[Mar-2026] CompTIA CY0-001 DUMPS WITH REAL EXAM QUESTIONS [Q11-Q30]

Share

[Mar-2026] CompTIA CY0-001 DUMPS WITH REAL EXAM QUESTIONS

2026 New PassLeaderVCE CY0-001 PDF Recently Updated Questions

NEW QUESTION # 11
Which of the following requires developers to harden infrastructure to protect AI systems?

  • A. Configuration standards
  • B. Intake processes
  • C. Acceptable use policies
  • D. Development guidelines

Answer: A

Explanation:
Configuration standards define how infrastructure and systems must be securely set up and maintained. By following these standards, developers harden the environment that supports AI systems, reducing risks from misconfigurations and vulnerabilities.


NEW QUESTION # 12
A penetration tester is assessing the controls of a deployed AI system that is designed to search and return the contents of files. The tester runs the following:

Which of the following is the best control to prevent abuse of the system?

  • A. Adding a large language model (LLM) guardrails library to the application code
  • B. Implementing custom detection rules for anomalous model behavior
  • C. Reducing the privilege scope of the service account
  • D. Segmenting the workload into a separate virtual private cloud (VPC)

Answer: C

Explanation:
The penetration test shows that the system accepts arbitrary commands like deleteBuckets or listPermissions, which could lead to privilege abuse. The most effective control is least privilege, ensuring the service account only has access to what is strictly necessary (e.g., reading files) and not sensitive operations like deleting buckets or altering permissions.


NEW QUESTION # 13
User experience is declining since the launch of a large language model (LLM) in internal networks. Which of the following should be the highest priority for the prompt engineers?

  • A. Customer success management
  • B. Sales life cycle
  • C. Business objectives
  • D. Quality control

Answer: D

Explanation:
When user experience is declining after an LLM launch, the top priority for prompt engineers is quality control. Ensuring prompts produce accurate, relevant, and safe outputs directly improves usability and restores user trust.


NEW QUESTION # 14
A short AI-generated video shows a celebrity's likeness talking about a fake public security event.
Which of the following was used to create this video?

  • A. Convolutional neural network
  • B. Random forest
  • C. Statistical analysis
  • D. Machine learning (ML) classifier

Answer: A

Explanation:
Convolutional neural networks (CNNs) are commonly used in generating deepfake videos, where a person's likeness is realistically mapped and animated to create fake but convincing audiovisual content.


NEW QUESTION # 15
Which of the following is the most concerning risk for a company that allows corporate end users to use public-facing large language models (LLMs)?

  • A. Inaccuracies due to hallucinations
  • B. Out-of-date acceptable use policies
  • C. Malicious code generation
  • D. Data security regulatory violations

Answer: D

Explanation:
The greatest concern with employees using public-facing LLMs is the potential exposure of sensitive or regulated corporate data. Submitting such information to external systems may violate data protection laws (e.g., GDPR, HIPAA), creating legal and compliance risks that outweigh issues like hallucinations or malicious outputs.


NEW QUESTION # 16
A security team is using an AI-based tool to try to bypass organizational boundaries. The team uses AI to look at the current state and suggest different attack vectors based on the outcome of the previous ones. Which of the following techniques is the team most likely using?

  • A. Code quality testing
  • B. Fraud detection
  • C. Manual signature matching
  • D. Automated penetration testing

Answer: D

Explanation:
The described behavior - iteratively assessing the environment and adapting attack paths based on prior outcomes - matches automated penetration testing, where AI-driven tools simulate attack chains and adjust tactics dynamically.


NEW QUESTION # 17
SIMULATION
Instructions
Click the (+) to assign each threat category into its appropriate framework.
If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.
An architect is modeling an agentic system to meet security standards.

Answer:

Explanation:

Explanation:
MAESTRO: Overreliance, Insecure plug-in design
OWASP Top 10: Broken access control, Identification and authentication failures OWASP Top 10 LLM: Prompt injection, Model denial of service STRIDE: Elevation of privilege, Repudiation, Supply chain vulnerabilities, Insecure design MAESTRO addresses AI-specific misuse such as excessive trust in outputs (overreliance) and unsafe plug-in design.
OWASP Top 10 maps to classic web threats: broken access control and authentication failures are key risks.
OWASP Top 10 LLM focuses on LLM-related threats like prompt injection and denial of service targeting the model.
STRIDE categories cover privilege escalation, repudiation (denying actions), supply chain risks, and insecure design flaws.


NEW QUESTION # 18
An AI security administrator notices that the information referenced by the model is incorrectly formatted and missing values. Which of the following job roles would most likely be responsible for correcting this error?

  • A. Data engineer
  • B. AI architect
  • C. Platform engineer
  • D. Machine learning operations (MLOps) engineer

Answer: A

Explanation:
A data engineer is responsible for preparing, cleaning, and formatting data pipelines. When information is incorrectly formatted or missing values, the data engineer ensures data integrity and quality before it is used by AI models.


NEW QUESTION # 19
A security administrator must provide access controls for AI systems to list tables. Which of the following should the administrator implement?

  • A. Agentic AI access
  • B. Data access
  • C. Network access control list (NACL)
  • D. Model access

Answer: B

Explanation:
Since the requirement is to control which users or systems can list tables, the proper control lies at the data access level. Implementing data access controls ensures only authorized entities can view or query the underlying tables used by the AI system.


NEW QUESTION # 20
User experience is declining since the launch of a large language model (LLM) in internal networks. Which of the following should be the highest priority for the prompt engineers?

  • A. Customer success management
  • B. Sales life cycle
  • C. Business objectives
  • D. Quality control

Answer: D

Explanation:
When user experience is declining after an LLM launch, the top priority for prompt engineers is quality control. Ensuring prompts produce accurate, relevant, and safe outputs directly improves usability and restores user trust.


NEW QUESTION # 21
A disgruntled employee changed the company policies that a chatbot references in order to create confusion and disrupt the business. Which of the following AI-generated vulnerabilities is the employee exploiting?

  • A. Data poisoning
  • B. Data masking
  • C. Data leaking
  • D. Data reduction

Answer: A

Explanation:
Altering the source data (policy content) that the chatbot relies on corrupts its knowledge and behavior, which is characteristic of data poisoning attacks.


NEW QUESTION # 22
Customer feedback for an AI chatbot has a high-rate of non-answers, which is causing higher central processing unit (CPU) utilization. Which of the following should be implemented?

  • A. Response confidence level
  • B. Prompt logging
  • C. Guardrails
  • D. Cost monitoring

Answer: A

Explanation:
Implementing a response confidence level ensures the chatbot only provides answers when the model is sufficiently confident. This reduces irrelevant or empty responses, improving user experience and lowering unnecessary CPU utilization.


NEW QUESTION # 23
Faculty members at a university are concerned about potential inherent bias and inconsistency in one department's AI plagiarism detection service.
Which of the following principles will most likely to address their concerns?

  • A. Consistency
  • B. Transparency
  • C. Accountability
  • D. Explainability

Answer: A

Explanation:
Consistency ensures that an AI system applies rules and produces results in a uniform manner across all cases. This principle directly addresses concerns about bias and irregular outcomes in the plagiarism detection service.


NEW QUESTION # 24
Which are indicators of lateral movement? (Choose two.)

  • A. Encrypted outbound traffic to a suspicious domain
  • B. Sudden increase in CPU usage
  • C. Use of Pass-the-Hash techniques
  • D. DNS tunneling traffic
  • E. Repeated SMB login attempts between internal hosts

Answer: C,E

Explanation:
Lateral movement often involves internal SMB attacks and credential reuse.


NEW QUESTION # 25
A global security operations center (SOC) wants to adapt and leverage the strength of AI in order to enhance its security operations. Which of the following is the best way to enhance the global SOC functions?

  • A. Generate code and execute in production to help save time.
  • B. Summarize alerts to easily gain insights on the environment.
  • C. Use open-source models in production to help the efficiency of threat detection and threat analysis.
  • D. Enable a personal assistant that can act in the global SOC with no human intervention.

Answer: B

Explanation:
AI can significantly enhance SOC operations by summarizing and correlating high volumes of alerts, enabling analysts to quickly identify patterns, prioritize threats, and gain actionable insights. This reduces analyst fatigue and improves response times without introducing unsafe automation risks.


NEW QUESTION # 26
Which of the following is the best example of an AI model that is trained to identify multiple points from input using a neural network to provide output for authentication?

  • A. Open Authorization (OAuth)
  • B. Facial recognition
  • C. Encryption key
  • D. Bounding box

Answer: B

Explanation:
Facial recognition uses neural networks to analyze multiple points or features from an input image (such as eyes, nose, mouth, and facial structure) to generate a unique identifier for authentication purposes.


NEW QUESTION # 27
A healthcare organization plans to deploy a chatbot for appointment scheduling and patient records. Which of the following is the first step a security administrator should take?

  • A. Conduct a risk assessment.
  • B. Enable role-based access management
  • C. Use a secure data communication channel for chat.
  • D. Implement prompt firewalls.

Answer: A

Explanation:
Before deploying an AI chatbot that will handle sensitive healthcare data, the first step is to conduct a risk assessment. This identifies potential threats, compliance requirements (such as HIPAA), and security gaps, ensuring proper controls are planned before implementation.


NEW QUESTION # 28
When should containment occur during the incident response lifecycle?

  • A. Immediately after recovery
  • B. Before identification
  • C. Before eradication
  • D. After lessons learned

Answer: C

Explanation:
Containment follows identification and precedes eradication.


NEW QUESTION # 29
A manufacturing company wants to use AI within its operations to improve the efficiency and accuracy of its processes. Which of the following should the organization do first to enable adoption and achieve the business objectives?

  • A. Hire a data and AI architect.
  • B. Select a large language model (LLM).
  • C. Achieve International Organization for Standardization (ISO) 42001 certification.
  • D. Introduce a generative adversarial network (GAN).

Answer: A

Explanation:
The first step in adopting AI to meet business objectives is to establish the right expertise. A data and AI architect can design the overall strategy, infrastructure, and data pipelines needed for effective AI integration, ensuring alignment with operational goals before selecting specific models or certifications.


NEW QUESTION # 30
......

Latest CY0-001 Pass Guaranteed Exam Dumps Certification Sample Questions: https://pass4itsure.passleadervce.com/CompTIA-SecAI/reliable-CY0-001-exam-learning-guide.html