Summer Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmas50

CompTIA CY0-001 - CompTIA SecAI+ v1 Exam

Page: 4 / 4
Total 126 questions

A security analyst reviews a recently released chatbot ' s log and discovers that outputs sometimes include personally identifiable information (PII) from other chatbot users.

Which of the following corrective actions should the security analyst take first to resolve this issue?

A.

Take the chatbot offline and restore it from a backup.

B.

Disable memory from the chat history for all users.

C.

Ask all users to refrain from using PII with the chatbot.

D.

Require users to label the sensitivity of their requests.

Which of the following attacks is most enabled by AI-generated content?

A.

Model poisoning

B.

Phishing

C.

Ransomware

D.

Remote code execution

A security analyst is aware of an active penetration test in the environment. The analyst examines SIEM log data and notices the following AI system output:

Which of the following is the vulnerability that has occurred and the control the analyst should implement?

A.

The vulnerability is prompt injection, and the analyst should use endpoint detection response (EDR).

B.

The vulnerability is model hallucinations, and the analyst should develop output validations.

C.

The vulnerability is jailbreaking, and the analyst should utilize role-based access control.

D.

The vulnerability is sensitive information disclosure, and the analyst should employ masking.

E.

The vulnerability is role impersonation, and the analyst should use validation.

A security consultant must summarize the impact of posture management on a machine learning (ML) use case.

Which of the following is the most appropriate reference for this purpose?

A.

Organization for Economic Co-operation and Development (OECD) standards

B.

National Institute of Standards and Technology (NIST) AI Risk Management Framework (RMF)

C.

European Union AI Act

D.

Generative adversarial network (GAN)

A security administrator must implement security controls for AI systems.

Which of the following access controls should the administrator set up first for authentication?

A.

Model

B.

Server

C.

Data

D.

Endpoint

An AI architect reviews AI utilization and wants to improve the user experience.

Which of the following should the architect review within the logs?

A.

Rate monitoring

B.

Model accuracy

C.

Access controls

D.

Data storage

A cybersecurity administrator needs a security mechanism that can validate input.

Which of the following controls should the administrator use?

A.

Prompt firewall

B.

Rate limits

C.

Token limits

D.

Input quantity