Spring Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

CY0-001 CompTIA SecAI+ v1 Exam Questions and Answers

Questions 4

A security analyst receives an alert about an AI system and is investigating the following output:

CY0-001 Question 4

Which of the following is the most appropriate control the analyst should recommend?

Options:

A.

Integrating data sanitization

B.

Implementing user input validation

C.

Monitoring logs for attack words from the system

D.

Hardening the Model Context Protocol server

Buy Now
Questions 5

A company deploys an internet-facing chatbot using RAG. Logs show that an administrator can retrieve employee names and usernames while an employee receives ' information not available. ' Which of the following is reducing the risk of sensitive data exposure in this scenario?

Options:

A.

Data access controls

B.

Model-specific guardrails

C.

Rate limiting

D.

Prompt templates

Buy Now
Questions 6

An organization recently developed an AI-powered product and discovers that it is vulnerable to attacks in which malicious actors can alter the input, causing the system to recommend inappropriate information.

Which of the following techniques is the most effective way to secure the system against manipulation attacks?

Options:

A.

Cross-validation

B.

Feature regularization

C.

Feature scaling

D.

Guardrails

Buy Now
Questions 7

An administrator must conduct generative AI cost monitoring for use in the healthcare industry.

Which of the following criteria is the best way to calculate this cost?

Options:

A.

Connection access and exchange gateway

B.

Encryption and decryption processing

C.

Storage retrieval and prompt processing

D.

Catalog servicing and exchange processing

Buy Now
Questions 8

Instructions: Use the drop-down menus to define two appropriate security controls for each component of the AI system. Each control may be used only once.

An engineer is deploying a new AI system and wants to integrate it into the core system through an API.

CY0-001 Question 8

Options:

Buy Now
Questions 9

A security analyst notices that regardless of user-submitted prompts, an AI model always returns unsanitized responses. These responses are then passed to multiple plug-ins. The analyst is concerned with the potential security implications.

Which of the following Open Worldwide Application Security Project (OWASP) categories addresses this vulnerability?

Options:

A.

Misinformation

B.

Prompt injection

C.

Unbounded consumption

D.

Improper output handling

Buy Now
Questions 10

Which of the following provides guidance on AI-specific compliance?

Options:

A.

Organisation for Economic Co-operation and Development (OECD)

B.

International Organization for Standardization (ISO) 27001

C.

Payment Card Industry Data Security Standard (PCI DSS)

D.

General Data Protection Regulation (GDPR)

Buy Now
Questions 11

An IT company implements an adaptable chatbot that learns from user prompts. Based on the conversation shown — where User 2 injected false information about a company acquisition that caused the chatbot to give incorrect responses to User 3 — which of the following compensating controls should an administrator implement to mitigate the issue?

Options:

A.

Data encryption

B.

Rate-limiting application programming interfaces (APIs)

C.

Transfer learning

D.

Guardrails

Buy Now
Questions 12

Which of the following is an example of how a security analyst uses generative AI in the triage process?

Options:

A.

To predict the next attack target with higher accuracy

B.

To use statistical analysis for malicious code assessment

C.

To summarize security findings by category

D.

To tag malware using machine learning (ML) algorithms

Buy Now
Questions 13

As a compliance requirement, a large language model (LLM) application requires setting up guardrails.

Which of the following resources is most appropriate to use?

Options:

A.

Retrieval-augmented generation (RAG)

B.

Open Worldwide Application Security Project (OWASP)

C.

LLM libraries

D.

Security incident and event management (SIEM)

Buy Now
Questions 14

A healthcare organization plans to deploy a chatbot for appointment scheduling and patient records.

Which of the following is the first step a security administrator should take?

Options:

A.

Implement prompt firewalls.

B.

Enable role-based access management

C.

Conduct a risk assessment.

D.

Use a secure data communication channel for chat.

Buy Now
Questions 15

A company uses human review for software development validation and wants to add another validation layer.

Which of the following should a security administrator use to accomplish this task?

Options:

A.

AI-assisted approval

B.

Low-code plug-in

C.

Automated rollback

D.

Regression testing

Buy Now
Questions 16

Which of the following is the most concerning risk for a company that allows corporate end users to use public-facing large language models (LLMs)?

Options:

A.

Inaccuracies due to hallucinations

B.

Out-of-date acceptable use policies

C.

Data security regulatory violations

D.

Malicious code generation

Buy Now
Questions 17

A management team is concerned about an unexpected cost increase for a public-facing AI chatbot.

Which of the following should a security administrator examine first to determine the root cause?

Options:

A.

Firewall logs

B.

Web application firewall (WAF) rules

C.

Vector database input/output operations per second performance

D.

Model token usage

Buy Now
Questions 18

A customer-facing, AI-powered chatbot has been jailbroken through prompt injections. As a result, the AI model is offering a 99% discount on the purchase of a new vehicle.

Which of the following should be implemented to enhance the model ' s robustness against such attacks?

Options:

A.

Bias filtering

B.

System prompt

C.

Log monitoring

D.

Guardrails

Buy Now
Questions 19

An organization is concerned with the exposure of sensitive data.

Which of the following is the most relevant security concern?

Options:

A.

Overfitting

B.

Model inversion

C.

Data normalization

D.

Hyperparameter tuning

Buy Now
Questions 20

Which of the following describes the number of training cycles used in an AI model for threat detection?

Options:

A.

k-means clustering

B.

Tokens

C.

Temperature

D.

Epoch

Buy Now
Questions 21

A security alert triggers an agentic system. An analyst notices the following payload in the logs. The alert includes multiple shell commands that are not typically run as part of any hardening:

CY0-001 Question 21

Which of the following is the most effective control to implement?

Options:

A.

Adding logic that includes approved strings before running the shell commands

B.

Deprecating model usage and retaining the model with safer parameters

C.

Modifying the application to ignore the SECURITY_UPDATE tag

D.

Using only approved libraries when interacting with agentic systems

Buy Now
Questions 22

An employee wants a consulting company to procure a data set that contains age, ethnicity, and diabetes status. During development, the employer wants to ensure the integrity of the data.

Which of the following is the best strategy to accomplish this task?

Options:

A.

Implementing checksums

B.

Conducting human evaluation

C.

Querying the model

D.

Enabling log monitoring

Buy Now
Questions 23

An architect is using the firm ' s recommended large language model (LLM) to find an internal solution for content management.

Given the following:

CY0-001 Question 23

Which of the following controls is the best for mitigating this issue?

Options:

A.

Model training

B.

Response validation

C.

Access controls

D.

Integrity monitoring

Buy Now
Questions 24

A social media company with more than a million lines of code wants to reduce the mean time to fix bugs and issues.

Which of the following is the most balanced AI strategy to automate the vulnerability management flow?

Options:

A.

Using AI to triage discovered issues and create tickets, but having a software engineer merge software

B.

Having security analysts triage discovered issues and create tickets, but using AI to merge software

C.

Having security analysts triage discovered issues and create tickets, but having a software engineer merge software

D.

Using AI to triage discovered issues, create tickets, and merge software fixes

Buy Now
Questions 25

A security analyst needs to conduct a security assessment of the output from an AI-enabled development tool.

Which of the following should the analyst do first?

Options:

A.

Remove hard-coded secrets from the source code.

B.

Enforce strict access controls for code repositories.

C.

Enable sensitive data discovery on code repositories.

D.

Perform a source code review.

Buy Now
Questions 26

A security consultant needs to detect attacks across a large language model (LLM) firewall.

Which of the following techniques should the consultant use?

Options:

A.

Signature matching

B.

Distributed denial-of-service

C.

Translation analysis

D.

Vulnerability enumeration

Buy Now
Questions 27

Which of the following is most resistant to AI manipulation?

Options:

A.

Payloads

B.

AI-generated content

C.

Application programming interface (API) gateway

D.

Attack surface reduction

E.

Antivirus

Buy Now
Questions 28

Which of the following is a risk addressed by responsible AI?

Options:

A.

Model drift

B.

Reputational loss

C.

Response bias

D.

Data poisoning

Buy Now
Questions 29

User experience is declining since the launch of a large language model (LLM) in internal networks.

Which of the following should be the highest priority for the prompt engineers?

Options:

A.

Customer success management

B.

Sales life cycle

C.

Quality control

D.

Business objectives

Buy Now
Questions 30

Which of the following controls is the best way to mitigate a denial-of-service (DoS) attack?

Options:

A.

Model guardrails

B.

Rate limiting

C.

End-to-end encryption

D.

Access controls

Buy Now
Questions 31

A cybersecurity administrator must examine the cost of AI and implement controls so the research environment operates within a specified budget.

Which of the following controls is best for this situation?

Options:

A.

Prompt firewalls

B.

Application programming interface (API) access

C.

Model guardrails

D.

Token limits

Buy Now
Questions 32

A penetration tester is assessing the controls of a deployed AI system that is designed to search and return the contents of files.

The tester runs the following:

CY0-001 Question 32

Which of the following is the best control to prevent abuse of the system?

Options:

A.

Implementing custom detection rules for anomalous model behavior

B.

Segmenting the workload into a separate virtual private cloud (VPC)

C.

Adding a large language model (LLM) guardrails library to the application code

D.

Reducing the privilege scope of the service account

Buy Now
Questions 33

Which of the following technologies is used in deepfake?

Options:

A.

Generative adversarial network (GAN)

B.

Multi-shot prompting

C.

Prompt engineering

D.

Transfer learning

Buy Now
Questions 34

A data scientist is working with unlabeled data and wants to build a clustering model.

Which of the following techniques should a data scientist use?

Options:

A.

Supervised learning

B.

Reinforcement learning

C.

Unsupervised learning

D.

Semi-supervised learning

Buy Now
Questions 35

A data scientist investigates reports that a production machine learning (ML) model no longer performs with accuracy.

The data scientist finds the following pipeline log entries:

CY0-001 Question 35

Which of the following should the security team do to mitigate future occurrences?

Options:

A.

Add static code scanning tooling to the runner job.

B.

Enable human review and approval workflows in the repository.

C.

Retrain the model on using increased data and epochs.

D.

Keep multiple copies of the model for restoration.

Buy Now
Questions 36

Part 1: Use drop-down menu to select the most appropriate protocol or cipher for each system component.

Part 2: Use the drop-down menu to select the most appropriate technique to apply to the modified data.

An engineer is analyzing findings from a penetration test that indicate insufficient data encryption. The engineer must implement data security.

CY0-001 Question 36

Options:

Buy Now
Questions 37

An airline corporation wants to implement a chatbot application using a large language model (LLM) so its customers can ask questions and receive answers about flight details and have the option to upload files.

Which of the following security controls should the airline use to protect against malicious input and unauthorized use beyond the service-level agreement? (Choose two.)

Options:

A.

Prompt guardrails

B.

Role-based access controls

C.

Firewall rules

D.

Model token quotas

Buy Now
Exam Code: CY0-001
Exam Name: CompTIA SecAI+ v1 Exam
Last Update: May 31, 2026
Questions: 126

PDF + Testing Engine

$64.99   $185.69

Testing Engine

$49.99   $142.83

PDF (Q&A)

$54.99   $157.11