CompTIA certification preparation

CY0-001 Practice Questions

Practice exam-style questions, check your answers, and review explanations and source references where they are available.

Exam
CY0-001
Provider
CompTIA
Full set
484 questions
Last Update Check
Social media backlash occurs after a customer-facing LLM produces biased medical advice, leading to a significant drop in user trust and brand equity. The incident highlights a failure in the organization's AI TRiSM strategy during the deployment of Generative AI tools. Which of the following actions BEST addresses the long-term mitigation of this Reputational Loss?
Answer options
Integrating Generative AI (GenAI) and LLMs into high-interaction Honeypots allows security teams to create dynamic, realistic environments that can fool sophisticated automated attackers. These AI-enhanced traps must be carefully monitored to prevent them from becoming a liability. Which of the following are the PRIMARY benefits of using AI-driven honeypots for defense against automated attacks? (Select TWO)
Answer options

Evaluating the core tenets of Responsible AI requires a clear understanding of the components that constitute a transparent system. Consider the following items:

I. Interpretability: The ability to explain the technical mechanics of a model. II. Traceability: The capability to track the data and processes used to develop the model. III. Obfuscation: The process of making the model's internal weights unreadable to protect Intellectual Property. IV. Disclosure: Providing notification to users that they are interacting with an AI system. Which of the following combinations represent the primary components of Transparency?

Answer options
Establishing a robust security baseline for the MLOps pipeline involves several cross- functional responsibilities. An AI Security Architect is collaborating with the Data Science team to integrate Security by Design into the development of a new financial fraud detection model. The architect needs to ensure that the infrastructure supporting the Jupyter environment and the automated CI/CD workflows are resilient against supply chain attacks. Which TWO of the following actions should the AI Security Architect prioritize? (Choose TWO.)
Answer options

Evaluate the following statements regarding the MITRE ATLAS (Adversarial Threat Landscape for Artificial-Intelligence Systems) framework:

I. It is modeled after the MITRE ATT&CK framework structure to facilitate cross-domain threat analysis. II. It includes tactics such as ML Model Access and Exfiltration to describe AI-specific attack goals. III. It focuses solely on the defense of Generative AI and Large Language Models (LLMs). Which of the following combinations is correct?

Answer options
Implementing AI-powered security plugins into a developer's IDE (Integrated Development Environment) aims to bridge the gap between development and security. By integrating these tools directly into the workflow, organizations can address vulnerabilities earlier in the lifecycle. Which of the following are the primary benefits of using AI-enabled IDE plugins for security facilitation? (Choose TWO)
Answer options

Consider the following activities performed during the Monitoring and Maintenance stage of the AI security life cycle:

I. Identifying Model Drift via performance metrics. II. Updating model weights through scheduled Retraining. III. Patching vulnerabilities in the Virtual Container environment. IV. Implementing Data Sanitization on the initial training set. Which of these activities are correctly associated with the Monitoring and Maintenance phase?

Answer options
Configuring a secure Large Language Model (LLM) for automated log analysis requires establishing high-level instructions that dictate the model's persona and safety boundaries. During the development of a security-focused chatbot, the team needs to ensure the model remains in "analyst mode" and refuses to provide administrative credentials, even if a user attempts to bypass standard filters. Which of the following approaches BEST utilizes the provided architecture to enforce these behavioral constraints?
Answer options
Inconsistent security protocols across various departments have resulted in multiple data leaks during the fine-tuning of decentralized models in Jupyter environments. To address these vulnerabilities and the lack of standardized Risk Management, executive leadership decides to implement a centralized governance structure. The primary objective is to harmonize AI Security policies and provide technical guidance for all machine learning initiatives within the organization. Which of the following organizational structures is BEST suited to provide this centralized leadership and standardization?
Answer options
Securing autonomous robotic systems in a manufacturing facility requires a strict adherence to Reliability and Safety standards to prevent physical injury to workers. A Lead AI Architect is reviewing the deployment of a vision-based obstacle avoidance system. The architect must ensure the system remains resilient against Out-of-Distribution (OOD) data and hardware malfunctions. Which of the following controls directly support the Reliability and Safety of this AI system? (Choose TWO.)
Answer options
Question 1 of 10

Source context

How this practice set is maintained

Maintained by the CertMage content team, this page loads questions from the exam dataset connected to its preparation resource. When an answer includes a supporting reference, it is shown with that answer so you can review the underlying vendor documentation.

Certification objectives, interfaces, and vendor services can change. Verify important details against the provider's current exam guide and documentation before your exam.

Scroll to Top