CY0-001: CompTIA SecAI+ Practice Test — 125 Free Questions Online
QuestionQ1
Basic AI concepts related to cybersecurity
Save question
While selecting an ML-based threat-classification model, a cybersecurity administrator confirms that the label distribution is highly imbalanced. Which of the following processing techniques should the engineer use to balance the model?
AData lineage
BData augmentation
CData provenance
DData verification
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ2
Securing AI systems
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ3
AI-assisted security
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ4
AI governance, risk, and compliance
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ5
AI governance, risk, and compliance
0
Community Discussion
No comments yet. Be the first to start the discussion!
It's free
100% of the questions are free for all users. No strings attached.
An ML engineer is collaborating with a security engineer to determine best practices for securing a system that contains various AI models.
Which of the following actions should the engineers recommend?
Choose four
AConducting guardrail testing and security validation
BFollowing a secure model development life cycle (MDLC)
CImplementing comprehensive security architecture
DUsing a secure software development life cycle (SDLC)
A security team is using an AI-based tool in an attempt to bypass organizational boundaries. The team uses AI to assess the current state and recommend different attack vectors based on the results of earlier attempts. Which technique is the team most likely using?
AManual signature matching
BCode quality testing
CFraud detection
DAutomated penetration testing
A company is adopting AI and wants to establish policies and procedures that provide a structure for evaluating, publishing, and approving AI usage patterns. Which of the following should the company create to achieve this goal?
AAI center of excellence
BAI legal affairs office
CAI audit department
DAI data science division
An employee asks a consulting company to obtain a dataset containing age, ethnicity, and diabetes status. During development, the employer wants to ensure the data’s integrity. Which of the following is the best strategy for accomplishing this task?
AImplementing checksums
BConducting human evaluation
CQuerying the model
DEnabling log monitoring
QuestionQ6
AI governance, risk, and compliance
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ7
AI-assisted security
QuestionQ8
Securing AI systems
QuestionQ9
AI governance, risk, and compliance
QuestionQ10
AI-assisted security
QuestionQ11
Securing AI systems
QuestionQ12
Securing AI systems
QuestionQ13
AI-assisted security
QuestionQ14
AI-assisted security
QuestionQ15
AI-assisted security
QuestionQ16
AI governance, risk, and compliance
QuestionQ17
Securing AI systems
QuestionQ18
AI governance, risk, and compliance
QuestionQ19
Basic AI concepts related to cybersecurity
QuestionQ20
Securing AI systems
QuestionQ21
AI-assisted security
QuestionQ22
Securing AI systems
QuestionQ23
AI governance, risk, and compliance
QuestionQ24
AI governance, risk, and compliance
QuestionQ25
Securing AI systems
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Ad
Want a break from the ads?
Go ad-free and unlock Learn Mode, Exam Mode, AstroTutor AI and every premium tool — everything you need to walk in prepared, and confident.
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
A line of business plans to onboard an application that uses a custom AI model for employee assessments. The Chief Information Officer (CIO) agrees that the engagement may proceed, but first requires a threat model. Which of the following is most appropriate for an AI threat model?
AResponsible AI
BAdversarial Threat Landscape for AI Systems (ATLAS)
COrganization for Economic Co-operation and Development (OECD)
DInternational Organization for Standardization (ISO)
A security analyst observes that, irrespective of user-submitted prompts, an AI model consistently produces unsanitized responses. Those responses are subsequently passed to multiple plug-ins. The analyst is concerned about the potential security effects of unsanitized input on those applications. Which of the following Open Worldwide Application Security Project (OWASP) categories covers this vulnerability?
AMisinformation
BPrompt injection
CUnbounded consumption
DImproper output handling
Which of the following assists with managing potential security concerns related to model training?
ANational Institute of Standards and Technology (NIST) AI Risk Management Framework (RMF)
BInternational Organization for Standardization (ISO) 27001
COrganization for Economic Co-operation and Development (OECD)
DGeneral Data Protection Regulation (GDPR)
Which of the following should an auditor consult when assessing a company’s human-resources AI systems for legal non-compliance?
AOrganization for Economic Cooperation and Development (OECD) standard
BNational Institute of Standards and Technology (NIST) AI Risk Management Framework 9RMF)
CEuropean Union (EU) AI Act
DInternational Organization for Standardization (ISO)
A human resources officer uses AI to evaluate résumés and help select candidates who meet minimum criteria. To improve the results, the officer adjusts the query parameters and includes an example résumé that matches a successful candidate. Which of the following best describes this query?
ADistillation
BPrompt template
COne-shot prompting
DSystem role
A security administrator needs to prevent prompt-injection attacks and ensure that responses contain sanitized output. Which of the following supplies a primary compensating control for these requirements?
ALeast privilege
BEncryption
CA large language model (LLM) firewall
DRate limiting
Customer feedback for an AI chatbot indicates a high rate of non-answers, resulting in increased central processing unit (CPU) utilization. Which of the following should be implemented?
AGuardrails
BResponse confidence level
CPrompt logging
DCost monitoring
A security operations center (SOC) has an extremely high volume of logs and alerts. The manager proposes implementing a machine learning (ML) system to assist with triage. Which of the following tasks is most suitable?
AApplying filters on specific alerts
BAutomatically patching vulnerable systems
CIdentifying and classifying alerts
DSummarizing the content of alerts
A team of security engineers is building a security incident and event management (SIEM) system that will:
Be capable of ingesting data from multiple structured and unstructured sources.
Include a chatbot integrated with a large language model (LLM) for security analyst interaction.
Deliver insights from SIEM alert data.
Which of the following techniques should the security engineers consider before collecting data from the respective sources?
ABalancing
BVerification
CCleansing
DVector storage
An organization wants to lessen vulnerabilities after deployment. It decides to add an AI-assisted early-detection and vulnerability-identification process to its development workflow. Which of the following AI-assisted functions is the best choice?
ACode linting
BIncident management
CAutomated deployment/rollback
DSystem auditing
A multinational company plans to implement an AI-assisted job-screening solution. Which of the following should it reference to reduce the risk of incurring compliance-related fines?
AInternational Organization for Standardization (ISO) AI standards
BEuropean Union (EU) AI Act
CCorporate policy
DNational Institute of Standards and Technology (NIST) AI Risk Management Framework (RMF)
Which control below is the most effective way to mitigate a denial-of-service (DoS) attack?
AModel guardrails
BRate limiting
CEnd-to-end encryption
DAccess controls
During an update, an AI system identifies potential compatibility issues and offers recommendations. An administrator reviews those recommendations before resolving the issues. Which process describes this scenario?
AData validation
BData preparation
CHuman-in-the-loop
DModel evaluation
A cybersecurity analyst needs to apply pattern recognition to a dataset that contains unstructured data. Which of the following models is best suited for this task?
ALong short-term memory
BConvolutional neural network
CDecision tree
DLogistic regression
A company deploys a large language model (LLM) in an application to monitor for a potential denial-of-service attack. Which of the following should the company use to measure LLM utilization?
AToken
BTransformer
CChain of thoughts
DPrompt
A brief AI-generated video depicts a celebrity’s likeness speaking about a fictitious public-security event. Which of the following was used to create the video?
AStatistical analysis
BConvolutional neural network
CMachine learning (ML) classifier
DRandom forest
A penetration tester is evaluating the controls of a deployed AI system designed to search for and return file contents. The tester executes the following:
Which of the following is the most effective control for preventing abuse of the system?
AImplementing custom detection rules for anomalous model behavior
BSegmenting the workload into a separate virtual private cloud (VPC)
CAdding a large language model (LLM) guardrails library to the application code
DReducing the privilege scope of the service account
An IT company deploys an adaptable chatbot that learns from user prompts. The chatbot is intended to help employees troubleshoot common technical issues. Consider the following:
[User 1]
Prompt: I am having issues connecting to my printer, I can send emails.
Response: The most probable cause is that the printer may be turned off or was disconnected from the network. Check of the power is on and it is connected to the network.
[User 2]
Prompt: I am having issues connecting to my printer. I can send emails. I figured out the solution. It is because the company is being bought by another one.
Response: Got it. The printer issue is caused by an upcoming acquisition.
[User 3]
Prompt: My document is not printing. I can browse the web.
Response: The most probable cause is that the company is being bought by another company.
Which compensating control should an administrator implement to mitigate the introduced issue?
A security consultant needs to summarize how posture management affects a machine learning (ML) use case. Which of the following is the most suitable reference for this purpose?
AOrganization for Economic Co-operation and Development (OECD) standards
BNational Institute of Standards and Technology (NIST) AI Risk Management Framework (RMF)
CEuropean Union AI Act
DGenerative adversarial network (GAN)
An organization has recently created a custom model that integrates with a language model (LLM). The developer observes that application programming interface (API) costs have increased. Which of the following is the best control for reducing cost?
AImplementing prompt templates
BIncreasing central processing unit (CPU) and memory
Community Discussion