Free CY0-001 sample questions
Real questions from the CompTIA SecAI+ (Security Artificial Intelligence Plus) practice bank, with the correct answer and an explanation for each one. No junk, no filler.
Try them in the simulator Same questions, with study, timed and flashcard modes.
Showing 6 of 12 free sample questions.
During a threat modeling session for a new LLM-powered customer service chatbot, the security team identifies a risk where an attacker could manipulate the chat history to trick the model into performing unauthorized actions by simulating a conversation that never happened. This specific vulnerability exploits the model's inability to distinguish between system instructions and user input in the context window. Which attack vector does this describe?
An organization is deploying an AI-driven intrusion detection system (IDS). The CISO is concerned that the model might be compromised during the training phase by an insider who subtly alters the training dataset to make the model ignore specific malicious traffic patterns from a certain IP range. Which type of attack is the CISO describing?
A multinational corporation is adopting the NIST AI Risk Management Framework (AI RMF) to govern its deployment of generative AI tools. The governance team is currently defining the policies, processes, and procedures to map, measure, and manage AI risks. Which function of the NIST AI RMF are they primarily executing?
An AI engineer is preparing a dataset for a credit scoring model. To comply with privacy regulations and reduce bias, they must ensure that sensitive attributes like 'race' and 'gender' are not directly used, but they also need to ensure the model doesn't infer these attributes from proxies like 'zip code'. Which data processing technique should be applied to assess and mitigate this specific risk before training?
A security operations center (SOC) is integrating a new AI-assisted tool that uses a Large Language Model (LLM) to summarize security incident logs. To prevent sensitive Personally Identifiable Information (PII) from leaking into the public model used by the vendor, which control should be implemented at the 'Gateway' layer of the architecture?
6 more free samples are waiting
Create a free account to unlock the whole CY0-001 sample bank, or get full access to all 171 practice questions in the simulator.