Summer Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmas50

CompTIA CY0-001 - CompTIA SecAI+ v1 Exam

Page: 4 / 4
Total 134 questions

An organization is developing and implementing AI features into a customer service application.

Which of the following practices should the organization put in place before releasing the application for customer trials?

A.

Data masking and sanitization

B.

External compliance audits

C.

Approved AI vendor lists

D.

Third-party risk management

Which of the following provides guidance on AI-specific compliance?

A.

Organisation for Economic Co-operation and Development (OECD)

B.

International Organization for Standardization (ISO) 27001

C.

Payment Card Industry Data Security Standard (PCI DSS)

D.

General Data Protection Regulation (GDPR)

A line of business wants to onboard an application that uses a custom AI model for employee assessments. The Chief Information Officer (CIO) agrees to allow the engagement to proceed but first wants a threat model.

Which of the following is the most appropriate to use for an AI threat model?

A.

Responsible AI

B.

Adversarial Threat Landscape for AI Systems (ATLAS)

C.

Organization for Economic Co-operation and Development (OECD)

D.

International Organization for Standardization (ISO)

Which of the following controls is the best way to mitigate a denial-of-service (DoS) attack?

A.

Model guardrails

B.

Rate limiting

C.

End-to-end encryption

D.

Access controls

After the latest software update, a developer receives reports that the system no longer requires reauthentication to display account balances because this issue was present in a previous release. Which of the following should the developer do to best mitigate the risk of recurrence?

A.

Ensure that AI approvals are required to push changes into production.

B.

Implement AI regression testing into the continuous integration/continuous deployment (CI/CD) pipeline.

C.

Deploy an AI-assisted change management system to schedule and track feature releases.

D.

Use code commit automation to perform AI-assisted static application security testing (SAST) scans.

A data set containing medical information is put into a machine learning (ML) model that is designed to predict specific illnesses for a population. In the process of verifying the reliability of the system, the compliance officer realizes that the system cannot reliably predict illnesses for certain segments of the population.

Which of the following types of risk is most applicable to this case?

A.

Bias

B.

Consistency

C.

Transparency

D.

Inclusiveness

A security alert triggers an agentic system. An analyst notices the following payload in the logs. The alert includes multiple shell commands that are not typically run as part of any hardening:

Which of the following is the most effective control to implement?

A.

Adding logic that includes approved strings before running the shell commands

B.

Deprecating model usage and retaining the model with safer parameters

C.

Modifying the application to ignore the SECURITY_UPDATE tag

D.

Using only approved libraries when interacting with agentic systems

A security analyst receives an alert about an AI system and is investigating the following output:

Which of the following is the most appropriate control the analyst should recommend?

A.

Integrating data sanitization

B.

Implementing user input validation

C.

Monitoring logs for attack words from the system

D.

Hardening the Model Context Protocol server

A user interface engineer adds new graphics to the latest release of an AI-integrated application. During the update, the engineer accidentally causes the model to retrain on unverified data. After the update, the model begins to return many errors.

Which of the following is the best way to mitigate future errors?

A.

Web application firewall

B.

Role-based access control

C.

Model development life cycle

D.

Generative adversarial network

An architect is creating a threat model for an agentic system.

Which of the following should the architect do first?

A.

Apply compensating controls based on exposure findings.

B.

Identify the trust boundary between the components.

C.

Calculate the risk to resources based on data sensitivity.

D.

Scan for vulnerabilities from the Open Worldwide Application Security Project (OWASP) Top 10.