Skip to content

CompTIA SecAI+ (Security Artificial Intelligence Plus) Practice Questions

Prepare for CY0-001 with more than an answer.

171 questions in the full set12 sample questionsUpdated Mar 12, 2026
Exam fee
$359 USD
Level
Expansion
Valid for
3 years
Domains covered on the exam 4
  1. Basic AI Concepts Related to Cybersecurity17%
  2. Securing AI Systems40%
  3. AI-Assisted Security24%
  4. AI Governance, Risk, and Compliance19%
  1. 1

    A financial company uses an AI model to detect fraudulent transactions. Attackers have begun sending a series of transactions specifically crafted to determine the exact threshold at which the model flags a transaction as fraud, essentially reverse-engineering the decision boundary. This is an example of which type of attack?

    Show answer details

    Correct answer: A

    In a Model Extraction or Oracle Attack, the attacker queries the model (the oracle) with various inputs to analyze the outputs (confidence scores or decisions). By mapping inputs to outputs, they can reconstruct the model's logic, parameters, or decision boundaries, effectively stealing the model's intellectual property.

  2. 2

    True or False: In the context of the EU AI Act, a 'High Risk' AI system is strictly prohibited from being deployed within the European Union.

    Show answer details

    Correct answer: B

    False. Under the EU AI Act, 'High Risk' systems (like those used in critical infrastructure, employment, or credit scoring) are permitted but are subject to strict obligations regarding data quality, documentation, transparency, human oversight, and robustness. Only 'Unacceptable Risk' systems (like social scoring or real-time remote biometric identification in public spaces) are prohibited.

  3. 3

    Case Study:

    GlobalHealth Corp is building a diagnostic AI tool using a Large Language Model (LLM) fine-tuned on patient records. The system architecture involves:

    1. A web portal for doctors to input patient symptoms.
    2. An API gateway handling authentication.
    3. A backend service that queries the fine-tuned LLM.
    4. A vector database storing anonymized medical research papers for RAG.

    The CISO requires that no patient data persists in the model logs and that the model cannot be tricked into revealing other patients' data.

    Which combination of controls addresses these specific requirements?

    Show answer details

    Correct answer: A

    To prevent patient data persistence in logs, a zero-retention policy ensures inputs are discarded after processing. To prevent the model from revealing other patients' data (Model Inversion/Extraction from training data), Differential Privacy during fine-tuning adds noise to the gradients, mathematically guaranteeing that the model output cannot be used to determine if a specific individual's data was in the training set.

  4. 4

    A security architect is designing a generative AI solution for a financial institution that requires strict adherence to data freshness and granular access control. The solution must answer employee queries based on internal policy documents that change weekly. Which architectural approach provides the BEST balance of up-to-date information retrieval and document-level security permissions without requiring frequent, expensive model retraining?

    Show answer details

    Correct answer: B

    Retrieval-Augmented Generation (RAG) allows the system to fetch the most current data from an external source (vector database) at query time. By integrating Access Control Lists (ACLs) at the retrieval layer, the system ensures users only receive answers based on documents they are authorized to view. Fine-tuning is computationally expensive, introduces latency in knowledge updates, and makes granular access control difficult since knowledge is baked into the model weights.

  5. 5

    During a threat modeling session for a new LLM-powered customer service chatbot, the security team identifies a risk where an attacker could manipulate the chat history to trick the model into performing unauthorized actions by simulating a conversation that never happened. This specific vulnerability exploits the model's inability to distinguish between system instructions and user input in the context window. Which attack vector does this describe?

    Show answer details

    Correct answer: B

    Prompt Injection occurs when an attacker inputs malicious instructions that the LLM interprets as system commands rather than data, effectively overriding the intended behavior. This exploits the 'context window' where user data and system instructions often coexist.

  6. 6

    An organization is deploying an AI-driven intrusion detection system (IDS). The CISO is concerned that the model might be compromised during the training phase by an insider who subtly alters the training dataset to make the model ignore specific malicious traffic patterns from a certain IP range. Which type of attack is the CISO describing?

    Show answer details

    Correct answer: B

    Data Poisoning involves corrupting the training data to compromise the model's behavior. By injecting specific bad data (backdoors) during training, an attacker can teach the model to misclassify specific inputs (like ignoring traffic from a specific IP) while functioning normally for other inputs.

Create an account to continue.