Pre-Winter Sale Special - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmaspas7

Easiest Solution 2 Pass Your Certification Exams

CY0-001 CompTIA SecAI+ v1 Exam Free Practice Exam Questions (2026 Updated)

Prepare effectively for your CompTIA CY0-001 CompTIA SecAI+ v1 Exam certification with our extensive collection of free, high-quality practice questions. Each question is designed to mirror the actual exam format and objectives, complete with comprehensive answers and detailed explanations. Our materials are regularly updated for 2026, ensuring you have the most current resources to build confidence and succeed on your first attempt.

Page: 2 / 3
Total 159 questions

Which of the following should an auditor reference when reviewing a company ' s human resources AI systems for legal non-compliance?

A.

Organization for Economic Cooperation and Development (OECD) standard

B.

National Institute of Standards and Technology (NIST) AI Risk Management Framework (RMF)

C.

European Union (EU) AI Act

D.

International Organization for Standardization (ISO)

A customer-facing, AI-powered chatbot has been jailbroken through prompt injections. As a result, the AI model is offering a 99% discount on the purchase of a new vehicle.

Which of the following should be implemented to enhance the model ' s robustness against such attacks?

A.

Bias filtering

B.

System prompt

C.

Log monitoring

D.

Guardrails

A data scientist asks about controls for public vs. private models used for training. A security agent responds by listing several factors to evaluate when making that determination. Which of the following is the most critical control?

A.

Model security

B.

Applicability

C.

Responsible AI

D.

Regulations

Which of the following describes the number of training cycles used in an AI model for threat detection?

A.

k-means clustering

B.

Tokens

C.

Temperature

D.

Epoch

A cybersecurity analyst wants to choose a machine learning (ML) model to classify log entries while providing the best explainability.

Which of the following models should the analyst use?

A.

Large language model (LLM)

B.

Neural networks

C.

Decision trees

D.

Generative adversarial network (GAN)

An administrator must conduct generative AI cost monitoring for use in the healthcare industry.

Which of the following criteria is the best way to calculate this cost?

A.

Connection access and exchange gateway

B.

Encryption and decryption processing

C.

Storage retrieval and prompt processing

D.

Catalog servicing and exchange processing

A detection engineering team wants to use AI to automatically prevent vulnerable code from reaching production.

Which of the following is the most effective way to accomplish this task?

A.

Deploying an integrated development environment (IDE) plug-in that will warn developers of dangerous code before compiling

B.

Using a security orchestration, automation, and response (SOAR) with a machine learning (ML) model to classify code

C.

Implementing a large language model (LLM) in the continuous integration and continuous deployment (CI/CD) runner to examine code and pass or fail build jobs

D.

Developing an agentic penetration testing tool to validate potential vulnerable code

A security analyst notices that regardless of user-submitted prompts, an AI model always returns unsanitized responses. These responses are then passed to multiple plug-ins. The analyst is concerned with the potential security implications.

Which of the following Open Worldwide Application Security Project (OWASP) categories addresses this vulnerability?

A.

Misinformation

B.

Prompt injection

C.

Unbounded consumption

D.

Improper output handling

An organization develops a chatbot that does not provide harmful or explicit responses, must use clean and professional language, and ensures that responses are accurate.

Which of the following should the organization conduct after the chatbot is fully developed but before a customer-facing deployment?

A.

Data labeling and classification

B.

Model auditing and evaluation

C.

Guardrail testing and validation

D.

Regression modeling and minimization

Security analysts want to track potential user behavior anomalies over time. Which of the following is the most comprehensive approach?

A.

Using an AI-enabled scanner to compare user permissions to other users in the department

B.

Using an agentic large language model (LLM) to search for multiple instances of a username in logs

C.

Leveraging browser plug-ins that monitor for uncommon sites visited by a user

D.

Running automated playbooks that monitor standard deviations from a user baseline

Which of the following technologies is used in deepfake?

A.

Generative adversarial network (GAN)

B.

Multi-shot prompting

C.

Prompt engineering

D.

Transfer learning

A team of engineers builds an application using a large language model (LLM). The application is built on Linux and is hosted on a virtual server. Users must create an account in order to access and use the platform.

Which of the following should the team do to protect the account credentials?

A.

Patch the model with the latest data set.

B.

Update the Linux and virtual servers.

C.

Implement hashing and encryption.

D.

Deploy an authenticated application programming interface (API).

Which of the following explains the reason a cybersecurity analyst prefers a machine learning (ML) model over a statistical model for attack classification?

A.

The ability to learn complex problems and adapt to new information

B.

A simplified development pipeline and deployment process

C.

Improved performance with a small data set and high durability

D.

Large community support and availability of global experts

A disgruntled employee changed the company policies that a chatbot references in order to create confusion and disrupt the business.

Which of the following AI-generated vulnerabilities is the employee exploiting?

A.

Data reduction

B.

Data masking

C.

Data poisoning

D.

Data leaking

Customer feedback for an AI chatbot has a high-rate of non-answers, which is causing higher central processing unit (CPU) utilization.

Which of the following should be implemented?

A.

Guardrails

B.

Response confidence level

C.

Prompt logging

D.

Cost monitoring

A manufacturing company wants to use AI within its operations to improve the efficiency and accuracy of its processes.

Which of the following should the organization do first to enable adoption and achieve the business objectives?

A.

Achieve International Organization for Standardization (ISO) 42001 certification.

B.

Hire a data and AI architect.

C.

Select a large language model (LLM).

D.

Introduce a generative adversarial network (GAN).

A customer using a travel chatbot reports that the chatbot responds with the following:

def choose_location(location):

    if location == " United States of America " :

        print( " You have selected an authorized travel destination " )

    elif location == " Europe " :

        print( " You have selected an unauthorized travel destination " )

Which of the following remediates this issue?

A.

Deploying DLP to prevent sensitive information disclosure

B.

Retraining the model to eliminate bias

C.

Implementing secure output handling

D.

Using cookies to protect against server-side request forgery

A developer is selecting authentication controls for an AI system.

Which of the following is the best way to prevent threat actor replay attacks?

A.

Identity provider (IdP) federation

B.

Secure Shell (SSH)-based certificate authentication

C.

Expiring session tokens

D.

Identity and access management access keys

Which of the following describes the most significant risk associated with AI agents that make autonomous decisions?

A.

Increased workload

B.

Accidental data leakage

C.

Overfitting

D.

Output bias

An analyst wants to develop a solution to review security information and event management (SIEM) logs for endpoint analytics. Which of the following is a benefit of a small language model (SLM) compared to a large language model (LLM) when cost efficiency is a consideration?

A.

Data aggregation

B.

Broad data set training

C.

Domain-specific data

D.

Data privacy

Page: 2 / 3
Total 159 questions
Copyright © 2014-2026 Solution2Pass. All Rights Reserved