CY0-001 CompTIA SecAI+ v1 Exam Free Practice Exam Questions (2026 Updated)
Prepare effectively for your CompTIA CY0-001 CompTIA SecAI+ v1 Exam certification with our extensive collection of free, high-quality practice questions. Each question is designed to mirror the actual exam format and objectives, complete with comprehensive answers and detailed explanations. Our materials are regularly updated for 2026, ensuring you have the most current resources to build confidence and succeed on your first attempt.
A cybersecurity engineer implements a large language model (LLM) tool to automate an incident management workflow. However, the output contains items that do not exist in the real world. Which of the following is a technique to address this issue?
A global security operations center (SOC) wants to adapt and leverage the strength of AI in order to enhance its security operations.
Which of the following is the best way to enhance the global SOC functions?
A security administrator wants to prevent prompt injection attacks and ensure responses have sanitized output.
Which of the following provides a primary compensating control for these requirements?
A security team is using an AI-based tool to try to bypass organizational boundaries. The team uses AI to look at the current state and suggest different attack vectors based on the outcome of the previous ones.
Which of the following techniques is the team most likely using?
Which of the following describes the process of adjusting the distribution of underrepresented classes in an AI model data set to improve model performance?
An AI security administrator notices that the information referenced by the model is incorrectly formatted and missing values.
Which of the following job roles would most likely be responsible for correcting this error?
A loan company compares a machine learning model that was found on the dark web with the company ' s proprietary model. Using proprietary information, the company generates the following:
Input
Dark web model
Company ' s proprietary model
Jane A.
Approve
Approve
John B.
Deny
Deny
Ann J.
Deny
Deny
Joe H.
Approve
Approve
Which of the following should the AI red team recommend to mitigate risks for future deployments?
Users report that the output of a generative AI application seems unrelated to the prompts and contains offensive content. A security team investigates and determines that there was an on-path attack.
Which of the following is the most likely attack method?
Which of the following provides guidance on AI-specific compliance?
A security administrator needs to improve an AI model. During an initial investigation, the administrator notices that two successive login failures are recorded every day, and then a successful login occurs after a specific time interval. All the successful login attempts have been during office hours.
Which of the following techniques should the administrator use to improve the AI model ' s security?
A security consultant must summarize the impact of posture management on a machine learning (ML) use case.
Which of the following is the most appropriate reference for this purpose?
An airline corporation wants to implement a chatbot application using a large language model (LLM) so its customers can ask questions and receive answers about flight details and have the option to upload files.
Which of the following security controls should the airline use to protect against malicious input and unauthorized use beyond the service-level agreement? (Choose two.)
After the deployment of an AI system, an organization is unable to identify who approved the system and the method of validation. Which of the following governance failures occurred?
Which of the following requires developers to harden infrastructure to protect AI systems?
Before submitting code to the upstream code repository, a security administrator wants to implement the following:
• Comments describing the inputs, outputs, and purpose of code blocks
• Recommendations for code security
Which of the following should the administrator implement to address both requirements?
Which of the following is the primary security risk when deploying AI models in production?
A security architect performs threat modeling of an AI system. The architect needs to determine which attacks can be performed against the system.
Which of the following actions should the architect take next?
A company is adopting AI and wants to create policies and procedures that include a structure for evaluating, publishing, and approving patterns for AI usage.
Which of the following should the company establish to meet this goal?
During a model validation procedure, an engineer notices that a model performs well during training but poorly during testing.
Which of the following best describes the reason?
A financial services company is being sued for using AI in the loan underwriting process. The lawsuit reveals that the AI model used biased sources to disproportionately deny loans to residents in certain postal codes. Which of the following employees is the most qualified to remove these biased sources from the model?