CompTIA SecAI + CY0-001 (V1) Exam Practice Test 2

Reviewed by Editorial Team
The ProProfs editorial team is comprised of experienced subject matter experts. They've collectively created over 10,000 quizzes and lessons, serving over 100 million users. Our team includes in-house content moderators and subject matter experts, as well as a global network of rigorously trained contributors. All adhere to our comprehensive editorial guidelines, ensuring the delivery of high-quality content.
Learn about Our Editorial Process
| By Thames
T
Thames
Community Contributor
Quizzes Created: 11201 | Total Attempts: 9,875,275
| Questions: 25 | Updated: Sep 30, 2026
Please wait...
Question 1 / 26
🏆 Rank #-- ▾
0 %
0/100
Score 0/100

1. An attacker embeds hidden instructions inside a document that a company's AI assistant is asked to summarize, and when the assistant processes the document, it silently follows the embedded instructions instead of just summarizing the content, without the user ever typing those instructions directly. Which attack is this?

Explanation

Hidden instructions embedded within content the model processes, rather than typed directly by the user, that the model then follows is an indirect form of prompt injection. Jailbreaking typically involves a user directly crafting input to bypass safety guardrails, model theft steals the model itself, membership inference determines whether specific data was used in training, and excessive agency concerns an AI system being granted more autonomous capability than appropriate rather than describing this specific injection technique.

Submit
Please wait...
About This Quiz
CompTIA SecAI + Cy0-001 (V1) Exam Practice Test 2 - Quiz

This practice assessment focuses on the CompTIA SecAI + CY0-001 (V1) Exam, evaluating your knowledge in cybersecurity principles, risk management, and security architecture. It is designed to help learners prepare effectively for the certification, ensuring a solid understanding of key concepts in the cybersecurity domain.

2.

What first name or nickname would you like us to use?

You may optionally provide this to label your report, leaderboard, or certificate.

2. A company hosting its AI model's training data must ensure that data collected from European customers remains stored and processed only within data centers physically located in the EU, per contractual and regulatory requirements. Which compliance concept does this requirement represent?

Explanation

Data sovereignty concerns legal requirements that data be stored and processed within specific geographic or jurisdictional boundaries, exactly as described with EU customer data. Third-party compliance evaluations assess vendor controls, sanctioned versus unsanctioned tools concerns internal approval status, private versus public models concerns model deployment architecture, and NIST AIRMF is a specific voluntary risk framework rather than a geographic data residency requirement.

Submit

3. A company discovers that its AI code-generation tool sometimes reproduces snippets that closely match licensed proprietary code from its training data, creating potential legal exposure if used in a commercial product. Which risk category does this represent?

Explanation

Reproducing licensed proprietary code creates a direct intellectual property risk, since using such output commercially could infringe on someone else's rights. Reputational loss and accidental data leakage are different potential consequences of AI risk generally, and bias introduction and autonomous systems risk describe unrelated risk categories.

Submit

4. A company evaluating a new AI vendor requires proof of an independently audited report confirming the vendor's security, availability, and confidentiality controls meet a recognized trust services framework before signing a contract. Which compliance concept does this requirement represent?

Explanation

Requiring an independently audited report of a vendor's controls before contracting is a third-party compliance evaluation. Data sovereignty concerns where data is legally allowed to reside, sanctioned versus unsanctioned tools concerns internal approval status, EU AI Act compliance is a specific regional legal requirement, and NIST AIRMF alignment is a specific voluntary framework rather than the general practice of vendor compliance review.

Submit

5. A company's AI ethics review board specifically evaluates whether a proposed model's decision-making process can be clearly explained to affected customers, rather than functioning as an opaque black box. Which responsible AI principle is under review?

Explanation

Evaluating whether a model's decisions can be clearly explained, rather than functioning as a black box, is explainability. Differential privacy concerns protecting individual data through statistical noise, consistency concerns stable behavior across similar inputs, fairness concerns equitable treatment across groups, and awareness training concerns educating people rather than the model's own interpretability.

Submit

6. A company creates a formal role responsible specifically for reviewing AI systems against internal and external requirements, verifying that documentation, testing, and controls meet expectations before and after deployment. Which role is this?

Explanation

An AI auditor specifically reviews AI systems against requirements, verifying documentation, testing, and controls before and after deployment. An AI risk analyst assesses and prioritizes risk rather than performing formal compliance review, a platform engineer builds underlying infrastructure, a data engineer builds data pipelines, and an AI architect designs system architecture rather than auditing it.

Submit

7. A security operations team configures an autonomous AI component that can independently investigate a triggered alert, gather supporting evidence from multiple systems, and open a fully documented incident ticket without a human initiating each step. Which automation concept does this represent?

Explanation

An autonomous component that independently investigates, gathers evidence, and takes multi-step action without a human initiating each step is an AI agent. Low-code scripting describes a development approach rather than autonomous action, document synthesis condenses existing content, automated deployment/rollback concerns pushing or reverting changes, and unit testing validates individual code components.

Submit

8. A security team builds a low-code workflow that uses an AI model to automatically read incoming vulnerability scan reports, extract the key findings, and draft a plain-language summary for a weekly leadership briefing, without any developer writing custom code. Which AI automation concept does this represent?

Explanation

Automatically extracting key findings from reports and drafting a plain-language summary is document synthesis and summarization. AI agents describes autonomous multi-step actors more broadly, change management concerns approving and deploying changes, incident response ticket management handles case tracking, and model testing validates AI model behavior rather than summarizing external reports.

Submit

9. A threat actor uses an AI writing tool to generate a large volume of convincing but entirely fabricated news articles about a competitor, timed to spread through social media ahead of a product launch, with the specific intent to deceive the public. Which category of AI-generated content attack is this?

Explanation

Deliberately fabricated content spread with intent to deceive is disinformation, distinguished from misinformation, which is false content spread without necessarily intending to deceive. Impersonation involves posing as a specific real person or entity, reconnaissance gathers target information, and social engineering manipulates people directly rather than describing this content-fabrication campaign.

Submit

10. Attackers use an AI system to rapidly cross-reference leaked credential dumps, social media profiles, and corporate org charts to automatically build detailed target profiles for a planned spearphishing campaign. Which AI-enhanced attack vector category does this represent?

Explanation

Rapidly cross-referencing disparate data sources to automatically build detailed target profiles is automated data correlation. Obfuscation hides malicious content from detection, a honeypot is a defensive decoy, adversarial networks refers to GAN-style competing model training, and distributed denial of service targets availability rather than building target profiles.

Submit

11. A SOC uses an AI model trained on months of historical network traffic to flag a sudden, unusual pattern of internal data transfers that doesn't match any previously known attack signature. Which use case does this represent?

Explanation

Flagging unusual patterns that deviate from a learned baseline, without matching a known signature, is anomaly detection. Signature matching relies on known patterns, translation converts between languages, summarization condenses content, and fraud detection specifically targets financial or transactional abuse rather than describing general network traffic anomalies.

Submit

12. A security analyst uses a command-line AI assistant integrated directly into their terminal to help generate and refine a complex regular expression for parsing suspicious log entries during an active investigation. Which category of AI-enabled tool is this?

Explanation

An AI assistant integrated directly into a terminal environment is a CLI plug-in. An IDE plug-in integrates into a code editor rather than a terminal, a browser plug-in integrates into web browsing, a chatbot is typically a standalone conversational interface, and an MCP server exposes tool access to a model rather than being the terminal-integrated assistant itself.

Submit

13. A company discovers that an AI agent integrated with its email and calendar systems was granted the ability to autonomously send emails and schedule meetings on a user's behalf, far beyond what its original intended function of drafting email replies actually required. Which risk category does this represent?

Explanation

Granting an AI agent autonomous capability far beyond what its actual intended function requires is excessive agency. Overreliance describes humans trusting AI output too much rather than the agent having too much capability, model skewing gradually biases model behavior, insecure plug-in design concerns flaws in how a plug-in is built rather than how much capability it was granted, and an output integrity attack tampers with output content rather than describing over-permissioning.

Submit

14. A model development team wants to periodically retrain a fraud-detection model using data collected directly from thousands of individual banks' own local devices, without any raw transaction data ever leaving each bank's own infrastructure. Which model training technique fits this constraint?

Explanation

Federated learning trains a shared model across many decentralized devices or organizations without raw data ever leaving its original location, exactly matching this constraint. Supervised and unsupervised learning describe how labels are used during training rather than where data resides, reinforcement learning trains through reward signals, and transfer learning reuses a pretrained model on a new task rather than describing decentralized training.

Submit

15. An audit of a customer service chatbot's outputs over the past month finds several confidently worded responses that reference product features and policies the company has never actually offered. Which auditing focus area does this finding fall under?

Explanation

Confidently worded but entirely fabricated details, such as referencing product features that don't exist, is the definition of hallucinations. Bias and fairness concerns disparate treatment across groups, access concerns who can use the system, and accuracy and accountability are broader or related but less precisely descriptive of this specific fabrication pattern than hallucinations.

Submit

16. Before storing chatbot conversation logs long-term for later analysis, a team runs an automated process that strips out any credit card numbers or social security numbers that users may have accidentally typed into the chat. Which activity is this?

Explanation

Automatically stripping sensitive data like credit card or social security numbers from logs before long-term storage is log sanitization. Log monitoring observes log activity for issues, log protection secures logs from unauthorized access or tampering, prompt monitoring observes live query and response content, and rate monitoring tracks request volume rather than removing sensitive content from stored logs.

Submit

17. A finance department notices that its monthly bill for a third-party AI API has spiked significantly, and investigates how much of that increase is driven specifically by the storage of conversation history versus the actual per-query processing charges. Which monitoring concept covers this investigation?

Explanation

Breaking down spend across categories like storage, prompts, and processing is specifically AI cost monitoring. Rate monitoring tracks request volume rather than dollar cost, log monitoring tracks log activity broadly, response confidence level tracks model certainty, and prompt monitoring observes query and response content rather than billing breakdowns.

Submit

18. A company processing highly sensitive AI training data removes direct identifiers like names and social security numbers so records can no longer be tied back to specific individuals at all, while for a separate reporting use case it instead partially obscures credit card numbers, showing only the last four digits. Which two data safety techniques are described, respectively?

Explanation

Removing direct identifiers so records can no longer be tied to specific individuals at all is data anonymization, while partially obscuring a value like a credit card number while retaining some visible portion is data masking. Classification labels tag data by sensitivity level rather than altering values, data minimization limits how much data is collected in the first place, and data redaction typically removes content entirely rather than partially obscuring it.

Submit

19. A company wants to ensure that a contractor working on an AI project can query the deployed model to test its responses, but cannot directly access the underlying training dataset stored in a separate data lake. Which two access control categories does this scenario primarily distinguish between?

Explanation

This scenario distinguishes model access, which governs the ability to query the deployed model, from data access, which governs the ability to reach the underlying training data, granting one without the other. Agent access concerns autonomous components rather than a human contractor, and network access and endpoint access describe connectivity layers rather than this specific query-versus-data-access distinction.

Submit

20. A multimodal AI system is configured to accept text input only and explicitly reject any attempt to submit image or audio data, even though the underlying model is technically capable of processing those formats. Which gateway control does this configuration represent?

Explanation

Restricting which input or output formats, such as text versus image or audio, are permitted is a modality limit. Rate limits cap request frequency, token limits cap content volume per call, input quotas cap the size or quantity of a given input type, and prompt firewalls filter malicious prompt content rather than restrict which data formats are accepted at all.

Submit

21. A platform team configures a control that automatically rewrites a user's raw prompt into a standardized, pre-approved structure before it reaches the model, ensuring consistent formatting and reducing the chance of malicious instructions being embedded. Which model control does this represent?

Explanation

Automatically rewriting user input into a standardized, pre-approved structure before it reaches the model is the use of prompt templates, a form of model guardrail. Model evaluation assesses overall model performance, rate limits cap request volume, endpoint access controls govern who can reach the API, and input quotas cap the size or quantity of input rather than restructuring its format.

Submit

22. A security team wants a single, categorized reference specifically listing the most critical vulnerability categories unique to applications built on large language models, such as prompt injection and insecure output handling, distinct from general web application vulnerabilities. Which resource fits this need?

Explanation

The OWASP LLM Top 10 specifically catalogs the most critical vulnerability categories unique to LLM-based applications, such as prompt injection. MITRE ATLAS catalogs adversary tactics and techniques rather than a top-vulnerability list, the MIT AI Risk Repository catalogs AI risks broadly, the CVE AI Working Group tracks formally disclosed vulnerabilities, and NIST AIRMF is a risk management framework rather than a vulnerability list.

Submit

23. During the deployment stage of an AI model's life cycle, the team specifically evaluates whether the model performs consistently when moved from the controlled test environment into the live production environment with real user traffic. Which life cycle stage does this evaluation most directly belong to?

Explanation

Validation specifically confirms the model performs as expected once moved into its real, live operating context, distinct from evaluation, which happens earlier against test data. Deployment is the act of releasing the model itself, monitoring and maintenance is the ongoing tracking that follows validation, and data preparation happens much earlier in the life cycle.

Submit

24. A data engineering team runs an automated process that checks a newly ingested dataset for missing values, duplicate records, and formatting inconsistencies before it is used for model training. Which data processing activity is this?

Explanation

Checking for and correcting missing values, duplicates, and formatting inconsistencies is data cleansing. Data lineage tracks a dataset's history, data provenance tracks its origin and ownership, data balancing adjusts class distribution, and data augmentation creates synthetic variations rather than fixing quality issues in existing records.

Submit

25. A team preparing a large pretrained language model for a specialized legal use case reduces the model's overall parameter count by removing weights that contribute little to its output, and separately converts the remaining weights from 32-bit to 8-bit precision to shrink the model's memory footprint. Which two fine-tuning techniques do these two steps represent, respectively?

Explanation

Removing weights that contribute little to the model's output is pruning, while converting weight precision to a lower bit-width to shrink memory footprint is quantization. Epoch adjustment concerns how many passes through the training data occur, federated learning concerns decentralized training location, and data augmentation creates synthetic training examples rather than modifying the trained model's own weights.

Submit
×
Saved
Thank you for your feedback!
View My Results
Cancel
  • All
    All (25)
  • Unanswered
    Unanswered ()
  • Answered
    Answered ()
An attacker embeds hidden instructions inside a document that a...
A company hosting its AI model's training data must ensure that data...
A company discovers that its AI code-generation tool sometimes...
A company evaluating a new AI vendor requires proof of an...
A company's AI ethics review board specifically evaluates whether a...
A company creates a formal role responsible specifically for reviewing...
A security operations team configures an autonomous AI component that...
A security team builds a low-code workflow that uses an AI model to...
A threat actor uses an AI writing tool to generate a large volume of...
Attackers use an AI system to rapidly cross-reference leaked...
A SOC uses an AI model trained on months of historical network traffic...
A security analyst uses a command-line AI assistant integrated...
A company discovers that an AI agent integrated with its email and...
A model development team wants to periodically retrain a...
An audit of a customer service chatbot's outputs over the past month...
Before storing chatbot conversation logs long-term for later analysis,...
A finance department notices that its monthly bill for a third-party...
A company processing highly sensitive AI training data removes direct...
A company wants to ensure that a contractor working on an AI project...
A multimodal AI system is configured to accept text input only and...
A platform team configures a control that automatically rewrites a...
A security team wants a single, categorized reference specifically...
During the deployment stage of an AI model's life cycle, the team...
A data engineering team runs an automated process that checks a newly...
A team preparing a large pretrained language model for a specialized...
play-Mute sad happy unanswered_answer up-hover down-hover success oval cancel Check box square blue
Alert!