CompTIA CY0-001 Exam Prep
CompTIA SecAI+ (Page 16 )

Updated On: 1-Oct-2026

A financial organization implements a new AI-based fraud detection system to flag suspicious transactions. A security analyst discovers that it occasionally blocks legitimate transactions.
Which of the following is the best recommendation?

  1. Retaining the model with more data and recent transaction patterns
  2. Implementing AI token usage and rate limits
  3. Encrypting all the data processed by AI and applying further access controls
  4. Rolling back the model and using a traditional fraud detection system

Answer(s): A

Explanation:

False positives occur when the AI model lacks sufficient or representative training data. Retraining the model with more diverse and recent transaction patterns improves accuracy, reducing the chance of legitimate transactions being incorrectly flagged.



Which of the following technologies is used in deepfake?

  1. Generative adversarial network (GAN)
  2. Multi-shot prompting
  3. Prompt engineering
  4. Transfer learning

Answer(s): A

Explanation:

Deepfakes are primarily created using GANs, where two neural networks (a generator and a discriminator) compete to produce highly realistic synthetic media, such as manipulated videos or images.



During the selection of a machine learning (ML)-based threat classification model, a cybersecurity administrator verifies that label distribution is highly unbalanced.
Which of the following processing techniques should the engineer use to balance the model?

  1. Data lineage
  2. Data augmentation
  3. Data provenance
  4. Data verification

Answer(s): B

Explanation:

When label distribution is highly unbalanced, data augmentation generates additional synthetic samples for the underrepresented classes. This balances the dataset, improving the ML model’s ability to classify threats accurately across all categories.



A healthcare organization plans to deploy a chatbot for appointment scheduling and patient records.
Which of the following is the first step a security administrator should take?

  1. Implement prompt firewalls.
  2. Enable role-based access management
  3. Conduct a risk assessment.
  4. Use a secure data communication channel for chat.

Answer(s): C

Explanation:

Before deploying an AI chatbot that will handle sensitive healthcare data, the first step is to conduct a risk assessment. This identifies potential threats, compliance requirements (such as HIPAA), and security gaps, ensuring proper controls are planned before implementation.



Which of the following helps in managing potential security issues related to model training?

  1. National Institute of Standards and Technology (NIST) AI Risk Management Framework (RMF)
  2. International Organization for Standardization (ISO) 27001
  3. Organization for Economic Co-operation and Development (OECD)
  4. General Data Protection Regulation (GDPR)

Answer(s): A

Explanation:

The NIST AI RMF provides structured guidance for identifying, assessing, and managing risks specific to AI systems, including those arising during model training. It addresses issues like bias, security, and data integrity, making it the best framework for managing training-related security concerns.



Viewing page 16 of 31
Viewing questions 76 - 80 out of 149 questions


Post your Comments and Discuss CompTIA CY0-001 exam prep with other Community members:

AI Tutor AI Tutor 👋 I’m here to help!