Summer Sale - Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 65percent

Welcome To DumpsPedia

CY0-001 Sample Questions Answers

Questions 4

Which of the following is the most impactful security risk associated with the use of a generative AI chatbot?

Options:

A.

Overly permissive access

B.

Data leakage

C.

Weak encryption

D.

Model validation

Buy Now
Questions 5

A security analyst reviews a recently released chatbot ' s log and discovers that outputs sometimes include personally identifiable information (PII) from other chatbot users.

Which of the following corrective actions should the security analyst take first to resolve this issue?

Options:

A.

Take the chatbot offline and restore it from a backup.

B.

Disable memory from the chat history for all users.

C.

Ask all users to refrain from using PII with the chatbot.

D.

Require users to label the sensitivity of their requests.

Buy Now
Questions 6

An administrator, who works for a financial institution, is required to implement data security controls for data at rest within AI systems that involve data disclosure.

Which of the following is the most suitable control?

Options:

A.

Data lineage

B.

Rate limits

C.

Encryption

D.

Masking

Buy Now
Questions 7

During a model validation procedure, an engineer notices that a model performs well during training but poorly during testing.

Which of the following best describes the reason?

Options:

A.

Fine-tuning

B.

Overfitting

C.

Regularization

D.

Inference

Buy Now
Questions 8

A SOC analyst identifies that a user extracted the full system prompt from the company ' s chatbot by prompting it to repeat the last query and provide the entire conversation context. Which of the following mitigations reduces the risk to the AI system?

Options:

A.

Restricting the LLM ' s access to internal services

B.

Using data version control to detect content manipulation

C.

Enhancing model guardrails

D.

Segregating and identifying external content

Buy Now
Questions 9

A security administrator wants to prevent prompt injection attacks and ensure responses have sanitized output.

Which of the following provides a primary compensating control for these requirements?

Options:

A.

Least privilege

B.

Encryption

C.

A large language model (LLM) firewall

D.

Rate limiting

Buy Now
Questions 10

An organization develops a chatbot that does not provide harmful or explicit responses, must use clean and professional language, and ensures that responses are accurate.

Which of the following should the organization conduct after the chatbot is fully developed but before a customer-facing deployment?

Options:

A.

Data labeling and classification

B.

Model auditing and evaluation

C.

Guardrail testing and validation

D.

Regression modeling and minimization

Buy Now
Questions 11

An organization deploys a browser-based AI plug-in to detect malicious websites and phishing links in corporate email.

Which of the following techniques is used in this AI plug-in?

Options:

A.

Code quality testing

B.

Pattern recognition and signature matching

C.

Automated penetration testing

D.

Automated incident response

Buy Now
Questions 12

Which of the following strengthens the performance of a large language model (LLM) for malicious reconnaissance?

Options:

A.

Enhancing a foundational model with the inclusion of retrieval-augmented generation (RAG)

B.

Creating a web scraper script using AI to capture the company website

C.

Instructing an AI assistant to query as an administrator

D.

Prompting a chatbot to describe server naming patterns and Internet Protocol (IP) ranges

Buy Now
Questions 13

An AI security administrator notices that the information referenced by the model is incorrectly formatted and missing values.

Which of the following job roles would most likely be responsible for correcting this error?

Options:

A.

Platform engineer

B.

Machine learning operations (MLOps) engineer

C.

Data engineer

D.

AI architect

Buy Now
Questions 14

A SOC team has an AI agent that performs web searches and calls to the SOAR solution. The team is concerned about enterprise uptime and case resolution time.

Which of the following is the most appropriate use of the AI agent?

Options:

A.

To analyze and contain offending users or hosts using SOAR playbooks

B.

To perform research using open-source intelligence to enrich the alerts

C.

To aggregate SOC metrics and generate reports for the leadership team

D.

To create tabletop exercises so the team can increase its incident response speed

Buy Now
Questions 15

A security consultant needs to detect attacks across a large language model (LLM) firewall.

Which of the following techniques should the consultant use?

Options:

A.

Signature matching

B.

Distributed denial-of-service

C.

Translation analysis

D.

Vulnerability enumeration

Buy Now
Questions 16

A machine learning (ML) engineer is working with a security engineer to identify the best practices for securing a system with various AI models.

Which of the following actions should the engineers suggest?

Options:

A.

Conducting guardrail testing and security validation

B.

Following a secure model development life cycle (MDLC)

C.

Implementing comprehensive security architecture

D.

Using a secure software development life cycle (SDLC)

Buy Now
Questions 17

Security analysts want to track potential user behavior anomalies over time. Which of the following is the most comprehensive approach?

Options:

A.

Using an AI-enabled scanner to compare user permissions to other users in the department

B.

Using an agentic large language model (LLM) to search for multiple instances of a username in logs

C.

Leveraging browser plug-ins that monitor for uncommon sites visited by a user

D.

Running automated playbooks that monitor standard deviations from a user baseline

Buy Now
Questions 18

A detection engineering team wants to use AI to automatically prevent vulnerable code from reaching production.

Which of the following is the most effective way to accomplish this task?

Options:

A.

Deploying an integrated development environment (IDE) plug-in that will warn developers of dangerous code before compiling

B.

Using a security orchestration, automation, and response (SOAR) with a machine learning (ML) model to classify code

C.

Implementing a large language model (LLM) in the continuous integration and continuous deployment (CI/CD) runner to examine code and pass or fail build jobs

D.

Developing an agentic penetration testing tool to validate potential vulnerable code

Buy Now
Questions 19

A security operations center (SOC) has a very high volume of logs and alerts. The manager proposes the implementation of a machine learning (ML) system to help with triage.

Which of the following tasks is most suitable?

Options:

A.

Applying filters on specific alerts

B.

Automatically patching vulnerable systems

C.

Identifying and classifying alerts

D.

Summarizing the content of alerts

Buy Now
Questions 20

An organization implements a domain-specific AI chatbot. After operating normally for weeks, the model returns contextually incorrect responses — treating ' worm ' as a biological pest rather than a computer worm when answering a cybersecurity question.

Which of the following should the organization do to address the issue?

Options:

A.

Configure guardrails.

B.

Encrypt the weights at rest.

C.

Apply model access controls.

D.

Deploy prompt templates.

Buy Now
Questions 21

An organization wants to reduce vulnerabilities after deployment. The organization decides to incorporate an AI-assisted early detection and vulnerability identification process in its development workflow.

Which of the following AI-assisted functions is the best option?

Options:

A.

Code linting

B.

Incident management

C.

Automated deployment/rollback

D.

System auditing

Buy Now
Questions 22

Which of the following describe the practice of providing examples in a prompt? (Choose two.)

Options:

A.

User prompt

B.

System prompt

C.

Prompt template

D.

Quantization

E.

One-shot

F.

Multi-shot

Buy Now
Questions 23

Which of the following responsible AI standards refers to a principle that clearly states the reasons behind the decisions for a particular conclusion?

Options:

A.

Accountability

B.

Auditability

C.

Transparency

D.

Explainability

Buy Now
Questions 24

A penetration tester is assessing the controls of a deployed AI system that is designed to search and return the contents of files.

The tester runs the following:

24

Which of the following is the best control to prevent abuse of the system?

Options:

A.

Implementing custom detection rules for anomalous model behavior

B.

Segmenting the workload into a separate virtual private cloud (VPC)

C.

Adding a large language model (LLM) guardrails library to the application code

D.

Reducing the privilege scope of the service account

Buy Now
Questions 25

A security administrator must provide access controls for AI systems to list tables.

Which of the following should the administrator implement?

Options:

A.

Agentic AI access

B.

Network access control list (NACL)

C.

Model access

D.

Data access

Buy Now
Questions 26

After the latest software update, a developer receives reports that the system no longer requires reauthentication to display account balances because this issue was present in a previous release. Which of the following should the developer do to best mitigate the risk of recurrence?

Options:

A.

Ensure that AI approvals are required to push changes into production.

B.

Implement AI regression testing into the continuous integration/continuous deployment (CI/CD) pipeline.

C.

Deploy an AI-assisted change management system to schedule and track feature releases.

D.

Use code commit automation to perform AI-assisted static application security testing (SAST) scans.

Buy Now
Questions 27

A recent release of an AI software update exposes confidential customer information due to storage misconfiguration.

Which of the following data security controls will help maintain confidentiality despite the data leak?

Options:

A.

Model encryption

B.

Encryption in transit

C.

Encryption in use

D.

Encryption at rest

Buy Now
Questions 28

Which of the following attacks would be the best to automate with AI during dynamic application software testing (DAST)?

Options:

A.

Distributed denial-of-service (DDoS)

B.

Data poisoning

C.

Payload creation

D.

Threat modeling

Buy Now
Questions 29

Which of the following improves the observability and auditing of an AI system?

Options:

A.

Redeploying the model

B.

Using manual detection

C.

Implementing machine learning operations (MLOps)

D.

Using anomaly detections

Buy Now
Questions 30

Which of the following describes the number of training cycles used in an AI model for threat detection?

Options:

A.

k-means clustering

B.

Tokens

C.

Temperature

D.

Epoch

Buy Now
Questions 31

A user interface engineer adds new graphics to the latest release of an AI-integrated application. During the update, the engineer accidentally causes the model to retrain on unverified data. After the update, the model begins to return many errors.

Which of the following is the best way to mitigate future errors?

Options:

A.

Web application firewall

B.

Role-based access control

C.

Model development life cycle

D.

Generative adversarial network

Buy Now
Questions 32

Which of the following types of prompts best describes a developer’s input that informs AI interactions?

Options:

A.

System

B.

User

C.

Zero-shot

D.

Multi-shot

Buy Now
Questions 33

A company uses human review for software development validation and wants to add another validation layer.

Which of the following should a security administrator use to accomplish this task?

Options:

A.

AI-assisted approval

B.

Low-code plug-in

C.

Automated rollback

D.

Regression testing

Buy Now
Questions 34

A security alert triggers an agentic system. An analyst notices the following payload in the logs. The alert includes multiple shell commands that are not typically run as part of any hardening:

34

Which of the following is the most effective control to implement?

Options:

A.

Adding logic that includes approved strings before running the shell commands

B.

Deprecating model usage and retaining the model with safer parameters

C.

Modifying the application to ignore the SECURITY_UPDATE tag

D.

Using only approved libraries when interacting with agentic systems

Buy Now
Questions 35

Which of the following is an example of how a security analyst uses generative AI in the triage process?

Options:

A.

To predict the next attack target with higher accuracy

B.

To use statistical analysis for malicious code assessment

C.

To summarize security findings by category

D.

To tag malware using machine learning (ML) algorithms

Buy Now
Questions 36

An administrator must conduct generative AI cost monitoring for use in the healthcare industry.

Which of the following criteria is the best way to calculate this cost?

Options:

A.

Connection access and exchange gateway

B.

Encryption and decryption processing

C.

Storage retrieval and prompt processing

D.

Catalog servicing and exchange processing

Buy Now
Questions 37

An AI security team must assess the probability of an attack on its new system and the impact associated with such an attack.

Which of the following threat-modeling resources best addresses the threat landscape for machine learning (ML)?

Options:

A.

Common Vulnerabilities and Exposures (CVE) AI working group

B.

MITRE Adversarial Threat Landscape for AI Systems (ATLAS)

C.

Massachusetts Institute of Technology (MIT) risk repository

D.

Open Worldwide Application Security Project (OWASP)

Buy Now
Questions 38

A management team is concerned about an unexpected cost increase for a public-facing AI chatbot.

Which of the following should a security administrator examine first to determine the root cause?

Options:

A.

Firewall logs

B.

Web application firewall (WAF) rules

C.

Vector database input/output operations per second performance

D.

Model token usage

Buy Now
Questions 39

A financial organization implements a new AI-based fraud detection system to flag suspicious transactions. A security analyst discovers that it occasionally blocks legitimate transactions.

Which of the following is the best recommendation?

Options:

A.

Retraining the model with more data and recent transaction patterns

B.

Implementing AI token usage and rate limits

C.

Encrypting all the data processed by AI and applying further access controls

D.

Rolling back the model and using a traditional fraud detection system

Buy Now
Questions 40

Which of the following is the primary purpose of validating data for an AI system?

Options:

A.

To automate the process

B.

To reduce consumption of resources

C.

To optimize the storage databases

D.

To ensure bias-free outcomes

Buy Now
Exam Code: CY0-001
Exam Name: CompTIA SecAI+ v1 Exam
Last Update: Aug 24, 2026
Questions: 134

PDF + Testing Engine

$59.99 $171.4

Testing Engine

$44.99 $128.55

PDF (Q&A)

$49.99 $142.82