CompTIA SecAI + CY0-001 (V1) Exam Practice Test 5

Reviewed by Editorial Team
The ProProfs editorial team is comprised of experienced subject matter experts. They've collectively created over 10,000 quizzes and lessons, serving over 100 million users. Our team includes in-house content moderators and subject matter experts, as well as a global network of rigorously trained contributors. All adhere to our comprehensive editorial guidelines, ensuring the delivery of high-quality content.
Learn about Our Editorial Process
| By Thames
T
Thames
Community Contributor
Quizzes Created: 11201 | Total Attempts: 9,875,275
| Questions: 25 | Updated: Sep 30, 2026
Please wait...
Question 1 / 26
🏆 Rank #-- ▾
0 %
0/100
Score 0/100

1. An attacker submits carefully crafted queries to a deployed model and, based on subtle differences in the model's responses, determines with high confidence whether a specific individual's medical record was included in the model's original training dataset. Which attack is this?

Explanation

Determining whether a specific individual's record was part of the training dataset, based on subtle response differences, is membership inference. Model inversion reconstructs approximations of training data more broadly rather than confirming one specific record's presence, model theft copies the model itself, model skewing gradually biases behavior, and an output integrity attack tampers with output content rather than inferring training set membership.

Submit
Please wait...
About This Quiz
CompTIA SecAI + Cy0-001 (V1) Exam Practice Test 5 - Quiz

This practice assessment focuses on the CompTIA SecAI + CY0-001 (V1) Exam, evaluating your understanding of essential cybersecurity concepts and skills. It covers areas such as threat detection, incident response, and security architecture, making it highly relevant for those preparing for a career in cybersecurity. Engaging with this material can... see moreenhance your readiness for the certification and deepen your knowledge in the field. see less

2.

What first name or nickname would you like us to use?

You may optionally provide this to label your report, leaderboard, or certificate.

2. A company handling highly regulated financial data establishes specific internal rules governing exactly which categories of sensitive data may ever be used as input to any AI system, and under what approval conditions. Which corporate policy concept does this represent?

Explanation

Specific internal rules governing which sensitive data categories may be used as AI input, and under what conditions, is sensitive data governance. Sanctioned versus unsanctioned tools concerns which tools are approved for use, private versus public models concerns hosting architecture, data sovereignty concerns geographic data residency, and third-party compliance evaluations assess vendor controls rather than internal data-handling rules.

Submit

3. A multinational company aligns its AI development practices with a set of broad, internationally recognized policy principles promoting trustworthy AI, developed through consensus among member countries' governments, distinct from a binding regulation or a technical standard. Which resource is this?

Explanation

OECD standards are broad, internationally recognized policy principles for trustworthy AI developed through consensus among member governments, distinct from a binding regulation or technical standard. The EU AI Act is a binding legal regulation, ISO AI standards are technical standards from a standards body, NIST AIRMF is a specific US voluntary framework, and GDPR governs personal data protection generally rather than AI policy principles specifically.

Submit

4. After deploying an AI-powered hiring tool, a company discovers that the tool systematically ranks resumes from a particular university lower than comparable resumes from other schools, for reasons unrelated to actual qualifications, due to patterns in its training data. Which risk does this represent?

Explanation

Systematically ranking candidates lower for reasons unrelated to actual qualifications, due to training data patterns, is introduction of bias. Accidental data leakage concerns unintended data exposure, reputational loss is a potential downstream consequence rather than the core risk itself, autonomous systems risk concerns unsupervised system action, and shadow AI concerns unauthorized tool adoption rather than describing this specific unfair ranking pattern.

Submit

5. A company's AI governance program specifically evaluates whether a proposed facial recognition system performs with comparable accuracy across people of different skin tones, rather than performing well only for the demographic groups best represented in its training data. Which responsible AI principle is under evaluation?

Explanation

Evaluating whether a system performs comparably across different demographic groups rather than favoring the best-represented ones is fairness. Explainability concerns whether decisions can be understood, consistency concerns stable behavior across repeated identical inputs, differential privacy concerns statistical noise-based data protection, and awareness training concerns educating people rather than evaluating a system's demographic performance parity.

Submit

6. A company creates a role responsible specifically for building and maintaining the pipelines that collect, clean, and structure the raw data used to train AI models, distinct from the person who designs the model itself. Which role is this?

Explanation

Building and maintaining the pipelines that collect, clean, and structure raw data is a data engineer's responsibility. A data scientist designs and analyzes models using that data, an AI architect designs overall system architecture, an MLOps engineer manages deployment pipelines specifically, and an AI risk analyst assesses risk rather than building data infrastructure.

Submit

7. A security team configures an AI-powered testing suite that specifically validates whether a newly retrained fraud-detection model's accuracy and behavior remain within acceptable bounds before it replaces the currently deployed version. Which CI/CD practice is this?

Explanation

Specifically validating a retrained model's accuracy and behavior before it replaces the current version is model testing, distinct from testing traditional application code. Unit testing validates individual code components, software composition analysis checks third-party dependencies, regression testing checks that code changes don't break existing functionality, and code scanning analyzes source code for flaws rather than validating a model's own behavioral performance.

Submit

8. A security team builds an automated pipeline that uses an AI model to scan every new code commit for known vulnerable patterns and outdated dependencies before the code is allowed to merge, without a human manually reviewing every single commit. Which CI/CD practice is this?

Explanation

Automatically scanning every new commit for known vulnerable patterns and outdated dependencies before merge is code scanning. Unit testing validates individual components' correctness, regression testing checks that changes don't break existing functionality, model testing validates AI model behavior specifically, and change management concerns the broader approval and deployment process rather than the specific act of scanning code for vulnerabilities.

Submit

9. An attacker uses an AI system to coordinate thousands of compromised devices, dynamically adjusting the timing and pattern of traffic from each one in real time to maximize the disruptive impact on a target website while evading basic rate-limiting defenses. Which attack does this AI-enhanced coordination support?

Explanation

Coordinating many compromised devices to maximize disruptive impact on a target while evading defenses is a distributed denial of service attack, here enhanced by AI-driven dynamic coordination. Reconnaissance gathers target information, social engineering manipulates people directly, obfuscation hides malicious content from detection, and a honeypot is a defensive decoy rather than an availability attack.

Submit

10. A threat actor sets up a decoy service, populated with AI-generated fake credentials and fabricated internal documents, specifically designed to waste an intruder's time and reveal their techniques once they interact with it. Which concept does this represent?

Explanation

A decoy system populated with fabricated content, designed to waste an intruder's time and reveal their techniques, is a honeypot. Reconnaissance gathers information about a target rather than deploying a decoy, obfuscation hides malicious content from detection, automated data correlation links data points together, and payloads are the actual malicious content delivered in an attack rather than a defensive decoy.

Submit

11. A security team uses an AI system to automatically review thousands of lines of newly committed code, flagging style violations, unused variables, and minor best-practice deviations before a human reviewer looks at the pull request. Which use case is this?

Explanation

Automatically flagging style violations, unused variables, and best-practice deviations in code is code quality and linting. Vulnerability analysis specifically targets security weaknesses rather than general style issues, pattern recognition identifies recurring structures more broadly, threat modeling maps potential attack paths conceptually, and fraud detection targets financial or transactional abuse rather than code style.

Submit

12. A DevOps team integrates an AI tool directly into their deployment pipeline through a standardized protocol that exposes specific internal tools and data sources to the model in a structured way, rather than relying on general-purpose chat. Which category of AI-enabled tool integration does this represent?

Explanation

A standardized protocol exposing specific internal tools and data sources to a model in a structured way is an MCP server. Chatbots and personal assistants provide general conversational interfaces rather than structured tool exposure, and browser and IDE plug-ins integrate into specific applications rather than describing this standardized protocol-based integration approach.

Submit

13. A company integrates a third-party AI plug-in into its internal chat platform, and later discovers the plug-in was built with a flaw that allows it to execute arbitrary commands on the host system whenever it processes a specially crafted message. Which risk category does this represent?

Explanation

A structural flaw in a plug-in's own construction that allows arbitrary command execution is insecure plug-in design. Excessive agency concerns a component being granted too much permitted capability rather than having an architectural flaw, model theft copies the model itself, sensitive information disclosure leaks confidential data through output, and model denial of service targets availability rather than describing a code-level flaw in a plug-in's implementation.

Submit

14. A vendor markets a compact AI model with far fewer parameters than a typical large language model, specifically designed to run efficiently on a smartphone or edge device while still handling common conversational tasks. Which type of AI does this describe?

Explanation

A compact model with far fewer parameters, designed to run efficiently on constrained devices, is a small language model. Large language models are far larger and typically require substantial compute, a GAN involves two competing networks, transformers describe an architecture rather than a size class, and statistical learning is a broader category rather than describing this compact, edge-optimized design specifically.

Submit

15. A security team notices that a large number of near-identical prompts are being submitted to their AI model from many different accounts within a short time window, suggesting a coordinated automated campaign rather than organic individual use. Which monitoring concept would most directly surface this pattern?

Explanation

Detecting a surge of near-identical requests across many accounts in a short window is exactly what rate monitoring is designed to surface. AI cost monitoring tracks spend, log protection secures stored log data, response confidence level tracks the model's own certainty, and data classification labels sensitivity rather than detecting coordinated request volume patterns.

Submit

16. A compliance team specifically checks whether an AI model's outputs remain reliable and correct across a wide range of test inputs, distinct from checking whether the model treats different demographic groups fairly. Which auditing focus area does this represent?

Explanation

Checking whether outputs remain reliable and correct across a wide range of inputs, separate from demographic fairness, is an accuracy audit. Bias and fairness specifically examines disparate treatment across groups, hallucinations concerns fabricated content specifically, access concerns who can use the system, and accountability concerns ownership of outcomes rather than output correctness itself.

Submit

17. A company applying data safety controls decides that its AI system should simply never collect certain categories of highly sensitive data in the first place, such as biometric identifiers, rather than collecting and then protecting them afterward. Separately, for data it does collect, the company de-identifies records so individuals cannot be traced back from the data at all. Which two data safety techniques are described, respectively?

Explanation

Deciding not to collect certain sensitive categories of data at all is data minimization, while de-identifying already-collected records so individuals cannot be traced back is data anonymization. Data masking partially obscures values rather than fully de-identifying them, classification labels tag data by sensitivity without altering collection or identity, and data redaction removes specific content from existing records rather than describing either not collecting data or de-identifying it.

Submit

18. A company encrypts AI training data while it moves between its data lake and the training cluster over the network, and separately encrypts that same data while it sits idle in the data lake's storage volumes. Which two encryption requirements do these two protections represent, respectively?

Explanation

Encrypting data while it moves across the network is encryption in transit, while encrypting it while sitting idle in storage is encryption at rest. Encryption in use protects data while actively being processed rather than moving or sitting idle, and data masking and anonymization alter data values rather than describing encryption states.

Submit

19. A platform team caps the maximum number of tokens a single API call to their AI model can consume, both for the input prompt and the generated response combined, specifically to prevent runaway costs from an unusually long conversation. Which gateway control is this?

Explanation

Capping the combined input and output token count for a single call is specifically a token limit, distinct from rate limits which cap request frequency over time. Input quotas cap raw data size or quantity rather than model-specific token units, modality limits restrict input/output formats, and endpoint access controls govern network-level reachability rather than per-call content volume.

Submit

20. A company wants to make sure that if a user's session token is somehow compromised, the attacker still cannot use it to query the AI model directly, since a separate layer of authentication is required specifically to reach the model itself. Which access control category does this extra layer represent?

Explanation

A separate authentication layer specifically required to query the model itself, independent of broader session validity, is model access control. Data access concerns permissions over underlying datasets, agent access concerns autonomous components, and network/API access and endpoint access controls concern network-layer reachability rather than this model-specific authentication layer.

Submit

21. A model deployment team configures a control that prevents a chatbot from ever recommending specific medical dosages, regardless of how the user phrases their question, by constraining what categories of content the model is allowed to generate in the first place. Which control category is this?

Explanation

Constraining what categories of content a model is allowed to generate at all, such as never recommending medical dosages, is a model guardrail. Rate limits cap request frequency, endpoint access controls govern network reachability, input quotas cap data size or quantity, and modality limits restrict input/output formats rather than restricting output content categories.

Submit

22. A security team wants a general conceptual approach for systematically identifying potential threats to a proposed AI system's architecture during the design phase, before selecting any specific named framework like ATLAS or the OWASP Top 10. Which broader category does this represent?

Explanation

A general conceptual approach for systematically identifying potential threats during design, before selecting any specific named tool, falls under the broader category of threat-modeling frameworks. The CVE AI Working Group and OWASP ML Security Top 10 are specific named resources rather than the general category, the MIT AI Risk Repository catalogs risks broadly, and NIST AIRMF is a specific risk management framework rather than describing threat modeling generically.

Submit

23. Before a new AI model is approved for a specific department's use, stakeholders formally confirm that the model's intended purpose actually supports a documented company priority, rather than being built simply because the technology is available. Which life cycle stage does this confirmation represent?

Explanation

Formally confirming that a model's purpose supports a documented company priority before proceeding is business use case alignment, the earliest life cycle stage. Data collection and model development/selection happen after this alignment is confirmed, deployment happens much later, and monitoring and maintenance is an ongoing post-deployment activity rather than this initial justification step.

Submit

24. A model development team applies a visible or invisible marker to AI-generated images specifically so that the content can later be identified as machine-generated rather than human-created, even after the image has been shared or edited. Which concept does this represent?

Explanation

Embedding a marker specifically to identify content as AI-generated after the fact is watermarking. Data provenance tracks where data originated more broadly, data lineage tracks a dataset's full processing history, data verification confirms accuracy, and RAG retrieves external information to ground model responses rather than marking generated content as machine-made.

Submit

25. A prompt engineer gives a model three separate worked examples of correctly formatted outputs before asking it to handle a new case, while a colleague designs a reusable, structured skeleton with placeholder fields that any user's input can be dropped into before reaching the model. Which two prompt engineering concepts are described, respectively?

Explanation

Providing three separate worked examples before the actual task is multi-shot prompting, while a reusable structured skeleton with placeholder fields is a template. Zero-shot prompting provides no examples at all, system roles assign a persona rather than a reusable input structure, and one-shot prompting provides exactly one example rather than three.

Submit
×
Saved
Thank you for your feedback!
View My Results
Cancel
  • All
    All (25)
  • Unanswered
    Unanswered ()
  • Answered
    Answered ()
An attacker submits carefully crafted queries to a deployed model and,...
A company handling highly regulated financial data establishes...
A multinational company aligns its AI development practices with a set...
After deploying an AI-powered hiring tool, a company discovers that...
A company's AI governance program specifically evaluates whether a...
A company creates a role responsible specifically for building and...
A security team configures an AI-powered testing suite that...
A security team builds an automated pipeline that uses an AI model to...
An attacker uses an AI system to coordinate thousands of compromised...
A threat actor sets up a decoy service, populated with AI-generated...
A security team uses an AI system to automatically review thousands of...
A DevOps team integrates an AI tool directly into their deployment...
A company integrates a third-party AI plug-in into its internal chat...
A vendor markets a compact AI model with far fewer parameters than a...
A security team notices that a large number of near-identical prompts...
A compliance team specifically checks whether an AI model's outputs...
A company applying data safety controls decides that its AI system...
A company encrypts AI training data while it moves between its data...
A platform team caps the maximum number of tokens a single API call to...
A company wants to make sure that if a user's session token is somehow...
A model deployment team configures a control that prevents a chatbot...
A security team wants a general conceptual approach for systematically...
Before a new AI model is approved for a specific department's use,...
A model development team applies a visible or invisible marker to...
A prompt engineer gives a model three separate worked examples of...
play-Mute sad happy unanswered_answer up-hover down-hover success oval cancel Check box square blue
Alert!