Browse all practice questions for the CompTIA SecAI+ (CY0-001) Practice Exam. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

Ace the CompTIA SecAI+ 2026 Exam – Become a Cybersecurity Superstar! course image
All questions

These questions are part of the practice quiz. Start practicing

  • In federated learning, what security concern is specifically addressed by secure aggregation?
  • What are key defenses for securing AI inference endpoints?
  • What is an approach to monitor for data leakage from memorized training data?
  • What is one of the main uses of a virtual private cloud (VPC)?
  • What does VPC stand for in cloud computing?
  • Which is an AI-specific step in incident response?
  • What does SOAR mean in cybersecurity?
  • What does 'IP' refer to in the context of AI systems?
  • What does the term 'IDE' stand for in the context of AI systems?
  • In applying STRIDE to an AI endpoint, which activity helps reduce tampering risk?
  • Differentiate white-box, black-box, and gray-box testing in AI security with an example.
  • SQL is primarily used for what purpose?
  • Which of the following describes the primary function of ITSM?
  • What role does red team testing play in AI security, and which scenario illustrates it?
  • Which security control is most appropriate for the Data collection stage in a secure ML lifecycle?
  • Which pairing correctly matches a common defense against adversarial examples with its limitation?
  • What is the purpose of a sandbox environment?
  • What does the process of model extraction involve?
  • What does excessive agency refer to in the context of AI systems?
  • What does SCA stand for in software development?
  • What is the difference between data drift and concept drift in AI security?
  • Data lineage refers to which of the following?
  • What type of attack involves a backdoor-like scenario with AI models?
  • What is the main benefit of customer relationship management systems?
  • What does ITSM encompass regarding AI services?
  • What is a privacy impact assessment (PIA) and when should it be conducted for AI projects?
  • Which statement about anomaly detection in SecAI+ is most accurate?
  • In data protection, why is data minimization significant?
  • Data redaction is used for which purpose?
  • What is a key focus of the security frameworks provided by NIST?
  • Which of the following best describes AI-driven systems?
  • What is the purpose of a Security Operations Center (SOC)?
  • What is federated learning and what security concerns accompany it?
  • Which organization publishes top security risks for applications?
  • Compare homomorphic encryption-based inference with encrypted inference using secure enclaves.
  • Dynamic Application Security Testing (DAST) focuses on which aspect of application security?
  • What is an adversarial example and how can an attacker exploit it in inference?
  • What does RMF stand for in the context of risk management?
  • What is 'jailbreaking' in the context of AI models?
  • What is typically a characteristic of a virtual private cloud (VPC)?
  • What type of behavior can data poisoning cause within AI models?
  • What does the acronym RAG stand for in the context of AI?
  • What aspect of AI does Intellectual Property (IP) relate to?
  • Which of the following is an AI-specific step in incident response?
  • What are AI supply chain risks related to external datasets and pre-trained models?
  • What does audit trails enable in AI security monitoring?
  • What does data leakage in model outputs mean and how can it occur in practice?
  • Which of the following can be a consequence of insecure output handling?
  • What is data minimization in AI, and how does it reduce risk?
  • How should organizations address ethics, bias, and fairness in SecAI+?
  • Which type of environment is an IDE primarily used for?
  • What is confidential computing in the context of SecAI+ and where is it useful?
  • In the context of software security, what does 'embeddeding' refer to in a RAG pipeline?
  • What does tool/function calling allow a model to do?
  • Which approach helps address both data drift and concept drift in a deployed AI system?
  • What is a primary characteristic of NoSQL databases?
  • What organization is represented by the acronym NIST?
  • What does SLM stand for in the context of language models?
  • What is one of the key aspects of the Risk Management Framework (RMF)?
  • Which of the following best describes AI-backed APIs?
  • What is the primary purpose of a RAG pipeline?
  • What is a Trojan attack in the context of AI?
  • What does CI/CD stand for in software development?
  • What is local differential privacy and how is it different from global DP?
  • Why is it important to monitor use of Shadow AI in organizations?
  • What is the primary use of machine learning models in AI?
  • What is the role of the OECD regarding AI principles?
  • Data minimization is a principle aimed at what goal?
  • Which option is NOT a commonly cited defense against adversarial examples?
  • What does MSSP stand for in cybersecurity?
  • Why is the concept of overreliance a concern in AI technology?
  • What is a backdoor attack in ML and how does trigger-based activation differ from natural triggers?
  • What is data anonymization used for in AI systems?
  • What does ITIL stand for in the context of IT service management?
  • Which practice supports ongoing monitoring in SecAI+ risk management?
  • AI supply chain risks include backdoors in models or data.
  • What is explainable AI (XAI) and how does it contribute to SecAI+?
  • What is the purpose of the Common Vulnerabilities and Exposures (CVE) catalog?
  • How can secure deployment of AI models be achieved through image provenance and container security?
  • What does provenance refer to in data management?
  • Managed Security Service Providers typically offer what type of support?
  • What defines supervised learning in machine learning?
  • Which feature does tool/function calling enhance in AI models?
  • Which statement best describes differential privacy in SecAI+?
  • What term describes a confident but inaccurate AI output that can mislead users?
  • What is a membership inference attack and what data leakage risk does it pose?
  • What is prompt injection?
  • What does data masking accomplish in a security context?
  • What does SIEM stand for?
  • Which platform is known for graph database management?
  • Which of the following options correctly identifies a privacy-preserving ML technique that operates on decentralized devices with local data and shares only updates?
  • What should be included in AI system logging for effective security monitoring?
  • What does OAuth stand for in cybersecurity?
  • What is a plausible characteristic of a true membership inference risk during model access?
  • In the context of SQL, what does 'querying' refer to?
  • What is a primary function of a Network Access Control List (NACL)?
  • Memorization of training data in models pose privacy risks; how can it be mitigated?
  • What is the primary purpose of a vector database?
  • Which elements should model governance include?
  • How does DAST improve application security?
  • What does overreliance on AI refer to?
  • What is a data poisoning attack and how can you detect it?
  • Which of the following options best describes model inversion?
  • What does PII stand for in data protection?
  • What issue arises from insecure output handling in AI?
  • What role does SIEM play in security?
  • What does the Software Development Life Cycle (SDLC) encompass?
  • Which of the following describes the role of SOAR in cybersecurity operations?
  • What is rate limiting used for in web applications?
  • In a SecAI+ risk assessment for a healthcare product, which combination best captures essential focus areas?
  • How would you approach a SecAI+ risk assessment for a new AI-enabled healthcare product?
  • What does TLS stand for and its main purpose?
  • What does it mean when an input is termed 'benign' in AI?
  • Which is a key objective of secure ML lifecycle?
  • What is Neo4j primarily used for?
  • What does SOC 2 focus on concerning its audit standards?
  • What does a backdoor refer to in AI models?
  • What does AI stand for?
  • What is a guardrail in the context of AI systems?
  • Common Weakness Enumeration (CWE) is primarily used for what purpose?
  • Which metric is used to evaluate AI security beyond traditional accuracy?
  • How does the governance of PII affect AI training models?
  • What does reinforcement learning primarily involve?
  • What type of scenarios often benefit from the use of small language models (SLM)?
  • What is the role of a CDN in AI applications?
  • Explain model stealing attacks and a countermeasure.
  • What is a significant advantage of using TLS?
  • What does CPU stand for in computing?
  • What is the significance of a vector database in AI?
  • Which of the following best defines unsupervised learning?
  • Which organization is known for issuing standards related to AI?
  • What is the primary function of EDR in cybersecurity?
  • What is a Command-line Interface (CLI)?
  • What is the main characteristic of federated learning?
  • In ML backdoor attacks, triggers can be what?
  • What is SSH mainly used for?
  • Which of the following best describes Natural Language Processing (NLP)?
  • What does OWASP focus on?
  • Which choice explains the term 'malicious model behavior'?
  • Differentiate between data poisoning and model poisoning in an AI system, and give an example of each.
  • What is a supply chain attack in the context of AI?
  • What is the primary goal of explainable AI (XAI) in SecAI+?
  • What is PCI DSS concerned with?
  • Explainability and transparency play what roles in SecAI+, and why are they important?
  • Which security control is most critical during deployment to protect inference endpoints?
  • Which of the following best describes the concept of retrieval-augmented generation?
  • What is the primary purpose of the OECD?
  • What does data poisoning involve?
  • In the STRIDE threat model, which threat category describes an attacker presenting forged credentials to access the AI service?
  • What is the primary objective of model evaluation?
  • What does CRM stand for in the context of business systems?
  • What is the purpose of AI threat modeling in SecAI+ and which lifecycle stages should it cover?
  • In the context of a WAF, what types of traffic does it primarily scrutinize?
  • What is the purpose of an API in software development?
  • What is the function of a GPU in AI and ML workloads?
  • What is meant by 'token limit' in AI systems?
  • What is ATLAS in the context of AI security?
  • What role does a CPU play in AI workloads?
  • Why is data provenance and lineage critical for SecAI+ and what elements should it include?
  • What is label poisoning and how can it affect model quality?
  • What is the function of a Web Application Firewall (WAF)?
  • What is meant by the term Shadow AI?
  • What is the purpose of embedding in AI systems?
  • Which mitigation technique is used to defend against prompt injection?
  • What does fine-tuning involve in machine learning?
  • Name a risk management framework commonly referenced in AI security and its relevance to SecAI+.
  • What is a model inversion attack and what risk does it pose?
  • Why is CI/CD for ML a security concern and what practices mitigate it?
  • What does a Web Application Firewall primarily protect against?
  • Which security concern is most closely associated with the Training stage of the AI lifecycle?
  • What regulatory aspect does PCI DSS address in relation to AI?
  • Unsupervised learning refers to which type of learning?
  • What is an adversarial example in the context of AI?
  • Which privacy-preserving ML techniques are commonly used in SecAI+ and what are their trade-offs?
  • Which of the following statements about anomaly detection in SecAI+ is most accurate?
  • Which components define effective data retention and deletion for AI systems?
  • Which defensive technique against prompt injection focuses on separating user input from system prompts?
  • Which process is associated with discovering patterns without labeled data?
  • Which IAM practice is foundational for securing access to AI models and data?
  • Explain differential privacy in ML and how it mitigates privacy risks.
  • When is adversarial training most effective?
  • What is just-in-time access in IAM for SecAI+?
  • What role do standards from the International Organization for Standardization (ISO) play in AI?
  • What does ETL stand for in data processing?
  • What type of attack does DoS refer to?
  • What best describes feedback loops in threat modeling for AI systems?
  • Which of the following questions best describes the purpose of rate limiting at AI inference endpoints?
  • What is prompt injection in AI chatbots and how can it be mitigated?
  • What is policy-as-code in the context of SecAI+ and give an example?
  • What does model drift refer to in the context of AI?
  • Which is a defense technique against prompt injection in chat assistants?
  • Which type of database is categorized as NoSQL?
  • In AI, what does the term 'Agent' refer to?
  • What is the purpose of hallucination monitoring in AI systems?
  • Which term describes the act of inferring sensitive attributes from a model's output?
  • What is a prompt template?
  • Which statement about rate limiting at AI inference endpoints is correct?
  • What is a key feature of Jupyter?
  • How does differential privacy limit the privacy risk in ML models, and what is a typical trade-off?
  • What does DDoS stand for in cybersecurity?
  • What is the function of a prompt firewall?
  • What does auditability mean in SecAI+ and how is it achieved?
  • Define a backdoor attack in machine learning and provide a scenario.
  • What is data provenance and why is it important for auditability in SecAI+?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy