ExamDumpster

Free CY0-001 sample questions

Real questions from the CompTIA SecAI+ (Security Artificial Intelligence Plus) practice bank, with the correct answer and an explanation for each one. No junk, no filler.

Try them in the simulator Same questions, with study, timed and flashcard modes.

Showing 6 of 12 free sample questions.

Question 1Choose one

A security architect is designing a generative AI solution for a financial institution that requires strict adherence to data freshness and granular access control. The solution must answer employee queries based on internal policy documents that change weekly. Which architectural approach provides the BEST balance of up-to-date information retrieval and document-level security permissions without requiring frequent, expensive model retraining?

Question 2Choose one

During a threat modeling session for a new LLM-powered customer service chatbot, the security team identifies a risk where an attacker could manipulate the chat history to trick the model into performing unauthorized actions by simulating a conversation that never happened. This specific vulnerability exploits the model's inability to distinguish between system instructions and user input in the context window. Which attack vector does this describe?

Question 3Choose one

An organization is deploying an AI-driven intrusion detection system (IDS). The CISO is concerned that the model might be compromised during the training phase by an insider who subtly alters the training dataset to make the model ignore specific malicious traffic patterns from a certain IP range. Which type of attack is the CISO describing?

Question 4Choose one

A multinational corporation is adopting the NIST AI Risk Management Framework (AI RMF) to govern its deployment of generative AI tools. The governance team is currently defining the policies, processes, and procedures to map, measure, and manage AI risks. Which function of the NIST AI RMF are they primarily executing?

Question 5Choose one

An AI engineer is preparing a dataset for a credit scoring model. To comply with privacy regulations and reduce bias, they must ensure that sensitive attributes like 'race' and 'gender' are not directly used, but they also need to ensure the model doesn't infer these attributes from proxies like 'zip code'. Which data processing technique should be applied to assess and mitigate this specific risk before training?

Question 6Choose one

A security operations center (SOC) is integrating a new AI-assisted tool that uses a Large Language Model (LLM) to summarize security incident logs. To prevent sensitive Personally Identifiable Information (PII) from leaking into the public model used by the vendor, which control should be implemented at the 'Gateway' layer of the architecture?

6 more free samples are waiting

Create a free account to unlock the whole CY0-001 sample bank, or get full access to all 171 practice questions in the simulator.

Create account