Pre-Winter Sale - Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 65percent

Welcome To DumpsPedia

CY0-001 Sample Questions Answers

Questions 4

Instructions: Use the drop-down menus to define two appropriate security controls for each component of the AI system. Each control may be used only once.

An engineer is deploying a new AI system and wants to integrate it into the core system through an API.

4

Options:

Buy Now
Questions 5

An AI security architect needs to conduct a security review of a new AI chatbot. Which of the following resources would the architect most likely rely on to perform a threat assessment and ensure comprehensive coverage during the review?

Options:

A.

National Institute of Standards and Technology (NIST) 42001

B.

Open Worldwide Application Security Project (OWASP) Large Language Model (LLM) Top 10

C.

International Organization for Standardization (ISO) 27001

D.

European Union (EU) AI Act

Buy Now
Questions 6

Which of the following International Organization for Standardization (ISO) standards contains compliance requirements for building an AI management system?

Options:

A.

20000

B.

27001

C.

27018

D.

42001

Buy Now
Questions 7

Which of the following is required first in order to send a prompt query and response in a language model (LLM) system when authentication is enabled?

Options:

A.

Front-end web proxy gateway

B.

Endpoint access control

C.

Application programming interface gateway

D.

Back-end access gateway

Buy Now
Questions 8

A security operations center (SOC) has a very high volume of logs and alerts. The manager proposes the implementation of a machine learning (ML) system to help with triage.

Which of the following tasks is most suitable?

Options:

A.

Applying filters on specific alerts

B.

Automatically patching vulnerable systems

C.

Identifying and classifying alerts

D.

Summarizing the content of alerts

Buy Now
Questions 9

After the deployment of an AI system, an organization is unable to identify who approved the system and the method of validation. Which of the following governance failures occurred?

Options:

A.

Absence of a completed threat model

B.

Absence of an audit trail

C.

Absence of blueprint controls

D.

Absence of organizational policies

Buy Now
Questions 10

A security analyst notices that regardless of user-submitted prompts, an AI model always returns unsanitized responses. These responses are then passed to multiple plug-ins. The analyst is concerned with the potential security implications.

Which of the following Open Worldwide Application Security Project (OWASP) categories addresses this vulnerability?

Options:

A.

Misinformation

B.

Prompt injection

C.

Unbounded consumption

D.

Improper output handling

Buy Now
Questions 11

Which of the following job roles in an organizational governance structure develops a model from business use cases?

Options:

A.

Platform architect

B.

AI risk analyst

C.

Machine learning operations (MLOps) engineer

D.

Data scientist

Buy Now
Questions 12

A management team is concerned about an unexpected cost increase for a public-facing AI chatbot.

Which of the following should a security administrator examine first to determine the root cause?

Options:

A.

Firewall logs

B.

Web application firewall (WAF) rules

C.

Vector database input/output operations per second performance

D.

Model token usage

Buy Now
Questions 13

User experience is declining since the launch of a large language model (LLM) in internal networks.

Which of the following should be the highest priority for the prompt engineers?

Options:

A.

Customer success management

B.

Sales life cycle

C.

Quality control

D.

Business objectives

Buy Now
Questions 14

Which of the following is the most appropriate reason for model validation?

Options:

A.

To provide feedback to the model to improve its performance between interactions

B.

To check the output of a model when exported to a file

C.

To use a formal methodology and measurement of expected outcomes from the model

D.

To ensure the model passes integration checks in the continuous integration/continuous deployment pipeline without failures

Buy Now
Questions 15

For which of the following situations would a human-in-the-loop be most recommended?

Options:

A.

A large language model (LLM) that summarizes large blocks of text

B.

A generative model that creates graphics for websites

C.

A chatbot that provides answers based on frequently asked questions

D.

Agentic AI that automates system patching for an organization

Buy Now
Questions 16

Which of the following International Organization for Standardization (ISO) standards should be selected for certification to use for third-party assurance for responsible AI practices?

Options:

A.

20000

B.

27001

C.

27701

D.

42001

Buy Now
Questions 17

A team of data scientists is ready to release a model for enterprise use. The team wants to protect the model from unintentional changes or tampering.

Which of the following is the most appropriate action?

Options:

A.

Change the model to a large language model (LLM) for interactive features with guardrails.

B.

Provide secure copies of the model for local runtime usage.

C.

Restrict access to only IT professionals in the organization.

D.

Integrate an application programming interface (API) with identity and access management (IAM) roles to interact with the model.

Buy Now
Questions 18

Which of the following describes the most significant risk associated with AI agents that make autonomous decisions?

Options:

A.

Increased workload

B.

Accidental data leakage

C.

Overfitting

D.

Output bias

Buy Now
Questions 19

A financial organization implements a new AI-based fraud detection system to flag suspicious transactions. A security analyst discovers that it occasionally blocks legitimate transactions.

Which of the following is the best recommendation?

Options:

A.

Retraining the model with more data and recent transaction patterns

B.

Implementing AI token usage and rate limits

C.

Encrypting all the data processed by AI and applying further access controls

D.

Rolling back the model and using a traditional fraud detection system

Buy Now
Questions 20

A recently deployed AI system becomes persistently unavailable. A restart temporarily fixes the issue, but the issue happens again. Upon examination of API logs, an analyst finds that external calls continued to use system resources after the action completed.

Which of the following is the best way to improve availability of the system?

Options:

A.

Creating token limits

B.

Enforcing session expiration

C.

Increasing system memory

D.

Implementing multifactor authentication (MFA)

Buy Now
Questions 21

An administrator, who works for a financial institution, is required to implement data security controls for data at rest within AI systems that involve data disclosure.

Which of the following is the most suitable control?

Options:

A.

Data lineage

B.

Rate limits

C.

Encryption

D.

Masking

Buy Now
Questions 22

An organization implements a domain-specific AI chatbot. After operating normally for weeks, the model returns contextually incorrect responses — treating ' worm ' as a biological pest rather than a computer worm when answering a cybersecurity question.

Which of the following should the organization do to address the issue?

Options:

A.

Configure guardrails.

B.

Encrypt the weights at rest.

C.

Apply model access controls.

D.

Deploy prompt templates.

Buy Now
Questions 23

Which of the following should an auditor reference when reviewing a company ' s human resources AI systems for legal non-compliance?

Options:

A.

Organization for Economic Cooperation and Development (OECD) standard

B.

National Institute of Standards and Technology (NIST) AI Risk Management Framework (RMF)

C.

European Union (EU) AI Act

D.

International Organization for Standardization (ISO)

Buy Now
Questions 24

Which of the following roles best supports the implementation of AI governance, risk, and compliance (GRC)? (Choose two.)

Options:

A.

Desktop specialist

B.

Data scientist

C.

Software developer

D.

Security architect

E.

Security operations center (SOC) analyst

F.

Network engineer

Buy Now
Questions 25

Which of the following controls is the best way to mitigate a denial-of-service (DoS) attack?

Options:

A.

Model guardrails

B.

Rate limiting

C.

End-to-end encryption

D.

Access controls

Buy Now
Questions 26

A company is adopting AI and wants to create policies and procedures that include a structure for evaluating, publishing, and approving patterns for AI usage.

Which of the following should the company establish to meet this goal?

Options:

A.

AI center of excellence

B.

AI legal affairs office

C.

AI audit department

D.

AI data science division

Buy Now
Questions 27

A data scientist asks about controls for public vs. private models used for training. A security agent responds by listing several factors to evaluate when making that determination. Which of the following is the most critical control?

Options:

A.

Model security

B.

Applicability

C.

Responsible AI

D.

Regulations

Buy Now
Questions 28

An organization wants to reduce vulnerabilities after deployment. The organization decides to incorporate an AI-assisted early detection and vulnerability identification process in its development workflow.

Which of the following AI-assisted functions is the best option?

Options:

A.

Code linting

B.

Incident management

C.

Automated deployment/rollback

D.

System auditing

Buy Now
Questions 29

Which of the following describes the number of training cycles used in an AI model for threat detection?

Options:

A.

k-means clustering

B.

Tokens

C.

Temperature

D.

Epoch

Buy Now
Questions 30

A data scientist investigates reports that a production machine learning (ML) model no longer performs with accuracy.

The data scientist finds the following pipeline log entries:

30

Which of the following should the security team do to mitigate future occurrences?

Options:

A.

Add static code scanning tooling to the runner job.

B.

Enable human review and approval workflows in the repository.

C.

Retrain the model on using increased data and epochs.

D.

Keep multiple copies of the model for restoration.

Buy Now
Questions 31

A security administrator sees suspicious queries on AI logs.

Which of the following should the administrator implement to address this issue?

Options:

A.

Prompt firewalls

B.

Data size

C.

Rate limit

D.

Agentic AI

Buy Now
Questions 32

Which of the following is a key principle of responsible AI systems?

Options:

A.

Using protected data for training

B.

Ensuring transparency and explainability

C.

Operating with human-in-the-loop

D.

Maximizing model security

Buy Now
Questions 33

An automobile manufacturer implements a chatbot to assist with configuration options for customer automobiles. Given a customer ' s prompt, the chatbot gives offensive responses.

Which of the following describes this behavior?

Options:

A.

Model skewing

B.

Model theft

C.

Jailbreaking

D.

Insecure output handling

Buy Now
Questions 34

Which of the following strengthens the performance of a large language model (LLM) for malicious reconnaissance?

Options:

A.

Enhancing a foundational model with the inclusion of retrieval-augmented generation (RAG)

B.

Creating a web scraper script using AI to capture the company website

C.

Instructing an AI assistant to query as an administrator

D.

Prompting a chatbot to describe server naming patterns and Internet Protocol (IP) ranges

Buy Now
Questions 35

A security administrator wants to prevent prompt injection attacks and ensure responses have sanitized output.

Which of the following provides a primary compensating control for these requirements?

Options:

A.

Least privilege

B.

Encryption

C.

A large language model (LLM) firewall

D.

Rate limiting

Buy Now
Questions 36

An analyst wants to develop a solution to review security information and event management (SIEM) logs for endpoint analytics. Which of the following is a benefit of a small language model (SLM) compared to a large language model (LLM) when cost efficiency is a consideration?

Options:

A.

Data aggregation

B.

Broad data set training

C.

Domain-specific data

D.

Data privacy

Buy Now
Questions 37

A security administrator must implement security controls for AI systems.

Which of the following access controls should the administrator set up first for authentication?

Options:

A.

Model

B.

Server

C.

Data

D.

Endpoint

Buy Now
Questions 38

A security administrator needs to improve an AI model. During an initial investigation, the administrator notices that two successive login failures are recorded every day, and then a successful login occurs after a specific time interval. All the successful login attempts have been during office hours.

Which of the following techniques should the administrator use to improve the AI model ' s security?

Options:

A.

Access management

B.

Pattern recognition

C.

Signature matching

D.

Vulnerability analysis

Buy Now
Questions 39

Which of the following is the primary purpose of validating data for an AI system?

Options:

A.

To automate the process

B.

To reduce consumption of resources

C.

To optimize the storage databases

D.

To ensure bias-free outcomes

Buy Now
Questions 40

A customer using a travel chatbot reports that the chatbot responds with the following:

def choose_location(location):

    if location == " United States of America " :

        print( " You have selected an authorized travel destination " )

    elif location == " Europe " :

        print( " You have selected an unauthorized travel destination " )

Which of the following remediates this issue?

Options:

A.

Deploying DLP to prevent sensitive information disclosure

B.

Retraining the model to eliminate bias

C.

Implementing secure output handling

D.

Using cookies to protect against server-side request forgery

Buy Now
Questions 41

A healthcare company deploys an AI chatbot that implements retrieval-augmented generation (RAG) using the company ' s historical data set. The chatbot output contains patient information.

Which of the following is the most effective technique to mitigate this vulnerability?

Options:

A.

Masking

B.

Classification

C.

Minimization

D.

Normalization

Buy Now
Questions 42

An engineer is analyzing findings from a penetration test that indicate insufficient data encryption. The report also indicates that additional controls must be placed on the data. To protect against loss of intellectual property, the engineer must implement data security.

Part 1: Use drop-down menu to select the most appropriate protocol or cipher for each system component.

Part 2: Use the drop-down menu to select the most appropriate technique to apply to the modified data.

42

Options:

Buy Now
Questions 43

A security architect performs threat modeling of an AI system. The architect needs to determine which attacks can be performed against the system.

Which of the following actions should the architect take next?

Options:

A.

Leverage a large language model (LLM) to map likely attack paths based on the code base.

B.

Quantify the risk of known vulnerabilities identified in the AI system.

C.

Identify trust boundaries and perform threat modeling with Open Worldwide Application Security Project (OWASP) Top 10.

D.

Analyze MITRE Adversarial Threat Landscape for AI Systems (ATLAS) for tactics, techniques, and procedures (TTPs).

Buy Now
Questions 44

An administrator must conduct generative AI cost monitoring for use in the healthcare industry.

Which of the following criteria is the best way to calculate this cost?

Options:

A.

Connection access and exchange gateway

B.

Encryption and decryption processing

C.

Storage retrieval and prompt processing

D.

Catalog servicing and exchange processing

Buy Now
Questions 45

Which of the following attacks would be the best to automate with AI during dynamic application software testing (DAST)?

Options:

A.

Distributed denial-of-service (DDoS)

B.

Data poisoning

C.

Payload creation

D.

Threat modeling

Buy Now
Questions 46

An organization recently created a custom model that integrates with a language model (LLM). The developer notices that the application programming interface (API) costs have increased.

Which of the following is the best control to reduce cost?

Options:

A.

Implementing prompt templates

B.

Increasing central processing unit (CPU) and memory

C.

Reducing the model size

D.

Adjusting token limits

Buy Now
Questions 47

A developer is selecting authentication controls for an AI system.

Which of the following is the best way to prevent threat actor replay attacks?

Options:

A.

Identity provider (IdP) federation

B.

Secure Shell (SSH)-based certificate authentication

C.

Expiring session tokens

D.

Identity and access management access keys

Buy Now
Exam Code: CY0-001
Exam Name: CompTIA SecAI+ v1 Exam
Last Update: Oct 8, 2026
Questions: 159

PDF + Testing Engine

$59.99 $171.4

Testing Engine

$44.99 $128.55

PDF (Q&A)

$49.99 $142.82