CompTIA SecAI + CY0-001 (V1) Exam Practice Test 3

Reviewed by Editorial Team
The ProProfs editorial team is comprised of experienced subject matter experts. They've collectively created over 10,000 quizzes and lessons, serving over 100 million users. Our team includes in-house content moderators and subject matter experts, as well as a global network of rigorously trained contributors. All adhere to our comprehensive editorial guidelines, ensuring the delivery of high-quality content.
Learn about Our Editorial Process
| By Thames
T
Thames
Community Contributor
Quizzes Created: 11201 | Total Attempts: 9,875,275
| Questions: 25 | Updated: Sep 30, 2026
Please wait...
Question 1 / 26
🏆 Rank #-- ▾
0 %
0/100
Score 0/100

1. An attacker submits a large volume of computationally expensive queries to a company's AI model specifically to exhaust its processing capacity and make it unresponsive to legitimate users. Which attack is this?

Explanation

Overwhelming a model's processing capacity with expensive queries to make it unresponsive is model denial of service. Model theft copies the model itself, sensitive information disclosure leaks confidential data through outputs, an output integrity attack tampers with output correctness, and insecure plug-in design concerns architectural flaws in integrated plug-ins rather than a volumetric availability attack.

Submit
Please wait...
About This Quiz
CompTIA SecAI + Cy0-001 (V1) Exam Practice Test 3 - Quiz

This assessment focuses on the CompTIA SecAI + CY0-001 (V1) Exam, evaluating essential cybersecurity concepts and skills. It covers topics such as risk management, security architecture, and incident response, making it a valuable resource for learners preparing for the certification. Understanding these areas is crucial for anyone looking to advance... see moretheir career in cybersecurity. see less

2.

What first name or nickname would you like us to use?

You may optionally provide this to label your report, leaderboard, or certificate.

2. A company drafts an internal policy explicitly stating that employees may use a specific approved AI writing assistant for drafting internal documents, but may not use any other AI tool that has not gone through security review. Which corporate policy concept does this represent?

Explanation

Explicitly designating which AI tools are approved for use versus which are not is the sanctioned versus unsanctioned tools policy concept. Private versus public models concerns model deployment and hosting architecture, sensitive data governance concerns handling rules for sensitive data specifically, data sovereignty concerns geographic data residency, and third-party compliance evaluations assess vendor controls rather than internal tool approval status.

Submit

3. A company deploys a fully autonomous AI trading system that executes trades without any human review of individual transactions, and later struggles to explain exactly why the system made a particular high-risk trade during a market anomaly. Which risk category does this scenario primarily illustrate?

Explanation

A fully autonomous system acting without human review, later difficult to explain, illustrates the autonomous systems risk category specifically. Accidental data leakage concerns unintended data exposure, reputational loss is a potential downstream consequence rather than the core risk category itself, shadow AI concerns unauthorized tool adoption, and bias introduction concerns unfair treatment rather than unexplainable autonomous decision-making.

Submit

4. A company evaluating a new AI vendor requirement specifically checks whether the vendor's model was trained and will continue to operate consistently across repeated runs with the same input, avoiding erratic or unpredictable variation in output for identical queries. Which responsible AI principle is this checking?

Explanation

Checking that a model behaves predictably and stably across repeated runs with the same input is consistency. Explainability concerns whether decisions can be understood, inclusiveness concerns fair treatment across diverse user groups, fairness concerns equitable outcomes across groups, and accountability concerns clear ownership of outcomes rather than output stability across repeated identical queries.

Submit

5. An organization documents formal, written expectations for how employees should evaluate, approve, and use AI tools company-wide, distinct from the informal norms that may have existed before. Which organizational structure does this represent?

Explanation

Formal, written expectations for evaluating, approving, and using AI tools are AI policies and procedures. An AI Center of Excellence is the coordinating body that often produces such policies rather than the documents themselves, an AI governance engineer and AI security architect are individual roles, and a platform engineer builds infrastructure rather than writing governance documentation.

Submit

6. A company creates a formal internal role specifically responsible for identifying, assessing, and prioritizing the risks a given AI system poses to the organization before and during its deployment. Which role is this?

Explanation

An AI risk analyst specifically identifies, assesses, and prioritizes the risks a given AI system poses. An AI architect designs system architecture, an MLOps engineer builds deployment pipelines, a data engineer builds data infrastructure, and a platform engineer maintains underlying compute platforms rather than performing formal risk assessment.

Submit

7. As part of a CI/CD pipeline, an AI-assisted test suite automatically re-runs a full battery of previously passing tests every time new code is merged, specifically to catch cases where a new change accidentally breaks something that used to work. Which CI/CD practice is this?

Explanation

Re-running previously passing tests to catch cases where new changes break existing functionality is regression testing. Unit testing validates individual components in isolation rather than checking for newly introduced breakage across the whole suite, software composition analysis checks third-party dependencies, model testing validates AI model behavior specifically, and code scanning analyzes source code for flaws rather than re-running a full prior test battery.

Submit

8. A DevOps team configures a pipeline so that if an AI-monitored deployment causes error rates to spike beyond a defined threshold, the system automatically reverts to the previous stable version without waiting for a human to notice and intervene. Which concept does this represent?

Explanation

Automatically reverting to a previous stable version when error rates spike, without waiting for human intervention, is automated deployment/rollback. AI-assisted approvals concern pre-deployment sign-off decisions, code scanning and unit testing analyze code before deployment, and document synthesis condenses content rather than managing live deployment state.

Submit

9. An attacker uses an AI system to rapidly generate and test many variations of a network-based exploit against a target's firewall configuration, automatically identifying which specific ports and protocols are vulnerable to a coordinated flood before launching the actual attack. Which category of AI-enhanced attack vector does the discovery portion of this activity represent?

Explanation

Automatically identifying which specific ports and protocols are vulnerable before launching an attack is attack vector discovery, a component of automated attack generation. Payloads and malware generation refer to creating the actual malicious content or code, honeypot evasion concerns avoiding decoy systems, and reconnaissance is a broader information-gathering activity distinct from this specific vulnerability-discovery step.

Submit

10. Security researchers observe an increase in phishing emails that show none of the typical grammar mistakes or awkward phrasing that previously helped users spot them, because attackers are now using AI writing tools to polish their messages. Which AI-enhanced attack vector does this best illustrate?

Explanation

AI-polished phishing content that better manipulates human targets by removing the usual red flags is an enhancement of social engineering. Reconnaissance gathers information about a target rather than crafting the deceptive message itself, obfuscation hides malicious code from technical detection, automated data correlation links data points together, and a honeypot is a defensive decoy rather than an attack technique.

Submit

11. A security team deploys an AI system that automatically attempts a range of common exploitation techniques against a staging environment, adapting its approach based on what it discovers, to identify exploitable weaknesses before a human tester begins. Which use case does this represent?

Explanation

Automatically attempting and adapting exploitation techniques to identify weaknesses is automated penetration testing. Vulnerability analysis typically identifies weaknesses without actively exploiting them, pattern recognition identifies recurring structures generally, threat modeling maps potential attack paths conceptually, and code quality and linting checks code style and correctness rather than actively attempting exploitation.

Submit

12. A developer working inside their code editor uses an integrated AI feature that suggests security fixes directly within the file they are editing, without switching to a separate application. Which category of AI-enabled tool is this?

Explanation

An AI feature integrated directly into a code editor is an IDE plug-in. A browser plug-in integrates into web browsing, a CLI plug-in integrates into a terminal, and a personal assistant and chatbot are typically standalone conversational interfaces rather than embedded directly within a code editing environment.

Submit

13. In one incident, an attacker embeds a hidden trigger directly into a model's weights during training so that the model behaves normally on virtually all inputs but produces a specific malicious output whenever it encounters a secret trigger pattern chosen by the attacker. In a separate incident, an attacker disguises a fully malicious model as a legitimate, benign-looking pretrained model uploaded to a public model repository, waiting for unsuspecting developers to download and deploy it. Which two attacks are described, respectively?

Explanation

A hidden trigger embedded into model weights that activates malicious behavior only under a specific attacker-chosen pattern is a backdoor attack, while disguising a fully malicious model as a legitimate one to trick developers into downloading it is a trojan attack. Model skewing gradually biases behavior over time rather than embedding a discrete trigger, model inversion reconstructs training data, and membership inference determines whether specific data was used in training.

Submit

14. A research team trains a model to play a complex strategy game by having it take actions in a simulated environment and receive positive or negative signals based on the outcomes of those actions, gradually improving its strategy over millions of games. Which training technique is this?

Explanation

Learning through trial and error via reward or penalty signals from an environment is reinforcement learning. Supervised learning requires labeled examples, unsupervised learning finds patterns without labels, federated learning concerns decentralized training location, and model validation checks performance rather than describing this reward-driven training process itself.

Submit

15. An attacker gains unauthorized access to a company's proprietary trained model file and deploys a copy of it on their own infrastructure to offer a competing service, without ever needing to retrain or reconstruct the model from scratch. Which attack is this?

Explanation

Directly stealing and redeploying the actual trained model file is model theft. Model inversion reconstructs training data from model behavior rather than stealing the model file itself, membership inference determines whether specific data was in the training set, model skewing gradually biases behavior over time, and a transfer learning attack abuses a shared base model across tasks rather than directly copying a proprietary model.

Submit

16. A security team wants to continuously watch the actual queries users send to a deployed AI model and the responses it generates, specifically to catch attempts at extracting sensitive information through carefully worded questions. Which monitoring concept covers this?

Explanation

Continuously watching both the queries sent and the responses generated is prompt monitoring, covering both the query and response side. Rate monitoring tracks request volume, AI cost monitoring tracks spend, log protection secures stored logs from tampering, and response confidence level tracks the model's own certainty rather than the content of queries and responses.

Submit

17. A compliance team reviewing an AI model's audit trail specifically checks two things: whether the model's average response time has stayed within acceptable limits under increased load, and separately whether only authorized roles were able to query a sensitive internal knowledge base connected to the model. Which two auditing focus areas do these two checks represent, respectively?

Explanation

Checking whether only authorized roles could query the sensitive knowledge base is specifically an access audit. Response time under load is more accurately a performance or rate monitoring concern than one of the four named auditing focus areas of hallucinations, accuracy, bias/fairness, and access, so only the access half of this scenario maps cleanly to an auditing focus area; the performance-monitoring half falls under a different, operational monitoring category instead.

Submit

18. A company applying data safety controls to a customer service transcript dataset wants to completely remove all mentions of customers' home addresses before the data is used for any purpose, rather than partially obscuring or replacing them with a placeholder. Which technique best fits this specific goal?

Explanation

Completely removing specific sensitive content, such as a home address, rather than partially obscuring or replacing it, is data redaction. Data masking partially obscures a value while keeping some visible portion, anonymization removes identifiers while potentially retaining other content, classification labels tag data by sensitivity without altering it, and data minimization limits what is collected in the first place rather than removing existing content.

Submit

19. A company wants to ensure that even employees with valid model access credentials cannot retrieve or export the raw training dataset used to build a proprietary internal model. Which access control category most directly addresses this concern?

Explanation

Restricting who can retrieve or export the underlying training dataset, separate from who can query the model itself, is data access control. Model access concerns querying the deployed model, agent access concerns autonomous components, and network/API access and endpoint access controls concern network-layer reachability rather than dataset export permissions specifically.

Submit

20. Before allowing a new AI model version into production, a team runs it against a held-out benchmark dataset to measure its accuracy, precision, and recall compared to the previous version. Which model control does this represent?

Explanation

Measuring a model's accuracy, precision, and recall against a benchmark before production release is model evaluation. Model guardrails constrain runtime output behavior rather than benchmark performance, prompt firewalls filter malicious input, and rate limits and endpoint access controls govern request volume and API reachability rather than model performance assessment.

Submit

21. A platform team wants to cap the total amount of data, measured in megabytes, that can be included in a single request sent to their AI model's API, separate from limiting how many requests can be sent per minute. Which gateway control does this represent?

Explanation

Capping the data size of a single request is an input quota, specifically limiting data size rather than request frequency. Rate limits cap requests per time window, token limits cap content volume in model-specific token units rather than raw data size, modality limits restrict input/output formats, and endpoint access controls govern who can reach the API at all.

Submit

22. A security team wants a single authoritative catalog specifically tracking formally disclosed, numbered vulnerabilities affecting popular AI frameworks and libraries, similar in structure to how traditional software vulnerabilities are tracked. Which resource fits this need?

Explanation

The CVE AI Working Group specifically extends the formal, numbered CVE vulnerability tracking system to AI frameworks and libraries. MITRE ATLAS catalogs adversary tactics rather than individual disclosed vulnerabilities, the OWASP ML Security Top 10 lists common ML vulnerability categories rather than numbered disclosures, the MIT AI Risk Repository catalogs broad AI risks, and generic threat-modeling frameworks are not a specific vulnerability tracking catalog.

Submit

23. A retrieval-augmented generation system converts a large internal knowledge base into numerical representations that capture semantic meaning, then stores them in a specialized database optimized for similarity search, so relevant passages can be retrieved to ground the model's responses. Which two RAG components does this process use, respectively?

Explanation

Converting text into numerical representations capturing semantic meaning is creating embeddings, and storing them in a database optimized for similarity search is vector storage, the two core components of a RAG pipeline. Fine-tuning and quantization modify a model's own weights, watermarking and data lineage concern provenance tracking, and data augmentation and balancing concern training data preparation rather than retrieval infrastructure.

Submit

24. A team preparing a dataset for a document classification model converts scanned invoices, which have no consistent fixed fields, into a format that still retains some organizational tags like sender and date but doesn't follow a rigid table schema. Which data type does this represent?

Explanation

Data with some organizational tags or metadata but without a rigid, fixed schema is semi-structured data. Structured data follows a strict, consistent schema like a database table, unstructured data has no organizational tags at all such as raw free text, and vector data and embedded data are not standard data type classifications in this objective's list.

Submit

25. A prompt engineer configures a chatbot with an initial instruction that defines its persona, tone, and behavioral boundaries before any user ever types a message, and separately, the actual question a customer types into the chat window. Which two prompt engineering concepts do these represent, respectively?

Explanation

The initial instruction defining persona, tone, and boundaries before any user interaction is a system prompt, while the actual question a customer types is a user prompt. One-shot prompting concerns providing a single example, templates concern standardized input structure, and system roles concern assigning a persona label rather than describing the full initial instruction set itself.

Submit
×
Saved
Thank you for your feedback!
View My Results
Cancel
  • All
    All (25)
  • Unanswered
    Unanswered ()
  • Answered
    Answered ()
An attacker submits a large volume of computationally expensive...
A company drafts an internal policy explicitly stating that employees...
A company deploys a fully autonomous AI trading system that executes...
A company evaluating a new AI vendor requirement specifically checks...
An organization documents formal, written expectations for how...
A company creates a formal internal role specifically responsible for...
As part of a CI/CD pipeline, an AI-assisted test suite automatically...
A DevOps team configures a pipeline so that if an AI-monitored...
An attacker uses an AI system to rapidly generate and test many...
Security researchers observe an increase in phishing emails that show...
A security team deploys an AI system that automatically attempts a...
A developer working inside their code editor uses an integrated AI...
In one incident, an attacker embeds a hidden trigger directly into a...
A research team trains a model to play a complex strategy game by...
An attacker gains unauthorized access to a company's proprietary...
A security team wants to continuously watch the actual queries users...
A compliance team reviewing an AI model's audit trail specifically...
A company applying data safety controls to a customer service...
A company wants to ensure that even employees with valid model access...
Before allowing a new AI model version into production, a team runs it...
A platform team wants to cap the total amount of data, measured in...
A security team wants a single authoritative catalog specifically...
A retrieval-augmented generation system converts a large internal...
A team preparing a dataset for a document classification model...
A prompt engineer configures a chatbot with an initial instruction...
play-Mute sad happy unanswered_answer up-hover down-hover success oval cancel Check box square blue
Alert!