Pre-Summer Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: clap70

CY0-001 CompTIA SecAI+ Certification Exam Questions and Answers

Questions 4

A cybersecurity analyst wants to choose a machine learning (ML) model to classify log entries while providing the best explainability.

Which of the following models should the analyst use?

Options:

A.

Large language model (LLM)

B.

Neural networks

C.

Decision trees

D.

Generative adversarial network (GAN)

Buy Now
Questions 5

An architect is using the firm ' s recommended large language model (LLM) to find an internal solution for content management.

Given the following:

Which of the following controls is the best for mitigating this issue?

Options:

A.

Model training

B.

Response validation

C.

Access controls

D.

Integrity monitoring

Buy Now
Questions 6

A security analyst notices that regardless of user-submitted prompts, an AI model always returns unsanitized responses. These responses are then passed to multiple plug-ins. The analyst is concerned with the potential security implications.

Which of the following Open Worldwide Application Security Project (OWASP) categories addresses this vulnerability?

Options:

A.

Misinformation

B.

Prompt injection

C.

Unbounded consumption

D.

Improper output handling

Buy Now
Questions 7

A security administrator sees suspicious queries on AI logs.

Which of the following should the administrator implement to address this issue?

Options:

A.

Prompt firewalls

B.

Data size

C.

Rate limit

D.

Agentic AI

Buy Now
Questions 8

Which of the following responsible AI standards refers to a principle that clearly states the reasons behind the decisions for a particular conclusion?

Options:

A.

Accountability

B.

Auditability

C.

Transparency

D.

Explainability

Buy Now
Questions 9

As a compliance requirement, a large language model (LLM) application requires setting up guardrails.

Which of the following resources is most appropriate to use?

Options:

A.

Retrieval-augmented generation (RAG)

B.

Open Worldwide Application Security Project (OWASP)

C.

LLM libraries

D.

Security incident and event management (SIEM)

Buy Now
Questions 10

An airline corporation wants to implement a chatbot application using a large language model (LLM) so its customers can ask questions and receive answers about flight details and have the option to upload files.

Which of the following security controls should the airline use to protect against malicious input and unauthorized use beyond the service-level agreement? (Choose two.)

Options:

A.

Prompt guardrails

B.

Role-based access controls

C.

Firewall rules

D.

Model token quotas

Buy Now
Questions 11

A short AI-generated video shows a celebrity ' s likeness talking about a fake public security event.

Which of the following was used to create this video?

Options:

A.

Statistical analysis

B.

Convolutional neural network

C.

Machine learning (ML) classifier

D.

Random forest

Buy Now
Questions 12

A human resources officer is using AI to evaluate resumes and help select candidates that meet minimum criteria. To improve the results, the human resources officer adjusts the query parameters and includes an example resume that matches a successful candidate.

Which of the following best describes this query?

Options:

A.

Distillation

B.

Prompt template

C.

One-shot prompting

D.

System role

Buy Now
Questions 13

Which of the following controls is the best way to mitigate a denial-of-service (DoS) attack?

Options:

A.

Model guardrails

B.

Rate limiting

C.

End-to-end encryption

D.

Access controls

Buy Now
Questions 14

A security operations center (SOC) analyst needs to automate multiple security tasks by breaking them down into smaller parts.

Which of the following AI tools is the best for this task?

Options:

A.

Agentic AI

B.

Retrieval-augmented generation (RAG) AI

C.

Generative AI

D.

Chatbot

Buy Now
Questions 15

Which of the following helps end users within an organization the most in safeguarding against the risk of AI-related non-compliance?

Options:

A.

AI center of excellence

B.

Policies and procedures

C.

Implementing data loss prevention

D.

Enabling multifactor authentication (MFA) for access

Buy Now
Questions 16

A security consultant needs to detect attacks across a large language model (LLM) firewall.

Which of the following techniques should the consultant use?

Options:

A.

Signature matching

B.

Distributed denial-of-service

C.

Translation analysis

D.

Vulnerability enumeration

Buy Now
Questions 17

Which of the following provides guidance on AI-specific compliance?

Options:

A.

Organisation for Economic Co-operation and Development (OECD)

B.

International Organization for Standardization (ISO) 27001

C.

Payment Card Industry Data Security Standard (PCI DSS)

D.

General Data Protection Regulation (GDPR)

Buy Now
Questions 18

A company introduces a large language model (LLM) in an application in order to monitor for a potential denial-of-service attack.

Which of the following should the company use to measure the utilization of the LLM?

Options:

A.

Token

B.

Transformer

C.

Chain of thoughts

D.

Prompt

Buy Now
Questions 19

User experience is declining since the launch of a large language model (LLM) in internal networks.

Which of the following should be the highest priority for the prompt engineers?

Options:

A.

Customer success management

B.

Sales life cycle

C.

Quality control

D.

Business objectives

Buy Now
Questions 20

Instructions: Use the drop-down menus to define two appropriate security controls for each component of the AI system. Each control may be used only once.

An engineer is deploying a new AI system and wants to integrate it into the core system through an API.

Options:

Buy Now
Questions 21

An administrator must conduct generative AI cost monitoring for use in the healthcare industry.

Which of the following criteria is the best way to calculate this cost?

Options:

A.

Connection access and exchange gateway

B.

Encryption and decryption processing

C.

Storage retrieval and prompt processing

D.

Catalog servicing and exchange processing

Buy Now
Questions 22

A social media company with more than a million lines of code wants to reduce the mean time to fix bugs and issues.

Which of the following is the most balanced AI strategy to automate the vulnerability management flow?

Options:

A.

Using AI to triage discovered issues and create tickets, but having a software engineer merge software

B.

Having security analysts triage discovered issues and create tickets, but using AI to merge software

C.

Having security analysts triage discovered issues and create tickets, but having a software engineer merge software

D.

Using AI to triage discovered issues, create tickets, and merge software fixes

Buy Now
Questions 23

A security analyst receives an alert about an AI system and is investigating the following output:

Which of the following is the most appropriate control the analyst should recommend?

Options:

A.

Integrating data sanitization

B.

Implementing user input validation

C.

Monitoring logs for attack words from the system

D.

Hardening the Model Context Protocol server

Buy Now
Questions 24

Which of the following technologies is used in deepfake?

Options:

A.

Generative adversarial network (GAN)

B.

Multi-shot prompting

C.

Prompt engineering

D.

Transfer learning

Buy Now
Questions 25

An administrator, who works for a financial institution, is required to implement data security controls for data at rest within AI systems that involve data disclosure.

Which of the following is the most suitable control?

Options:

A.

Data lineage

B.

Rate limits

C.

Encryption

D.

Masking

Buy Now
Questions 26

Which of the following attacks would be the best to automate with AI during dynamic application software testing (DAST)?

Options:

A.

Distributed denial-of-service (DDoS)

B.

Data poisoning

C.

Payload creation

D.

Threat modeling

Buy Now
Questions 27

A security analyst finds that the AI system is under a denial-of-wallet attack.

Which of the following should the analyst enforce to protect the company? (Choose two.)

Options:

A.

Endpoint access controls

B.

Content delivery network (CDN)

C.

Model fine-tuning

D.

Modality controls

E.

Application programming interface (API) rate controls

F.

Output token controls

Buy Now
Questions 28

A multinational company wants to implement an AI-assisted job screening solution.

Which of the following should the company reference to reduce the risk of incurring compliance-related fines?

Options:

A.

International Organization for Standardization (ISO) AI standards

B.

European Union (EU) AI Act

C.

Corporate policy

D.

National Institute of Standards and Technology (NIST) AI Risk Management Framework (RMF)

Buy Now
Questions 29

A security architect performs threat modeling of an AI system. The architect needs to determine which attacks can be performed against the system.

Which of the following actions should the architect take next?

Options:

A.

Leverage a large language model (LLM) to map likely attack paths based on the code base.

B.

Quantify the risk of known vulnerabilities identified in the AI system.

C.

Identify trust boundaries and perform threat modeling with Open Worldwide Application Security Project (OWASP) Top 10.

D.

Analyze MITRE Adversarial Threat Landscape for AI Systems (ATLAS) for tactics, techniques, and procedures (TTPs).

Buy Now
Questions 30

Which of the following is the primary purpose of validating data for an AI system?

Options:

A.

To automate the process

B.

To reduce consumption of resources

C.

To optimize the storage databases

D.

To ensure bias-free outcomes

Buy Now
Questions 31

Which of the following should an auditor reference when reviewing a company ' s human resources AI systems for legal non-compliance?

Options:

A.

Organization for Economic Cooperation and Development (OECD) standard

B.

National Institute of Standards and Technology (NIST) AI Risk Management Framework (RMF)

C.

European Union (EU) AI Act

D.

International Organization for Standardization (ISO)

Buy Now
Questions 32

Which of the following strengthens the performance of a large language model (LLM) for malicious reconnaissance?

Options:

A.

Enhancing a foundational model with the inclusion of retrieval-augmented generation (RAG)

B.

Creating a web scraper script using AI to capture the company website

C.

Instructing an AI assistant to query as an administrator

D.

Prompting a chatbot to describe server naming patterns and Internet Protocol (IP) ranges

Buy Now
Questions 33

A data scientist is working with unlabeled data and wants to build a clustering model.

Which of the following techniques should a data scientist use?

Options:

A.

Supervised learning

B.

Reinforcement learning

C.

Unsupervised learning

D.

Semi-supervised learning

Buy Now
Questions 34

A company uses human review for software development validation and wants to add another validation layer.

Which of the following should a security administrator use to accomplish this task?

Options:

A.

AI-assisted approval

B.

Low-code plug-in

C.

Automated rollback

D.

Regression testing

Buy Now
Questions 35

A manufacturing company wants to use AI within its operations to improve the efficiency and accuracy of its processes.

Which of the following should the organization do first to enable adoption and achieve the business objectives?

Options:

A.

Achieve International Organization for Standardization (ISO) 42001 certification.

B.

Hire a data and AI architect.

C.

Select a large language model (LLM).

D.

Introduce a generative adversarial network (GAN).

Buy Now
Questions 36

A security team is using an AI-based tool to try to bypass organizational boundaries. The team uses AI to look at the current state and suggest different attack vectors based on the outcome of the previous ones.

Which of the following techniques is the team most likely using?

Options:

A.

Manual signature matching

B.

Code quality testing

C.

Fraud detection

D.

Automated penetration testing

Buy Now
Questions 37

A security analyst needs to conduct a security assessment of the output from an AI-enabled development tool.

Which of the following should the analyst do first?

Options:

A.

Remove hard-coded secrets from the source code.

B.

Enforce strict access controls for code repositories.

C.

Enable sensitive data discovery on code repositories.

D.

Perform a source code review.

Buy Now
Exam Code: CY0-001
Exam Name: CompTIA SecAI+ Certification Exam
Last Update: May 29, 2026
Questions: 0
CY0-001 pdf

CY0-001 PDF

$25.5  $84.99
CY0-001 Engine

CY0-001 Testing Engine

$30  $99.99
CY0-001 PDF + Engine

CY0-001 PDF + Testing Engine

$180  $600