CompTIA CY0-001 - CompTIA SecAI+ Beta Exam
Page: 3 / 26
Total 126 questions
Question #11 (Topic: Exam A)
Which of the following is the best example of an AI model that is trained to identify multiple points from input using a neural network to provide output for authentication?
A. Facial recognition
B. Encryption key
C. Open Authorization (OAuth)
D. Bounding box
Answer: A
Question #12 (Topic: Exam A)
An organization is developing and implementing AI features into a customer service application. Which of the following practices should the organization put the place before releasing the application for customer trials?
A. Data masking and sanitization
B. External compliance audits
C. Approved AI vendor lists
D. Third-party risk management
Answer: A
Question #13 (Topic: Exam A)
An internal user enters a client credit card number into an internal generative machine learning (ML) model:
#User prompt: Customer Jane Doe has a new credit card that she wants to add to her account. The number is 5555-5555-5555-5555
Which of the following is the most effective way to prevent prompt injection attacks against a large language model (LLM)?
#User prompt: Customer Jane Doe has a new credit card that she wants to add to her account. The number is 5555-5555-5555-5555
Which of the following is the most effective way to prevent prompt injection attacks against a large language model (LLM)?
A. Guardrails
B. Antivirus
C. Web application firewall (WAF)
D. Role-based access control
Answer: A
Question #14 (Topic: Exam A)
A security alert triggers an agentic system. An analyst notices the following payload in the logs”

The alert includes multiple shell commands that are not typically run as part of any hardening. Which of the following is the most effective control to implement?

The alert includes multiple shell commands that are not typically run as part of any hardening. Which of the following is the most effective control to implement?
A. Adding logic that includes approved strings before running the shell commands
B. Deprecating model usage and retaining the model with safer parameters
C. Modifying the application to ignore the SECURITY_UPDATE tag
D. Using only approved libraries when interacting with agentic systems
Answer: A
Question #15 (Topic: Exam A)
A global security operations center (SOC) wants to adapt and leverage the strength of AI in order to enhance its security operations. Which of the following is the best way to enhance the global SOC functions?
A. Generate code and execute in production to help save time.
B. Enable a personal assistant that can act in the global SOC with no human intervention.
C. Use open-source models in production to help the efficiency of threat detection and threat analysis.
D. Summarize alerts to easily gain insights on the environment.
Answer: D