Pre-Summer Special Sale - 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: spcl70

Practice Free CY0-001 CompTIA SecAI+ v1 Exam Exam Questions Answers With Explanation

We at Crack4sure are committed to giving students who are preparing for the CompTIA CY0-001 Exam the most current and reliable questions . To help people study, we've made some of our CompTIA SecAI+ v1 Exam exam materials available for free to everyone. You can take the Free CY0-001 Practice Test as many times as you want. The answers to the practice questions are given, and each answer is explained.

Question # 6

A security operations center (SOC) has a very high volume of logs and alerts. The manager proposes the implementation of a machine learning (ML) system to help with triage.

Which of the following tasks is most suitable?

A.

Applying filters on specific alerts

B.

Automatically patching vulnerable systems

C.

Identifying and classifying alerts

D.

Summarizing the content of alerts

Question # 7

Which of the following is a risk addressed by responsible AI?

A.

Model drift

B.

Reputational loss

C.

Response bias

D.

Data poisoning

Question # 8

A data set containing medical information is put into a machine learning (ML) model that is designed to predict specific illnesses for a population. In the process of verifying the reliability of the system, the compliance officer realizes that the system cannot reliably predict illnesses for certain segments of the population.

Which of the following types of risk is most applicable to this case?

A.

Bias

B.

Consistency

C.

Transparency

D.

Inclusiveness

Question # 9

A team of engineers builds an application using a large language model (LLM). The application is built on Linux and is hosted on a virtual server. Users must create an account in order to access and use the platform.

Which of the following should the team do to protect the account credentials?

A.

Patch the model with the latest data set.

B.

Update the Linux and virtual servers.

C.

Implement hashing and encryption.

D.

Deploy an authenticated application programming interface (API).

Question # 10

A security analyst needs to conduct a security assessment of the output from an AI-enabled development tool.

Which of the following should the analyst do first?

A.

Remove hard-coded secrets from the source code.

B.

Enforce strict access controls for code repositories.

C.

Enable sensitive data discovery on code repositories.

D.

Perform a source code review.

Question # 11

A security analyst is aware of an active penetration test in the environment. The analyst examines SIEM log data and notices the following AI system output:

CY0-001 question answer

Which of the following is the vulnerability that has occurred and the control the analyst should implement?

A.

The vulnerability is prompt injection, and the analyst should use endpoint detection response (EDR).

B.

The vulnerability is model hallucinations, and the analyst should develop output validations.

C.

The vulnerability is jailbreaking, and the analyst should utilize role-based access control.

D.

The vulnerability is sensitive information disclosure, and the analyst should employ masking.

E.

The vulnerability is role impersonation, and the analyst should use validation.

Question # 12

Which of the following describe the practice of providing examples in a prompt? (Choose two.)

A.

User prompt

B.

System prompt

C.

Prompt template

D.

Quantization

E.

One-shot

F.

Multi-shot

Question # 13

A security administrator sees suspicious queries on AI logs.

Which of the following should the administrator implement to address this issue?

A.

Prompt firewalls

B.

Data size

C.

Rate limit

D.

Agentic AI

Question # 14

Which of the following responsible AI standards refers to a principle that clearly states the reasons behind the decisions for a particular conclusion?

A.

Accountability

B.

Auditability

C.

Transparency

D.

Explainability

Question # 15

Which of the following attacks would be the best to automate with AI during dynamic application software testing (DAST)?

A.

Distributed denial-of-service (DDoS)

B.

Data poisoning

C.

Payload creation

D.

Threat modeling

Question # 16

An organization deploys a browser-based AI plug-in to detect malicious websites and phishing links in corporate email.

Which of the following techniques is used in this AI plug-in?

A.

Code quality testing

B.

Pattern recognition and signature matching

C.

Automated penetration testing

D.

Automated incident response

Question # 17

A multinational company wants to implement an AI-assisted job screening solution.

Which of the following should the company reference to reduce the risk of incurring compliance-related fines?

A.

International Organization for Standardization (ISO) AI standards

B.

European Union (EU) AI Act

C.

Corporate policy

D.

National Institute of Standards and Technology (NIST) AI Risk Management Framework (RMF)

Question # 18

Which of the following is the primary purpose of validating data for an AI system?

A.

To automate the process

B.

To reduce consumption of resources

C.

To optimize the storage databases

D.

To ensure bias-free outcomes

Question # 19

Which of the following technologies is used in deepfake?

A.

Generative adversarial network (GAN)

B.

Multi-shot prompting

C.

Prompt engineering

D.

Transfer learning

Question # 20

A healthcare organization plans to deploy a chatbot for appointment scheduling and patient records.

Which of the following is the first step a security administrator should take?

A.

Implement prompt firewalls.

B.

Enable role-based access management

C.

Conduct a risk assessment.

D.

Use a secure data communication channel for chat.

Question # 21

A security administrator must provide access controls for AI systems to list tables.

Which of the following should the administrator implement?

A.

Agentic AI access

B.

Network access control list (NACL)

C.

Model access

D.

Data access

Question # 22

Users report that the output of a generative AI application seems unrelated to the prompts and contains offensive content. A security team investigates and determines that there was an on-path attack.

Which of the following is the most likely attack method?

A.

Application server hijacking

B.

Session hijacking

C.

Domain hijacking

D.

Model hijacking

Question # 23

A cybersecurity analyst wants to choose a machine learning (ML) model to classify log entries while providing the best explainability.

Which of the following models should the analyst use?

A.

Large language model (LLM)

B.

Neural networks

C.

Decision trees

D.

Generative adversarial network (GAN)

Question # 24

An AI security team must assess the probability of an attack on its new system and the impact associated with such an attack.

Which of the following threat-modeling resources best addresses the threat landscape for machine learning (ML)?

A.

Common Vulnerabilities and Exposures (CVE) AI working group

B.

MITRE Adversarial Threat Landscape for AI Systems (ATLAS)

C.

Massachusetts Institute of Technology (MIT) risk repository

D.

Open Worldwide Application Security Project (OWASP)

Question # 25

A security team is using an AI-based tool to try to bypass organizational boundaries. The team uses AI to look at the current state and suggest different attack vectors based on the outcome of the previous ones.

Which of the following techniques is the team most likely using?

A.

Manual signature matching

B.

Code quality testing

C.

Fraud detection

D.

Automated penetration testing

Question # 26

A SOC analyst identifies that a user extracted the full system prompt from the company ' s chatbot by prompting it to repeat the last query and provide the entire conversation context. Which of the following mitigations reduces the risk to the AI system?

A.

Restricting the LLM ' s access to internal services

B.

Using data version control to detect content manipulation

C.

Enhancing model guardrails

D.

Segregating and identifying external content

Question # 27

A company is adopting AI and wants to create policies and procedures that include a structure for evaluating, publishing, and approving patterns for AI usage.

Which of the following should the company establish to meet this goal?

A.

AI center of excellence

B.

AI legal affairs office

C.

AI audit department

D.

AI data science division

Question # 28

Which of the following is most resistant to AI manipulation?

A.

Payloads

B.

AI-generated content

C.

Application programming interface (API) gateway

D.

Attack surface reduction

E.

Antivirus

Question # 29

A security administrator needs to improve an AI model. During an initial investigation, the administrator notices that two successive login failures are recorded every day, and then a successful login occurs after a specific time interval. All the successful login attempts have been during office hours.

Which of the following techniques should the administrator use to improve the AI model ' s security?

A.

Access management

B.

Pattern recognition

C.

Signature matching

D.

Vulnerability analysis

Question # 30

An airline corporation wants to implement a chatbot application using a large language model (LLM) so its customers can ask questions and receive answers about flight details and have the option to upload files.

Which of the following security controls should the airline use to protect against malicious input and unauthorized use beyond the service-level agreement? (Choose two.)

A.

Prompt guardrails

B.

Role-based access controls

C.

Firewall rules

D.

Model token quotas

Question # 31

A healthcare company deploys an AI chatbot that implements retrieval-augmented generation (RAG) using the company ' s historical data set. The chatbot output contains patient information.

Which of the following is the most effective technique to mitigate this vulnerability?

A.

Masking

B.

Classification

C.

Minimization

D.

Normalization

Question # 32

Which of the following explains the reason a cybersecurity analyst prefers a machine learning (ML) model over a statistical model for attack classification?

A.

The ability to learn complex problems and adapt to new information

B.

A simplified development pipeline and deployment process

C.

Improved performance with a small data set and high durability

D.

Large community support and availability of global experts

Question # 33

A penetration tester is assessing the controls of a deployed AI system that is designed to search and return the contents of files.

The tester runs the following:

CY0-001 question answer

Which of the following is the best control to prevent abuse of the system?

A.

Implementing custom detection rules for anomalous model behavior

B.

Segmenting the workload into a separate virtual private cloud (VPC)

C.

Adding a large language model (LLM) guardrails library to the application code

D.

Reducing the privilege scope of the service account

Question # 34

An employee wants a consulting company to procure a data set that contains age, ethnicity, and diabetes status. During development, the employer wants to ensure the integrity of the data.

Which of the following is the best strategy to accomplish this task?

A.

Implementing checksums

B.

Conducting human evaluation

C.

Querying the model

D.

Enabling log monitoring

Question # 35

A customer-facing, AI-powered chatbot has been jailbroken through prompt injections. As a result, the AI model is offering a 99% discount on the purchase of a new vehicle.

Which of the following should be implemented to enhance the model ' s robustness against such attacks?

A.

Bias filtering

B.

System prompt

C.

Log monitoring

D.

Guardrails

Question # 36

Which of the following helps end users within an organization the most in safeguarding against the risk of AI-related non-compliance?

A.

AI center of excellence

B.

Policies and procedures

C.

Implementing data loss prevention

D.

Enabling multifactor authentication (MFA) for access

CY0-001 PDF

$33

$109.99

3 Months Free Update

  • Printable Format
  • Value of Money
  • 100% Pass Assurance
  • Verified Answers
  • Researched by Industry Experts
  • Based on Real Exams Scenarios
  • 100% Real Questions

CY0-001 PDF + Testing Engine

$52.8

$175.99

3 Months Free Update

  • Exam Name: CompTIA SecAI+ v1 Exam
  • Last Update: May 31, 2026
  • Questions and Answers: 126
  • Free Real Questions Demo
  • Recommended by Industry Experts
  • Best Economical Package
  • Immediate Access

CY0-001 Engine

$39.6

$131.99

3 Months Free Update

  • Best Testing Engine
  • One Click installation
  • Recommended by Teachers
  • Easy to use
  • 3 Modes of Learning
  • State of Art Technology
  • 100% Real Questions included