Pre-Winter Sale Special - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmaspas7

Easiest Solution 2 Pass Your Certification Exams

CY0-001 CompTIA SecAI+ v1 Exam Free Practice Exam Questions (2026 Updated)

Prepare effectively for your CompTIA CY0-001 CompTIA SecAI+ v1 Exam certification with our extensive collection of free, high-quality practice questions. Each question is designed to mirror the actual exam format and objectives, complete with comprehensive answers and detailed explanations. Our materials are regularly updated for 2026, ensuring you have the most current resources to build confidence and succeed on your first attempt.

Page: 1 / 3
Total 159 questions

A cybersecurity engineer implements a large language model (LLM) tool to automate an incident management workflow. However, the output contains items that do not exist in the real world. Which of the following is a technique to address this issue?

A.

Watermarking

B.

Output filtering

C.

Retrieval-augmented generation (RAG)

D.

Data rebalancing

A global security operations center (SOC) wants to adapt and leverage the strength of AI in order to enhance its security operations.

Which of the following is the best way to enhance the global SOC functions?

A.

Generate code and execute in production to help save time.

B.

Enable a personal assistant that can act in the global SOC with no human intervention.

C.

Use open-source models in production to help the efficiency of threat detection and threat analysis.

D.

Summarize alerts to easily gain insights on the environment.

A security administrator wants to prevent prompt injection attacks and ensure responses have sanitized output.

Which of the following provides a primary compensating control for these requirements?

A.

Least privilege

B.

Encryption

C.

A large language model (LLM) firewall

D.

Rate limiting

A security team is using an AI-based tool to try to bypass organizational boundaries. The team uses AI to look at the current state and suggest different attack vectors based on the outcome of the previous ones.

Which of the following techniques is the team most likely using?

A.

Manual signature matching

B.

Code quality testing

C.

Fraud detection

D.

Automated penetration testing

Which of the following describes the process of adjusting the distribution of underrepresented classes in an AI model data set to improve model performance?

A.

Data balancing

B.

Data lineage

C.

Data augmentation

D.

Data cleansing

An AI security administrator notices that the information referenced by the model is incorrectly formatted and missing values.

Which of the following job roles would most likely be responsible for correcting this error?

A.

Platform engineer

B.

Machine learning operations (MLOps) engineer

C.

Data engineer

D.

AI architect

A loan company compares a machine learning model that was found on the dark web with the company ' s proprietary model. Using proprietary information, the company generates the following:

Input

Dark web model

Company ' s proprietary model

Jane A.

Approve

Approve

John B.

Deny

Deny

Ann J.

Deny

Deny

Joe H.

Approve

Approve

Which of the following should the AI red team recommend to mitigate risks for future deployments?

A.

Parameter anonymization

B.

Prompt firewall

C.

Model encryption

D.

Input validation

Users report that the output of a generative AI application seems unrelated to the prompts and contains offensive content. A security team investigates and determines that there was an on-path attack.

Which of the following is the most likely attack method?

A.

Application server hijacking

B.

Session hijacking

C.

Domain hijacking

D.

Model hijacking

Which of the following provides guidance on AI-specific compliance?

A.

Organisation for Economic Co-operation and Development (OECD)

B.

International Organization for Standardization (ISO) 27001

C.

Payment Card Industry Data Security Standard (PCI DSS)

D.

General Data Protection Regulation (GDPR)

A security administrator needs to improve an AI model. During an initial investigation, the administrator notices that two successive login failures are recorded every day, and then a successful login occurs after a specific time interval. All the successful login attempts have been during office hours.

Which of the following techniques should the administrator use to improve the AI model ' s security?

A.

Access management

B.

Pattern recognition

C.

Signature matching

D.

Vulnerability analysis

A security consultant must summarize the impact of posture management on a machine learning (ML) use case.

Which of the following is the most appropriate reference for this purpose?

A.

Organization for Economic Co-operation and Development (OECD) standards

B.

National Institute of Standards and Technology (NIST) AI Risk Management Framework (RMF)

C.

European Union AI Act

D.

Generative adversarial network (GAN)

An airline corporation wants to implement a chatbot application using a large language model (LLM) so its customers can ask questions and receive answers about flight details and have the option to upload files.

Which of the following security controls should the airline use to protect against malicious input and unauthorized use beyond the service-level agreement? (Choose two.)

A.

Prompt guardrails

B.

Role-based access controls

C.

Firewall rules

D.

Model token quotas

After the deployment of an AI system, an organization is unable to identify who approved the system and the method of validation. Which of the following governance failures occurred?

A.

Absence of a completed threat model

B.

Absence of an audit trail

C.

Absence of blueprint controls

D.

Absence of organizational policies

Which of the following requires developers to harden infrastructure to protect AI systems?

A.

Intake processes

B.

Acceptable use policies

C.

Development guidelines

D.

Configuration standards

Before submitting code to the upstream code repository, a security administrator wants to implement the following:

• Comments describing the inputs, outputs, and purpose of code blocks

• Recommendations for code security

Which of the following should the administrator implement to address both requirements?

A.

Machine learning (ML)-based code checker

B.

Command-line interface (CLI)-based AI add-on

C.

AI-enabled integrated development environment (IDE) plug-in

D.

AI-assisted code repository runner

Which of the following is the primary security risk when deploying AI models in production?

A.

Graphics processing unit (GPU) acceleration

B.

Model overfitting

C.

Model encryption

D.

Data exposure

A security architect performs threat modeling of an AI system. The architect needs to determine which attacks can be performed against the system.

Which of the following actions should the architect take next?

A.

Leverage a large language model (LLM) to map likely attack paths based on the code base.

B.

Quantify the risk of known vulnerabilities identified in the AI system.

C.

Identify trust boundaries and perform threat modeling with Open Worldwide Application Security Project (OWASP) Top 10.

D.

Analyze MITRE Adversarial Threat Landscape for AI Systems (ATLAS) for tactics, techniques, and procedures (TTPs).

A company is adopting AI and wants to create policies and procedures that include a structure for evaluating, publishing, and approving patterns for AI usage.

Which of the following should the company establish to meet this goal?

A.

AI center of excellence

B.

AI legal affairs office

C.

AI audit department

D.

AI data science division

During a model validation procedure, an engineer notices that a model performs well during training but poorly during testing.

Which of the following best describes the reason?

A.

Fine-tuning

B.

Overfitting

C.

Regularization

D.

Inference

A financial services company is being sued for using AI in the loan underwriting process. The lawsuit reveals that the AI model used biased sources to disproportionately deny loans to residents in certain postal codes. Which of the following employees is the most qualified to remove these biased sources from the model?

A.

Platform engineer

B.

Data scientist

C.

Cybersecurity analyst

D.

AI architect

Page: 1 / 3
Total 159 questions
Copyright © 2014-2026 Solution2Pass. All Rights Reserved