Summer Sale Special - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmaspas7

Easiest Solution 2 Pass Your Certification Exams

CY0-001 CompTIA SecAI+ v1 Exam Free Practice Exam Questions (2026 Updated)

Prepare effectively for your CompTIA CY0-001 CompTIA SecAI+ v1 Exam certification with our extensive collection of free, high-quality practice questions. Each question is designed to mirror the actual exam format and objectives, complete with comprehensive answers and detailed explanations. Our materials are regularly updated for 2026, ensuring you have the most current resources to build confidence and succeed on your first attempt.

Page: 1 / 2
Total 126 questions

An organization recently created a custom model that integrates with a language model (LLM). The developer notices that the application programming interface (API) costs have increased.

Which of the following is the best control to reduce cost?

A.

Implementing prompt templates

B.

Increasing central processing unit (CPU) and memory

C.

Reducing the model size

D.

Adjusting token limits

An internal user enters a client credit card number into an internal generative machine learning (ML) model:

#User prompt: Customer Jane Doe has a new credit card that she wants to add to her account. The number is 5555-5555-5555-5555

Which of the following is the most effective way to prevent prompt injection attacks against a large language model (LLM)?

A.

Guardrails

B.

Antivirus

C.

Web application firewall (WAF)

D.

Role-based access control

A security operations center (SOC) analyst needs to automate multiple security tasks by breaking them down into smaller parts.

Which of the following AI tools is the best for this task?

A.

Agentic AI

B.

Retrieval-augmented generation (RAG) AI

C.

Generative AI

D.

Chatbot

A detection engineering team wants to use AI to automatically prevent vulnerable code from reaching production.

Which of the following is the most effective way to accomplish this task?

A.

Deploying an integrated development environment (IDE) plug-in that will warn developers of dangerous code before compiling

B.

Using a security orchestration, automation, and response (SOAR) with a machine learning (ML) model to classify code

C.

Implementing a large language model (LLM) in the continuous integration and continuous deployment (CI/CD) runner to examine code and pass or fail build jobs

D.

Developing an agentic penetration testing tool to validate potential vulnerable code

An employee wants a consulting company to procure a data set that contains age, ethnicity, and diabetes status. During development, the employer wants to ensure the integrity of the data.

Which of the following is the best strategy to accomplish this task?

A.

Implementing checksums

B.

Conducting human evaluation

C.

Querying the model

D.

Enabling log monitoring

Which of the following is most resistant to AI manipulation?

A.

Payloads

B.

AI-generated content

C.

Application programming interface (API) gateway

D.

Attack surface reduction

E.

Antivirus

A cybersecurity administrator needs a security mechanism that can validate input.

Which of the following controls should the administrator use?

A.

Prompt firewall

B.

Rate limits

C.

Token limits

D.

Input quantity

Which of the following responsible AI standards refers to a principle that clearly states the reasons behind the decisions for a particular conclusion?

A.

Accountability

B.

Auditability

C.

Transparency

D.

Explainability

A management team is concerned about an unexpected cost increase for a public-facing AI chatbot.

Which of the following should a security administrator examine first to determine the root cause?

A.

Firewall logs

B.

Web application firewall (WAF) rules

C.

Vector database input/output operations per second performance

D.

Model token usage

A large number of employees receive a video message in which the company ' s CEO states that the company will be filing for bankruptcy. After an investigation, it was discovered that the CEO did not send this message.

Which of the following is this scenario an example of?

A.

On-path attack

B.

Phishing

C.

Deepfake

D.

Social engineering

A cybersecurity administrator generates patching reports using AI, but the process takes a long time. Which of the following is the best way to increase performance?

A.

Deploy a Model Context Protocol (MCP) server to delegate several versions of this query to the back-end LLM simultaneously.

B.

Have the AI download the full CVE database first to prevent multiple similar external queries.

C.

Configure the AI system prompt to specify summarization algorithms.

D.

Increase the amount of model tokens available to eliminate time-consuming session restarts.

A human resources officer is using AI to evaluate resumes and help select candidates that meet minimum criteria. To improve the results, the human resources officer adjusts the query parameters and includes an example resume that matches a successful candidate.

Which of the following best describes this query?

A.

Distillation

B.

Prompt template

C.

One-shot prompting

D.

System role

A security analyst notices that regardless of user-submitted prompts, an AI model always returns unsanitized responses. These responses are then passed to multiple plug-ins. The analyst is concerned with the potential security implications.

Which of the following Open Worldwide Application Security Project (OWASP) categories addresses this vulnerability?

A.

Misinformation

B.

Prompt injection

C.

Unbounded consumption

D.

Improper output handling

A user interface engineer adds new graphics to the latest release of an AI-integrated application. During the update, the engineer accidentally causes the model to retrain on unverified data. After the update, the model begins to return many errors.

Which of the following is the best way to mitigate future errors?

A.

Web application firewall

B.

Role-based access control

C.

Model development life cycle

D.

Generative adversarial network

A SOC team has an AI agent that performs web searches and calls to the SOAR solution. The team is concerned about enterprise uptime and case resolution time.

Which of the following is the most appropriate use of the AI agent?

A.

To analyze and contain offending users or hosts using SOAR playbooks

B.

To perform research using open-source intelligence to enrich the alerts

C.

To aggregate SOC metrics and generate reports for the leadership team

D.

To create tabletop exercises so the team can increase its incident response speed

Which of the following job roles in an organizational governance structure develops a model from business use cases?

A.

Platform architect

B.

AI risk analyst

C.

Machine learning operations (MLOps) engineer

D.

Data scientist

An automobile manufacturer implements a chatbot to assist with configuration options for customer automobiles. Given a customer ' s prompt, the chatbot gives offensive responses.

Which of the following describes this behavior?

A.

Model skewing

B.

Model theft

C.

Jailbreaking

D.

Insecure output handling

A security analyst is aware of an active penetration test in the environment. The analyst examines SIEM log data and notices the following AI system output:

Which of the following is the vulnerability that has occurred and the control the analyst should implement?

A.

The vulnerability is prompt injection, and the analyst should use endpoint detection response (EDR).

B.

The vulnerability is model hallucinations, and the analyst should develop output validations.

C.

The vulnerability is jailbreaking, and the analyst should utilize role-based access control.

D.

The vulnerability is sensitive information disclosure, and the analyst should employ masking.

E.

The vulnerability is role impersonation, and the analyst should use validation.

A team of engineers builds an application using a large language model (LLM). The application is built on Linux and is hosted on a virtual server. Users must create an account in order to access and use the platform.

Which of the following should the team do to protect the account credentials?

A.

Patch the model with the latest data set.

B.

Update the Linux and virtual servers.

C.

Implement hashing and encryption.

D.

Deploy an authenticated application programming interface (API).

A multinational company wants to implement an AI-assisted job screening solution.

Which of the following should the company reference to reduce the risk of incurring compliance-related fines?

A.

International Organization for Standardization (ISO) AI standards

B.

European Union (EU) AI Act

C.

Corporate policy

D.

National Institute of Standards and Technology (NIST) AI Risk Management Framework (RMF)

Page: 1 / 2
Total 126 questions
Copyright © 2014-2026 Solution2Pass. All Rights Reserved