B.

Quantify the risk of known vulnerabilities identified in the AI system.

C.

Identify trust boundaries and perform threat modeling with Open Worldwide Application Security Project (OWASP) Top 10.

D.

Analyze MITRE Adversarial Threat Landscape for AI Systems (ATLAS) for tactics, techniques, and procedures (TTPs).

Buy Now
Questions 20

A social media company with more than a million lines of code wants to reduce the mean time to fix bugs and issues.

Which of the following is the most balanced AI strategy to automate the vulnerability management flow?

Options:

A.

Using AI to triage discovered issues and create tickets, but having a software engineer merge software

B.

Having security analysts triage discovered issues and create tickets, but using AI to merge software

C.

Having security analysts triage discovered issues and create tickets, but having a software engineer merge software

D.

Using AI to triage discovered issues, create tickets, and merge software fixes

Buy Now
Questions 21

A team of data scientists is ready to release a model for enterprise use. The team wants to protect the model from unintentional changes or tampering.

Which of the following is the most appropriate action?

Options:

A.

Change the model to a large language model (LLM) for interactive features with guardrails.

B.

Provide secure copies of the model for local runtime usage.

C.

Restrict access to only IT professionals in the organization.

D.

Integrate an application programming interface (API) with identity and access management (IAM) roles to interact with the model.

Buy Now
Questions 22

An AI architect reviews AI utilization and wants to improve the user experience.

Which of the following should the architect review within the logs?

Options:

A.

Rate monitoring

B.

Model accuracy

C.

Access controls

D.

Data storage

Buy Now
Questions 23

Which of the following International Organization for Standardization (ISO) standards should be selected for certification to use for third-party assurance for responsible AI practices?

Options:

A.

20000

B.

27001

C.

27701

D.

42001

Buy Now
Questions 24

A human resources officer is using AI to evaluate resumes and help select candidates that meet minimum criteria. To improve the results, the human resources officer adjusts the query parameters and includes an example resume that matches a successful candidate.

Which of the following best describes this query?

Options:

A.

Distillation

B.

Prompt template

C.

One-shot prompting

D.

System role

Buy Now
Questions 25

A critical AI system cannot be shut down and must remain secure. Which of the following actions should be performed to apply controls?

Options:

A.

Removing the data encryption

B.

Patching critical vulnerabilities

C.

Scanning logs to detect anomalies

D.

Redeploying the production models

Buy Now
Questions 26

A data set containing medical information is put into a machine learning (ML) model that is designed to predict specific illnesses for a population. In the process of verifying the reliability of the system, the compliance officer realizes that the system cannot reliably predict illnesses for certain segments of the population.

Which of the following types of risk is most applicable to this case?

Options:

A.

Bias

B.

Consistency

C.

Transparency

D.

Inclusiveness

Buy Now
Questions 27

An organization implements a domain-specific AI chatbot. After operating normally for weeks, the model returns contextually incorrect responses — treating ' worm ' as a biological pest rather than a computer worm when answering a cybersecurity question.

Which of the following should the organization do to address the issue?

Options:

A.

Configure guardrails.

B.

Encrypt the weights at rest.

C.

Apply model access controls.

D.

Deploy prompt templates.

Buy Now
Questions 28

A security operations center (SOC) analyst needs to automate multiple security tasks by breaking them down into smaller parts.

Which of the following AI tools is the best for this task?

Options:

A.

Agentic AI

B.

Retrieval-augmented generation (RAG) AI

C.

Generative AI

D.

Chatbot

Buy Now
Questions 29

Which of the following is the most impactful security risk associated with the use of a generative AI chatbot?

Options:

A.

Overly permissive access

B.

Data leakage

C.

Weak encryption

D.

Model validation

Buy Now
Questions 30

Which of the following technologies is used in deepfake?

Options:

A.

Generative adversarial network (GAN)

B.

Multi-shot prompting

C.

Prompt engineering

D.

Transfer learning

Buy Now
Questions 31

An engineer is analyzing findings from a penetration test that indicate insufficient data encryption. The report also indicates that additional controls must be placed on the data. To protect against loss of intellectual property, the engineer must implement data security.

Part 1: Use drop-down menu to select the most appropriate protocol or cipher for each system component.

Part 2: Use the drop-down menu to select the most appropriate technique to apply to the modified data.

CY0-001 Question 31

Options:

Buy Now
Questions 32

A security analyst reviews a recently released chatbot ' s log and discovers that outputs sometimes include personally identifiable information (PII) from other chatbot users.

Which of the following corrective actions should the security analyst take first to resolve this issue?

Options:

A.

Take the chatbot offline and restore it from a backup.

B.

Disable memory from the chat history for all users.

C.

Ask all users to refrain from using PII with the chatbot.

D.

Require users to label the sensitivity of their requests.

Buy Now
Questions 33

An administrator, who works for a financial institution, is required to implement data security controls for data at rest within AI systems that involve data disclosure.

Which of the following is the most suitable control?

Options:

A.

Data lineage

B.

Rate limits

C.

Encryption

D.

Masking

Buy Now
Questions 34

Which of the following provides guidance on AI-specific compliance?

Options:

A.

Organisation for Economic Co-operation and Development (OECD)

B.

International Organization for Standardization (ISO) 27001

C.

Payment Card Industry Data Security Standard (PCI DSS)

D.

General Data Protection Regulation (GDPR)

Buy Now
Questions 35

Which of the following describe the practice of providing examples in a prompt? (Choose two.)

Options:

A.

User prompt

B.

System prompt

C.

Prompt template

D.

Quantization

E.

One-shot

F.

Multi-shot

Buy Now
Questions 36

During a model validation procedure, an engineer notices that a model performs well during training but poorly during testing.

Which of the following best describes the reason?

Options:

A.

Fine-tuning

B.

Overfitting

C.

Regularization

D.

Inference

Buy Now
Questions 37

A financial organization implements a new AI-based fraud detection system to flag suspicious transactions. A security analyst discovers that it occasionally blocks legitimate transactions.

Which of the following is the best recommendation?

Options:

A.

Retraining the model with more data and recent transaction patterns

B.

Implementing AI token usage and rate limits

C.

Encrypting all the data processed by AI and applying further access controls

D.

Rolling back the model and using a traditional fraud detection system

Buy Now
Questions 38

A customer-facing, AI-powered chatbot has been jailbroken through prompt injections. As a result, the AI model is offering a 99% discount on the purchase of a new vehicle.

Which of the following should be implemented to enhance the model ' s robustness against such attacks?

Options:

A.

Bias filtering

B.

System prompt

C.

Log monitoring

D.

Guardrails

Buy Now
Questions 39

An AI security administrator receives an inquiry about an unusually high monthly bill from the AI solution provider. The administrator thinks the majority of staff might be using the most powerful model available.

Which of the following AI measures should the administrator implement to lower costs?

Options:

A.

Storage monitoring

B.

Modality types

C.

Prompt firewalls

D.

Token limits

Buy Now
Questions 40

A security analyst receives an alert about an AI system and is investigating the following output:

CY0-001 Question 40

Which of the following is the most appropriate control the analyst should recommend?

Options:

A.

Integrating data sanitization

B.

Implementing user input validation

C.

Monitoring logs for attack words from the system

D.

Hardening the Model Context Protocol server

Buy Now
Exam Code: CY0-001
Exam Name: CompTIA SecAI+ v1 Exam
Last Update: Aug 27, 2026
Questions: 134

PDF + Testing Engine

$55.71   $185.69

Testing Engine

$42.85   $142.83

PDF (Q&A)

$47.13   $157.11