CompTIA SecAI + CY0-001 (V1) Exam Practice Test 4

Reviewed by Editorial Team
The ProProfs editorial team is comprised of experienced subject matter experts. They've collectively created over 10,000 quizzes and lessons, serving over 100 million users. Our team includes in-house content moderators and subject matter experts, as well as a global network of rigorously trained contributors. All adhere to our comprehensive editorial guidelines, ensuring the delivery of high-quality content.
Learn about Our Editorial Process
| By Thames
T
Thames
Community Contributor
Quizzes Created: 11201 | Total Attempts: 9,875,275
| Questions: 25 | Updated: Sep 30, 2026
Please wait...
Question 1 / 26
🏆 Rank #-- ▾
0 %
0/100
Score 0/100

1. A company discovers that its AI customer service agent, when asked cleverly worded follow-up questions, sometimes reveals internal pricing formulas and unreleased product details that were present in its training data or connected knowledge base. Which risk does this represent?

Explanation

Revealing confidential internal information like pricing formulas through cleverly worded questions is sensitive information disclosure. Model theft copies the model itself, model denial of service targets availability, insecure plug-in design concerns architectural flaws in integrated plug-ins, and membership inference determines whether specific data was in the training set rather than describing general leakage of confidential business content through conversation.

Submit
Please wait...
About This Quiz
CompTIA SecAI + Cy0-001 (V1) Exam Practice Test 4 - Quiz

This practice assessment focuses on the CompTIA SecAI + CY0-001 (V1) Exam, evaluating critical skills in cybersecurity and artificial intelligence integration. It covers essential concepts such as threat detection, risk management, and security frameworks. This resource is invaluable for learners aiming to enhance their knowledge and prepare effectively for the... see morecertification. see less

2.

What first name or nickname would you like us to use?

You may optionally provide this to label your report, leaderboard, or certificate.

2. A company deploying an internal AI assistant decides that certain highly sensitive legal documents may only be processed by a model hosted entirely within the company's own private infrastructure, never sent to a third-party public API. Which corporate policy concept does this decision represent?

Explanation

Deciding that certain data may only be processed by a privately hosted model rather than a third-party public API is the private versus public models policy concept. Sanctioned versus unsanctioned tools concerns which tools are approved for use generally, data sovereignty concerns geographic data residency, third-party compliance evaluations assess vendor controls, and sensitive data governance is the broader category this specific hosting decision falls under rather than the precise concept being illustrated.

Submit

3. A company operating globally references a voluntary US government framework that provides structured guidance for identifying, assessing, and managing risks throughout the AI system life cycle, without imposing binding legal requirements. Which resource is this?

Explanation

The NIST AI Risk Management Framework is a voluntary US government framework providing structured risk guidance without binding legal force. The EU AI Act is a binding legal regulation, ISO AI standards provide international technical guidance through a different standards body, OECD standards offer broader international policy principles, and GDPR governs personal data protection generally rather than AI risk management specifically.

Submit

4. After deploying a new AI-powered chatbot, a company finds that customers increasingly trust and act on its recommendations without verifying them independently, even in cases where the chatbot's advice turns out to be wrong. Which risk does this represent?

Explanation

Users trusting and acting on AI output without independent verification, even when it is wrong, is overreliance. Excessive agency concerns the AI system itself being granted too much autonomous capability rather than human trust behavior, model skewing concerns gradual bias introduction, shadow AI concerns unauthorized tool adoption, and autonomous systems risk concerns systems acting without human review rather than human trust in a system's advice.

Submit

5. A company invests in training its employees to recognize when an AI system's output should be questioned rather than accepted at face value, as part of a broader effort to build trustworthy AI practices. Which responsible AI principle category does this training effort support?

Explanation

Training employees to appropriately question AI output rather than blindly trust it is awareness training, a responsible AI principle focused on human readiness. Differential privacy is a technical data protection method, consistency concerns stable model behavior, explainability concerns whether decisions can be understood, and inclusiveness concerns fair treatment across diverse user groups rather than employee education specifically.

Submit

6. A company creates a role responsible specifically for designing the overall technical architecture of its AI systems, including how models, data pipelines, and infrastructure components fit together, distinct from the role that builds the automated deployment pipelines. Which role is this?

Explanation

An AI architect designs the overall technical architecture connecting models, data pipelines, and infrastructure. An MLOps engineer builds and maintains the deployment pipelines specifically, a data engineer builds general data infrastructure, an AI governance engineer focuses on policy and compliance structures, and a platform engineer maintains underlying compute platforms rather than the overall AI system architecture.

Submit

7. A citizen-developer with no formal programming background uses a drag-and-drop AI-assisted platform to build a simple internal approval workflow, without writing any traditional code. Which scripting tool category does this represent?

Explanation

Building a workflow entirely through a drag-and-drop interface without writing any traditional code is a no-code approach. Low-code still involves some manual code, even if minimal, CI/CD concerns automated build and deployment pipelines, and unit testing and model testing validate code or model behavior rather than describing how the workflow itself was built.

Submit

8. A SOC configures an AI-powered system that automatically opens, categorizes, and assigns priority levels to incoming security tickets based on their content, routing each to the appropriate team without a human triaging every single ticket manually. Which automation concept is this?

Explanation

Automatically opening, categorizing, and routing security tickets based on content is incident response ticket management. AI agents describes autonomous multi-step actors more broadly, document synthesis and summarization condenses existing content, change management concerns approving and deploying changes, and model testing validates AI model behavior rather than ticket triage specifically.

Submit

9. A ransomware operator uses an AI system to automatically generate hundreds of unique, functionally equivalent variants of the same malware, each with a different code structure, specifically to evade signature-based antivirus detection at scale. Which category of AI-enhanced attack does this represent?

Explanation

Automatically generating many functionally equivalent but structurally different malware variants to evade signature detection is a form of automated attack generation. Adversarial networks refers specifically to GAN-style competing model training, reconnaissance gathers target information, social engineering manipulates people directly, and honeypot evasion concerns avoiding decoy systems rather than generating malware variants at scale.

Submit

10. An attacker uses an AI voice cloning tool trained on a few seconds of a real executive's publicly available speech to generate a convincing fake voicemail instructing an employee to bypass normal approval steps for an urgent payment. Which category of attack does this represent?

Explanation

A synthetically generated voice convincingly impersonating a real executive is deepfake impersonation. Reconnaissance gathers target information rather than generating impersonation content, obfuscation hides malicious content from detection, automated data correlation links data points together, and a honeypot is a defensive decoy rather than an impersonation technique.

Submit

11. A fraud team uses an AI model trained on historical transaction data to flag new transactions that share subtle characteristics with previously confirmed fraudulent cases, even when the specific details differ from any single past case. Which use case is this?

Explanation

Flagging new transactions based on learned characteristics of previously confirmed fraud cases is fraud detection specifically. Anomaly detection flags general deviations from a baseline without necessarily being fraud-specific, signature matching relies on matching known exact patterns, and translation and summarization concern language conversion and content condensation rather than transactional fraud analysis.

Submit

12. A security team deploys a conversational AI tool that security analysts can ask general questions of throughout their workday, such as summarizing a CVE or explaining a suspicious log entry, functioning as an always-available knowledge assistant rather than being embedded in a specific application. Which category of AI-enabled tool is this?

Explanation

An always-available, general-purpose conversational assistant that analysts consult throughout the day, rather than being embedded in one specific application, is a personal assistant. IDE, browser, and CLI plug-ins are embedded within specific applications or environments, and an MCP server exposes structured tool access to a model rather than serving as the conversational assistant itself.

Submit

13. Match each AI attack type to its correct description.

Explanation

A transfer learning attack exploits vulnerabilities in a shared base model that propagate to every downstream task built on it, an output integrity attack tampers with generated output after the fact, insecure output handling fails to validate or sanitize model output before downstream use, and membership inference determines whether a specific record was part of the training set, each representing a distinct point in the AI attack surface.

Submit

14. A data scientist trains a model on unlabeled customer transaction data specifically to discover natural groupings of similar spending behavior, without ever telling the model which group any given transaction belongs to. In a separate project, the team trains a spam filter using thousands of emails that are each explicitly labeled as spam or not spam. Which two model training techniques are described, respectively?

Explanation

Discovering natural groupings in unlabeled data is unsupervised learning, while training on explicitly labeled examples is supervised learning. Reinforcement learning trains through reward signals rather than labels, federated learning concerns decentralized training location, and model validation checks performance rather than describing either of these two training styles.

Submit

15. An attacker crafts a phrase specifically designed to trick a content-moderation AI into classifying clearly harmful content as acceptable, bypassing its safety filters entirely. In a separate incident, an attacker deliberately introduces a subtle pattern into a lending model's training data over time so that applicants from a specific zip code are gradually approved at a lower rate than their actual creditworthiness would justify. Which two attacks are described, respectively?

Explanation

Crafting input specifically to bypass safety filters and misclassify harmful content as acceptable is circumventing AI guardrails, while gradually introducing bias into a model's behavior over time through subtle training data patterns is model skewing. Jailbreaking typically aims to produce prohibited content directly rather than misclassify moderation decisions, model inversion reconstructs training data, and data poisoning is a broader category that model skewing is a specific gradual form of, distinguished here by its slow, incremental nature.

Submit

16. A security team implements strict access controls and encryption specifically around the stored history of AI model queries and responses, recognizing that this log data itself could reveal sensitive business information if it were ever breached. Which monitoring concept does this represent?

Explanation

Applying access controls and encryption to protect stored log data itself from breach is log protection. Log monitoring observes log activity for issues, log sanitization removes sensitive content from logs before storage, rate monitoring tracks request frequency, and prompt monitoring observes live query and response content rather than securing the stored log data itself.

Submit

17. A security team wants to track, over time, how many requests per minute their AI model's API is receiving, specifically to detect a sudden spike that might indicate an automated scraping or abuse attempt. Which monitoring concept is this?

Explanation

Tracking requests per minute to detect a sudden spike indicating scraping or abuse is rate monitoring. AI cost monitoring tracks spend, response confidence level tracks the model's own certainty, log sanitization removes sensitive data from stored logs, and prompt monitoring observes query and response content rather than raw request frequency.

Submit

18. A company tags every dataset used in its AI pipeline with a label indicating whether it contains public information, internal-only information, or highly restricted personal data, so downstream systems can apply appropriate handling rules automatically. Which data safety technique is this?

Explanation

Tagging datasets by sensitivity level so downstream systems can apply appropriate handling automatically is data classification labeling. Anonymization removes identifiers, masking partially obscures values, redaction removes specific content entirely, and data minimization limits how much data is collected in the first place rather than labeling existing data by sensitivity.

Submit

19. A company wants to ensure that a third-party AI agent integrated into its customer support platform can only read ticket data relevant to the specific conversation it is handling, and cannot query the entire historical ticket database at will. Which access control category does this restriction represent?

Explanation

Restricting what an autonomous agent is permitted to act on, such as limiting it to only the current conversation's data, is agent access. Model access concerns who may query the model itself, data access concerns broader data permissions not scoped to a specific autonomous actor, and network/API access and endpoint access controls concern network-layer reachability rather than the agent's scope of action.

Submit

20. A company restricts which specific network zones and IP ranges are allowed to reach its AI model's inference endpoint at all, entirely independent of any authentication that happens afterward. Which gateway control is this?

Explanation

Restricting which network zones or IP ranges can reach an endpoint at all, independent of downstream authentication, is an endpoint access control. Rate limits cap request frequency, token limits cap content volume, modality limits restrict input/output formats, and prompt firewalls filter prompt content rather than controlling network-level reachability.

Submit

21. A company deploys a filtering layer in front of its AI model specifically designed to detect and block known malicious prompt patterns, such as attempts to extract the system prompt, before they ever reach the model itself. Which gateway control is this?

Explanation

A filtering layer specifically designed to detect and block known malicious prompt patterns before they reach the model is a prompt firewall. Rate limits cap request frequency, token limits cap content volume, modality limits restrict input/output formats, and input quotas cap data size or quantity rather than filtering for malicious content patterns specifically.

Submit

22. A security team wants a broad, curated inventory of AI-specific risks spanning technical, ethical, and societal categories, developed by a leading academic research institution, to help structure their organization's own risk assessment process. Which resource fits this description?

Explanation

The MIT AI Risk Repository is a broad, curated inventory of AI risks spanning technical, ethical, and societal categories from an academic research institution. MITRE ATLAS focuses on adversarial tactics specifically, the OWASP LLM Top 10 focuses narrowly on LLM application vulnerabilities, the CVE AI Working Group tracks formally disclosed vulnerabilities, and NIST AIRMF is a US government risk management framework rather than an academic risk catalog.

Submit

23. After a new fraud-detection model has been running in production for several months, the team collects cases where the model's predictions turned out to be wrong and uses that information to inform the next round of retraining. Which life cycle stage does this represent?

Explanation

Collecting real-world outcomes, including incorrect predictions, and using them to inform the next round of retraining is feedback and iteration. Data preparation and model development/selection happen earlier in the life cycle before deployment, business use case alignment happens at the very start, and model evaluation happens against a held-out test set rather than live production feedback specifically.

Submit

24. A team preparing training data for a computer vision model artificially creates additional training images by rotating, flipping, and adjusting the brightness of existing photos, without collecting any new real-world images. Which data processing technique is this?

Explanation

Creating additional synthetic training examples by transforming existing data, such as rotating or adjusting brightness of images, is data augmentation. Data balancing adjusts the proportion of classes represented, data cleansing fixes errors, data lineage tracks history, and data verification confirms accuracy rather than generating new synthetic examples.

Submit

25. A prompt engineer designs a system message that explicitly tells the model to respond as a formal, cautious legal assistant rather than a casual conversational chatbot, shaping its tone and behavior for the entire session. Which prompt engineering concept does this represent?

Explanation

Explicitly assigning a persona, such as a formal legal assistant, that shapes tone and behavior for the whole session is a system role. User prompts are the actual questions a person types, and one-shot, multi-shot, and zero-shot prompting describe how many examples are provided rather than assigning an overall persona.

Submit
×
Saved
Thank you for your feedback!
View My Results
Cancel
  • All
    All (25)
  • Unanswered
    Unanswered ()
  • Answered
    Answered ()
A company discovers that its AI customer service agent, when asked...
A company deploying an internal AI assistant decides that certain...
A company operating globally references a voluntary US government...
After deploying a new AI-powered chatbot, a company finds that...
A company invests in training its employees to recognize when an AI...
A company creates a role responsible specifically for designing the...
A citizen-developer with no formal programming background uses a...
A SOC configures an AI-powered system that automatically opens,...
A ransomware operator uses an AI system to automatically generate...
An attacker uses an AI voice cloning tool trained on a few seconds of...
A fraud team uses an AI model trained on historical transaction data...
A security team deploys a conversational AI tool that security...
Match each AI attack type to its correct description.
A data scientist trains a model on unlabeled customer transaction data...
An attacker crafts a phrase specifically designed to trick a...
A security team implements strict access controls and encryption...
A security team wants to track, over time, how many requests per...
A company tags every dataset used in its AI pipeline with a label...
A company wants to ensure that a third-party AI agent integrated into...
A company restricts which specific network zones and IP ranges are...
A company deploys a filtering layer in front of its AI model...
A security team wants a broad, curated inventory of AI-specific risks...
After a new fraud-detection model has been running in production for...
A team preparing training data for a computer vision model...
A prompt engineer designs a system message that explicitly tells the...
play-Mute sad happy unanswered_answer up-hover down-hover success oval cancel Check box square blue
Alert!